{
  "assessment": {
    "decisions": [
      {
        "decided_by": "scorer",
        "defect_id": null,
        "finding_id": "f1",
        "id": "d1",
        "outcome": "rejected",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "17",
        "finding_id": "f2",
        "id": "d2",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "12",
        "finding_id": "f3",
        "id": "d3",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "6",
        "finding_id": "f4",
        "id": "d4",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "13",
        "finding_id": "f5",
        "id": "d5",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "4",
        "finding_id": "f6",
        "id": "d6",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "7",
        "finding_id": "f7",
        "id": "d7",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "2",
        "finding_id": "f8",
        "id": "d8",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "11",
        "finding_id": "f9",
        "id": "d9",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "scorer",
        "defect_id": null,
        "finding_id": "f10",
        "id": "d10",
        "outcome": "rejected",
        "reason": null
      }
    ],
    "judge": null,
    "judged": false,
    "scorer": {
      "commit": "10b3b2068100b7ba429855e062500eaf83b90120",
      "digest": "sha256:a1a935298956020ee6d767a756847abb4c00694c88c2eb80d454886ebc4acf8c",
      "id": "bench-score",
      "version": "1"
    },
    "state": "measured"
  },
  "benchmark": {
    "input_fingerprint": "69301578538a",
    "key_fingerprint": "bd331c0b144e",
    "policy_fingerprint": "c53f8cfc8c75",
    "prompt_fingerprint": "74234e98afe7",
    "subject": "proxy"
  },
  "build": {
    "commit": "b0f313c0b59a66ecc7612396dc8db0ea5da13a7a",
    "digest": null,
    "dirty": false,
    "label": "afi 0.30.0",
    "version": "0.30.0"
  },
  "configuration": {
    "fingerprint": "be7c5b1aa470",
    "label": "default",
    "models": [
      {
        "effort": "high",
        "model": "z-ai/glm-5.3-flash",
        "protocol": null,
        "provider": "z-ai",
        "role": "agent"
      }
    ],
    "profile": null,
    "resolved": {
      "effort": "high",
      "instructions": [],
      "sandbox": {
        "backend": "macOS Seatbelt",
        "mode": "read-only",
        "network": "denied"
      },
      "source": "openrouter",
      "system_prompt": {
        "file": null,
        "mode": "builtin"
      },
      "tools": [
        "read_file",
        "write_file",
        "edit_file",
        "list_dir",
        "search_files",
        "glob_files",
        "run_bash",
        "wait_background"
      ]
    }
  },
  "coverage": {
    "chunks": null,
    "files_failed": 0,
    "files_kept": null,
    "files_skipped": 0,
    "files_unreviewed": 0,
    "hunks": null,
    "state": "measured"
  },
  "evidence": [
    {
      "digest": "sha256:62c8db7fa4e91bcc4422ff54920c75c8581e53d920a862033457b1d000380bf6",
      "media_type": "application/json",
      "path": "summary.json",
      "role": "summary"
    },
    {
      "digest": "sha256:fe4c62c6297fa64042ba0f7241cf1fc0b985d4ea3ae4be49a0f7e65a9a196f87",
      "media_type": "application/json",
      "path": "findings.json",
      "role": "findings"
    },
    {
      "digest": "sha256:d30a5e5e0fc7cf44da3dbb3ccaa4e41fe23904f4486ae636f4422cdb4631f987",
      "media_type": "application/json",
      "path": "meta.json",
      "role": "meta"
    },
    {
      "digest": "sha256:24a6b6eaec318356a90706dfcad5af4661b82230ba22948bd3f2b6c9201f8c07",
      "media_type": "application/json",
      "path": "spend.json",
      "role": "spend"
    },
    {
      "digest": "sha256:4ab8f4ba9d6f532243f766217fd13aa703c40924f595ebacfad5875cd96048d4",
      "media_type": "application/jsonl",
      "path": "result.jsonl",
      "role": "result"
    },
    {
      "digest": "sha256:d3e4fdbdaf0705a26adc2576ea02f9558e659e8834f9f9ba5fb69a34ecdfb82d",
      "media_type": "text/plain",
      "path": "stderr.txt",
      "role": "stderr"
    },
    {
      "digest": "sha256:de03e5e15aa8cd40b807dc269eeea65b36e63c29435d4eff17594c8c3161283f",
