{
  "assessment": {
    "decisions": [
      {
        "decided_by": "locality",
        "defect_id": "12",
        "finding_id": "f1",
        "id": "d1",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "1",
        "finding_id": "f2",
        "id": "d2",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "17",
        "finding_id": "f3",
        "id": "d3",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "13",
        "finding_id": "f4",
        "id": "d4",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "6",
        "finding_id": "f5",
        "id": "d5",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "18",
        "finding_id": "f6",
        "id": "d6",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "11",
        "finding_id": "f7",
        "id": "d7",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "7",
        "finding_id": "f8",
        "id": "d8",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "4",
        "finding_id": "f9",
        "id": "d9",
        "outcome": "matched",
        "reason": null
      },
      {
        "decided_by": "locality",
        "defect_id": "2",
        "finding_id": "f10",
        "id": "d10",
        "outcome": "matched",
        "reason": null
      }
    ],
    "judge": null,
    "judged": false,
    "scorer": {
      "commit": "d5372b5a9797137af68e35c478f308f58ca4510c",
      "digest": "sha256:a1a935298956020ee6d767a756847abb4c00694c88c2eb80d454886ebc4acf8c",
      "id": "bench-score",
      "version": "1"
    },
    "state": "measured"
  },
  "benchmark": {
    "input_fingerprint": "69301578538a",
    "key_fingerprint": "bd331c0b144e",
    "policy_fingerprint": "c53f8cfc8c75",
    "prompt_fingerprint": "74234e98afe7",
    "subject": "proxy"
  },
  "build": {
    "commit": "b0f313c0b59a66ecc7612396dc8db0ea5da13a7a",
    "digest": null,
    "dirty": false,
    "label": "afi 0.30.0",
    "version": "0.30.0"
  },
  "configuration": {
    "fingerprint": "8232536cf248",
    "label": "default",
    "models": [
      {
        "effort": "high",
        "model": "anthropic/claude-fable-5",
        "protocol": null,
        "provider": "anthropic",
        "role": "agent"
      }
    ],
    "profile": null,
    "resolved": {
      "effort": "high",
      "instructions": [],
      "sandbox": {
        "backend": "macOS Seatbelt",
        "mode": "read-only",
        "network": "denied"
      },
      "source": "openrouter",
      "system_prompt": {
        "file": null,
        "mode": "builtin"
      },
      "tools": [
        "read_file",
        "write_file",
        "edit_file",
        "list_dir",
        "search_files",
        "glob_files",
        "run_bash",
        "wait_background"
      ]
    }
  },
  "coverage": {
    "chunks": null,
    "files_failed": 0,
    "files_kept": null,
    "files_skipped": 0,
    "files_unreviewed": 0,
    "hunks": null,
    "state": "measured"
  },
  "evidence": [
    {
      "digest": "sha256:b0596269ba456758eb787478cc4580ae6f4fbfd6a89200f5ac2e44928150bca4",
      "media_type": "application/json",
      "path": "summary.json",
      "role": "summary"
    },
    {
      "digest": "sha256:59197dc193f7da922c1ed19ad051be1cb93ab09b0acdf4f4de5d24882e0acde8",
      "media_type": "application/json",
      "path": "findings.json",
      "role": "findings"
    },
    {
      "digest": "sha256:87f7424686e3a0cdb74bf26c24f929217c38da8e82ee41af36f3ac326a2cb26d",
      "media_type": "application/json",
      "path": "meta.json",
      "role": "meta"
    },
    {
      "digest": "sha256:376188ed94db45c549f9b73a3ebd0a4baabc85a20b951c273b6aeec052aa0400",
      "media_type": "application/json",
      "path": "spend.json",
      "role": "spend"
    },
    {
      "digest": "sha256:df005e67c01e068e5b9d363ea2a57fedca7ce27e235fc5b3c8df213378c2ad37",
      "media_type": "application/jsonl",
      "path": "result.jsonl",
      "role": "result"
    },
    {
      "digest": "sha256:fa7d2d559b8c27b0591425147821959125de90e3edc3789c6d031c0d22ba705c",
      "media_type": "text/plain",
      "path": "stderr.txt",
      "role": "stderr"
    },
    {
      "digest": "sha256:6d844dcd842e2d88b96d7cebf2feb03b9c5d1596d13ea30cd6864ed891ca738e",
      "media_type": "application/gzip",
      "path": "afi-home/logs.tar.gz",
      "role": "traffic"
    }
  ],
  "execution": {
    "billing_limit_usd": 20.0,
    "budget_usd": 20.0,
    "deadline_exceeded": false,
    "exit_code": 0,
    "finished_at": "2026-08-31T17:32:00Z",
    "started_at": "2026-08-31T17:29:10Z",
    "wall_seconds": 170.0
  },
  "extensions": {
    "afi": {
      "found_per_pass": {
        "agent": 10
      },
      "passes": null,
      "review_seconds": 168.31,
      "tier1_only": false,
      "variant_hash": null
    }
  },
  "findings": {
    "items": [
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "forget(&index, &gone)` runs even when `dry_run` is true, so a \"report only\" dry run permanently deletes the index entries for every blob it would have removed \u2014 the blobs become unreachable cache\u2026\n\nforget(&index, &gone)` runs even when `dry_run` is true, so a \"report only\" dry run permanently deletes the index entries for every blob it would have removed \u2014 the blobs become unreachable cache misses and are collected as unreferenced garbage by the next real sweep, making `?dry_run=true` destructive despite the route's promise.",
        "id": "f1",
        "locations": [
          {