      "media_type": "application/gzip",
      "path": "afi-home/logs.tar.gz",
      "role": "traffic"
    }
  ],
  "execution": {
    "billing_limit_usd": 2.0,
    "budget_usd": null,
    "deadline_exceeded": false,
    "exit_code": 0,
    "finished_at": "2026-08-31T11:35:44Z",
    "started_at": "2026-08-31T11:28:41Z",
    "wall_seconds": 423.0
  },
  "extensions": {
    "afi": {
      "found_per_pass": {
        "agent": 10
      },
      "passes": null,
      "review_seconds": 421.952,
      "tier1_only": false,
      "variant_hash": null
    }
  },
  "findings": {
    "items": [
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "Duration::from_hours` and `Duration::from_mins` (line 84) do not exist in `std::time::Duration` \u2014 std only has `from_secs`/`from_millis`/`from_micros`/`from_nanos` \u2014 so the proxy does not compile;\u2026\n\nDuration::from_hours` and `Duration::from_mins` (line 84) do not exist in `std::time::Duration` \u2014 std only has `from_secs`/`from_millis`/`from_micros`/`from_nanos` \u2014 so the proxy does not compile; the whole sweep feature is dead on arrival. Needs `Duration::from_secs(3600)` / `Duration::from_secs(900)`.",
        "id": "f1",
        "locations": [
          {
            "end_line": 83,
            "path": "services/proxy/src/config.rs",
            "start_line": 83
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "clear_partials` unlinks every file in `incoming`, including the temp files of downloads currently in flight (`BlobWriter` creates them there, store.rs:173).\n\nThe write continues into the unlinked inode, then `commit`'s rename (store.rs:259) fails with ENOENT, so every concurrent fetch that spans a sweep fails with a 500 after downloading fully \u2014 routine with the default 15-minute sweep. It must skip files younger than `min_age` (or only remove files not owned by a live writer).",
        "id": "f2",
        "locations": [
          {
            "end_line": 232,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 232
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "forget` runs unconditionally, so a `dry_run=true` sweep deletes the index entries of blobs it would have removed \u2014 the dry run is not side-effect free as its doc and the admin route promise\u2026\n\nforget` runs unconditionally, so a `dry_run=true` sweep deletes the index entries of blobs it would have removed \u2014 the dry run is not side-effect free as its doc and the admin route promise (admin.rs:77-79). Next request for those coordinates misses and refetches; gate it on `!dry_run`.",
        "id": "f3",
        "locations": [
          {
            "end_line": 140,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 140
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "the on-demand route calls `app.sweeper.sweep(dry_run)` directly instead of `run()`, bypassing the `running` mutex, so it can execute concurrently with the background sweep \u2014 exactly the\u2026\n\nthe on-demand route calls `app.sweeper.sweep(dry_run)` directly instead of `run()`, bypassing the `running` mutex, so it can execute concurrently with the background sweep \u2014 exactly the two-sweeps-over-one-directory over-eviction the module doc (sweep.rs:10-12) claims the type makes impossible.",
        "id": "f4",
        "locations": [
          {
            "end_line": 76,
            "path": "services/proxy/src/routes/admin.rs",
            "start_line": 76
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "values()` returns `sweep_bytes_reclaimed` before `sweep_blobs_removed`, while `COUNTERS` (lines 51-57) lists blobs before bytes, so `render()` publishes the blob count under\u2026\n\nvalues()` returns `sweep_bytes_reclaimed` before `sweep_blobs_removed`, while `COUNTERS` (lines 51-57) lists blobs before bytes, so `render()` publishes the blob count under `cairn_proxy_sweep_bytes_reclaimed_total` and vice versa \u2014 the very mispairing the comment at line 30-32 says this layout prevents. operations.md:54 tells operators to alert on the bytes counter, which would actually alert on blob counts.",
        "id": "f5",
        "locations": [
          {
            "end_line": 94,
            "path": "services/proxy/src/metrics.rs",
            "start_line": 94
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "the comment says a symlink is \"counted at the size of the link\", but `fs::metadata` follows links; a hardlink-style store double-counts linked blobs at full size and evicts prematurely.\n\n`fs::symlink_metadata` is what the comment describes.",
        "id": "f6",
        "locations": [
          {
            "end_line": 164,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 164
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "the comment (lines 101-102) claims the first tick is one interval away, but `tokio::time::interval`'s first tick completes immediately, so a sweep runs at startup \u2014 on a pre-populated store it\u2026\n\nthe comment (lines 101-102) claims the first tick is one interval away, but `tokio::time::interval`'s first tick completes immediately, so a sweep runs at startup \u2014 on a pre-populated store it evicts and clears `incoming` the moment the process boots, contrary to the stated intent.",
        "id": "f7",
        "locations": [
          {
            "end_line": 108,
            "path": "services/proxy/src/main.rs",
            "start_line": 108
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "when `remove_file` fails (line 126), the blob is still counted in `removed`/`bytes` and pushed to `gone`, so `forget` deletes index entries pointing at a blob still on disk and the recorded metrics\u2026\n\nwhen `remove_file` fails (line 126), the blob is still counted in `removed`/`bytes` and pushed to `gone`, so `forget` deletes index entries pointing at a blob still on disk and the recorded metrics claim bytes that were never reclaimed. Only count/push on a successful (or simulated) unlink.",
        "id": "f8",
        "locations": [
          {
            "end_line": 137,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 137
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "sweep` runs the entire synchronous `read_dir`/`unlink` walk inline on a tokio worker thread \u2014 in both the background task and the HTTP handler \u2014 blocking that worker for the whole pass (the module's\u2026\n\nsweep` runs the entire synchronous `read_dir`/`unlink` walk inline on a tokio worker thread \u2014 in both the background task and the HTTP handler \u2014 blocking that worker for the whole pass (the module's own example is 65,000 directories). `spawn_blocking` would keep the scheduler serving requests during a long sweep.",
        "id": "f9",
        "locations": [
          {
            "end_line": 90,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 90
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "cache_min_age` is the only new setting with no validation, unlike its siblings `fetch_timeout` and `sweep_interval`; a `CAIRN_CACHE_MIN_AGE=0` typo silently disables the documented grace period,\u2026\n\ncache_min_age` is the only new setting with no validation, unlike its siblings `fetch_timeout` and `sweep_interval`; a `CAIRN_CACHE_MIN_AGE=0` typo silently disables the documented grace period, letting a store over its ceiling evict blobs seconds after they were fetched.",
        "id": "f10",
        "locations": [
          {
            "end_line": 131,
            "path": "services/proxy/src/config.rs",
            "start_line": 131
          }
        ],
        "severity": "bug",
        "title": "bug"
      }
    ],
    "problems": [],
    "state": "measured"
  },
  "harness": {
    "adapter": {
      "digest": "sha256:a1a935298956020ee6d767a756847abb4c00694c88c2eb80d454886ebc4acf8c",
      "id": "afi",
      "version": "1"
    },
    "commit": "10b3b2068100b7ba429855e062500eaf83b90120",
    "digest": "sha256:a1a935298956020ee6d767a756847abb4c00694c88c2eb80d454886ebc4acf8c",
    "dirty": true,
    "id": "bench",
    "repository_url": "https://github.com/smykla-skalski/benchee",
    "version": "1"
  },
  "incremental": {
    "carried_count": null,
    "mode": "not_recorded",
    "prior_reviewed_sha": null,
    "reused_tokens": null,
    "state_source": null
  },
  "label": "glm-5.3-flash",