            "end_line": 140,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 140
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "sort_by_key(|c| c.age)` sorts ascending, putting the *youngest* blobs first, so the eviction loop removes the most recently fetched blobs first \u2014 the exact opposite of the \"Oldest first\" comment and\u2026\n\nsort_by_key(|c| c.age)` sorts ascending, putting the *youngest* blobs first, so the eviction loop removes the most recently fetched blobs first \u2014 the exact opposite of the \"Oldest first\" comment and of the documented `CAIRN_CACHE_MAX_BYTES` behaviour; the hot working set is evicted while the stalest blobs survive.",
        "id": "f2",
        "locations": [
          {
            "end_line": 102,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 102
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "clear_partials` unlinks every file in `incoming/` with no age check, but `BlobStore::temp_path` (store.rs:201) puts *live* in-flight downloads there; each sweep unlinks the temp files of concurrent\u2026\n\nclear_partials` unlinks every file in `incoming/` with no age check, but `BlobStore::temp_path` (store.rs:201) puts *live* in-flight downloads there; each sweep unlinks the temp files of concurrent fetches, whose `commit` rename (store.rs:259) then fails, so every sweep fails all downloads in flight at that moment.",
        "id": "f3",
        "locations": [
          {
            "end_line": 230,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 230
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "values()` loads `sweep_bytes_reclaimed` at index 4 and `sweep_blobs_removed` at index 5, but `COUNTERS` puts `..._blobs_removed_total` at index 4 and `..._bytes_reclaimed_total` at index 5, so the\u2026\n\nvalues()` loads `sweep_bytes_reclaimed` at index 4 and `sweep_blobs_removed` at index 5, but `COUNTERS` puts `..._blobs_removed_total` at index 4 and `..._bytes_reclaimed_total` at index 5, so the two new counters are rendered under each other's names \u2014 the exact mix-up the comment above `COUNTERS` warns about, and the ops doc tells operators to alert on the misrendered `cairn_proxy_sweep_bytes_reclaimed_total`.",
        "id": "f4",
        "locations": [
          {
            "end_line": 94,
            "path": "services/proxy/src/metrics.rs",
            "start_line": 94
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "the admin route calls `app.sweeper.sweep(dry_run)` directly, bypassing the `running` mutex that only `Sweeper::run` takes (sweep.rs:83), so an admin-triggered sweep can run concurrently with the\u2026\n\nthe admin route calls `app.sweeper.sweep(dry_run)` directly, bypassing the `running` mutex that only `Sweeper::run` takes (sweep.rs:83), so an admin-triggered sweep can run concurrently with the background sweep (or with another admin sweep) \u2014 the exact double-sweep over-eviction the module doc at sweep.rs:10-12 says the mutex exists to prevent.",
        "id": "f5",
        "locations": [
          {
            "end_line": 76,
            "path": "services/proxy/src/routes/admin.rs",
            "start_line": 76
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "an unreferenced blob is removed with no `min_age` grace, but a blob is legitimately unreferenced in the window between `writer.commit()` (cache.rs:151) and `store.link` (cache.rs:163), which spans a\u2026\n\nan unreferenced blob is removed with no `min_age` grace, but a blob is legitimately unreferenced in the window between `writer.commit()` (cache.rs:151) and `store.link` (cache.rs:163), which spans a registry round-trip; a sweep in that window deletes the freshly committed blob and the request 500s at cache.rs:90 (\"a blob committed by this request is already missing\").",
        "id": "f6",
        "locations": [
          {
            "end_line": 119,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 119
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "performance",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "run()` (and the admin handler via admin.rs:76) executes the fully synchronous walk-and-unlink `sweep()` directly on a tokio worker thread instead of `spawn_blocking`; the router comment in\u2026\n\nrun()` (and the admin handler via admin.rs:76) executes the fully synchronous walk-and-unlink `sweep()` directly on a tokio worker thread instead of `spawn_blocking`; the router comment in routes/mod.rs concedes a sweep \"legitimately takes longer than ten seconds\", so a large store blocks an async runtime worker for that whole time.",
        "id": "f7",
        "locations": [
          {
            "end_line": 84,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 84
          }
        ],
        "severity": "performance",
        "title": "performance"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "tokio::time::interval` completes its first tick immediately, so the first sweep runs at startup \u2014 the doc comment at lines 101-102 claims the first tick is one interval away precisely to avoid this;\u2026\n\ntokio::time::interval` completes its first tick immediately, so the first sweep runs at startup \u2014 the doc comment at lines 101-102 claims the first tick is one interval away precisely to avoid this; `interval_at(Instant::now() + period, period)` is what the comment describes.",
        "id": "f8",
        "locations": [
          {