  "metrics": {
    "anchor_max": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 0
    },
    "anchor_median": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 0
    },
    "anchor_missed": {
      "reason": "no judging pass has looked beyond the scored slack",
      "state": "not_recorded",
      "unit": "count",
      "value": null
    },
    "carried": {
      "reason": "the reviewer reported no reuse figure",
      "state": "not_recorded",
      "unit": "count",
      "value": null
    },
    "category_defect": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.46153846153846156
    },
    "category_maintainability": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.0
    },
    "category_performance": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.3333333333333333
    },
    "category_security": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.5
    },
    "f1": {
      "reason": "no qualified judge decided these findings, so only locality was measured",
      "state": "not_applicable",
      "unit": "ratio",
      "value": null
    },
    "finding_count": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 10
    },
    "found": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 8
    },
    "intended": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 0
    },
    "judge_bill": {
      "reason": "no qualified judge decided these findings, so only locality was measured",
      "state": "not_applicable",
      "unit": "usd",
      "value": null
    },
    "missed": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 12
    },
    "precision": {
      "reason": "no qualified judge decided these findings, so only locality was measured",
      "state": "not_applicable",
      "unit": "ratio",
      "value": null
    },
    "recall": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.4
    },
    "review_bill": {
      "reason": null,
      "state": "measured",
      "unit": "usd",
      "value": 0.030604054
    },
    "seconds": {
      "reason": null,
      "state": "measured",
      "unit": "seconds",
      "value": 423.0
    },
    "tier_1": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.3333333333333333
    },
    "tier_2": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.42857142857142855
    },
    "tier_3": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.5
    },
    "tier_4": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.25
    },
    "tokens": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 46555
    },
    "total_bill": {
      "reason": null,
      "state": "measured",
      "unit": "usd",
      "value": 0.030604054
    },
    "unkeyed": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 2
    }
  },
  "producer": {
    "commit": "10b3b2068100b7ba429855e062500eaf83b90120",
    "digest": "sha256:a1a935298956020ee6d767a756847abb4c00694c88c2eb80d454886ebc4acf8c",
    "dirty": true,
    "id": "benchee",
    "repository_url": "https://github.com/smykla-skalski/benchee",
    "version": "1"
  },
  "reviewer": {
    "id": "afi",
    "label": "afi review",
    "repository_url": "https://github.com/smykla-skalski/afi",
    "tool": {
      "interface": "cli",
      "name": "afi"
    }
  },
  "run_id": "afi/glm-5.3-flash/20260831T111212Z",
  "runtime": {
    "architecture": "arm64",
    "cache_mode": null,
    "cpus": 14,
    "memory_bytes": 38654705664,
    "os": "Darwin",
    "provider_route": "openrouter",
    "region": null,
    "runner_image": null
  },
  "schema": "benchee-run-1",
  "stamp": "20260831T111212Z",
  "status": {
    "reason": null,
    "state": "completed"
  },
  "target": {
    "base_sha": null,
    "diff_digest": "sha256:e4038205478b5c2646697e6c6a82c1ab83e90117fe066c4f7862592287880c01",
    "pull_request": 8,
    "repository_url": "https://github.com/smykla-skalski/cairn",
    "reviewed_sha": "9b51f95ef609a219e211e37b082cd2e6913190e0"
  },
  "usage": {
    "reason": null,
    "state": "measured",
    "value": {
      "cached_input_tokens": 319104,
      "input_tokens": 45780,
      "models": null,
      "output_tokens": 775,
      "reasoning_tokens": 28447,
      "requests": 13,
      "stages": []
    }
  }
}