            "end_line": 108,
            "path": "services/proxy/src/main.rs",
            "start_line": 108
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "fs::metadata` follows symlinks, so a link is counted at the size of its *target* (and a symlinked directory is recursed into and its contents unlinked), the inverse of the comment's claim that \"a\u2026\n\nfs::metadata` follows symlinks, so a link is counted at the size of its *target* (and a symlinked directory is recursed into and its contents unlinked), the inverse of the comment's claim that \"a link is counted at the size of the link\"; `symlink_metadata` is what the comment describes.",
        "id": "f9",
        "locations": [
          {
            "end_line": 164,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 164
          }
        ],
        "severity": "bug",
        "title": "bug"
      },
      {
        "attributes": {
          "category": "bug",
          "confidence": null,
          "evidence_quote": null,
          "suggested_fix": null
        },
        "body": "when `fs::remove_file` fails on line 126, the blob is still counted in `removed`/`bytes`/`remaining` and pushed to `gone`, so the reported reclaim overstates reality and `forget` deletes the index\u2026\n\nwhen `fs::remove_file` fails on line 126, the blob is still counted in `removed`/`bytes`/`remaining` and pushed to `gone`, so the reported reclaim overstates reality and `forget` deletes the index entries of a blob that is still on disk, orphaning it until a later sweep.",
        "id": "f10",
        "locations": [
          {
            "end_line": 134,
            "path": "services/proxy/src/sweep.rs",
            "start_line": 134
          }
        ],
        "severity": "bug",
        "title": "bug"
      }
    ],
    "problems": [],
    "state": "measured"
  },
  "harness": {
    "adapter": {
      "digest": "sha256:a1a935298956020ee6d767a756847abb4c00694c88c2eb80d454886ebc4acf8c",
      "id": "afi",
      "version": "1"
    },
    "commit": "d5372b5a9797137af68e35c478f308f58ca4510c",
    "digest": "sha256:a1a935298956020ee6d767a756847abb4c00694c88c2eb80d454886ebc4acf8c",
    "dirty": false,
    "id": "bench",
    "repository_url": "https://github.com/smykla-skalski/benchee",
    "version": "1"
  },
  "incremental": {
    "carried_count": null,
    "mode": "not_recorded",
    "prior_reviewed_sha": null,
    "reused_tokens": null,
    "state_source": null
  },
  "label": "fable-5",
  "metrics": {
    "anchor_max": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 0
    },
    "anchor_median": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 0
    },
    "anchor_missed": {
      "reason": "no judging pass has looked beyond the scored slack",
      "state": "not_recorded",
      "unit": "count",
      "value": null
    },
    "carried": {
      "reason": "the reviewer reported no reuse figure",
      "state": "not_recorded",
      "unit": "count",
      "value": null
    },
    "category_defect": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.6153846153846154
    },
    "category_maintainability": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.0
    },
    "category_performance": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.3333333333333333
    },
    "category_security": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.5
    },
    "f1": {
      "reason": "no qualified judge decided these findings, so only locality was measured",
      "state": "not_applicable",
      "unit": "ratio",
      "value": null
    },
    "finding_count": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 10
    },
    "found": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 10
    },
    "intended": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 0
    },
    "judge_bill": {
      "reason": "no qualified judge decided these findings, so only locality was measured",
      "state": "not_applicable",
      "unit": "usd",
      "value": null
    },
    "missed": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 10
    },
    "precision": {
      "reason": "no qualified judge decided these findings, so only locality was measured",
      "state": "not_applicable",
      "unit": "ratio",
      "value": null
    },
    "recall": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.5
    },
    "review_bill": {
      "reason": null,
      "state": "measured",
      "unit": "usd",
      "value": 1.70665
    },
    "seconds": {
      "reason": null,
      "state": "measured",
      "unit": "seconds",
      "value": 170.0
    },
    "tier_1": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.6666666666666666
    },
    "tier_2": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.42857142857142855
    },
    "tier_3": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.5
    },
    "tier_4": {
      "reason": null,
      "state": "measured",
      "unit": "ratio",
      "value": 0.5
    },
    "tokens": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 108636
    },
    "total_bill": {
      "reason": null,
      "state": "measured",
      "unit": "usd",
      "value": 1.70665
    },
    "unkeyed": {
      "reason": null,
      "state": "measured",
      "unit": "count",
      "value": 0
    }
  },
  "producer": {
    "commit": "d5372b5a9797137af68e35c478f308f58ca4510c",
    "digest": "sha256:a1a935298956020ee6d767a756847abb4c00694c88c2eb80d454886ebc4acf8c",
    "dirty": false,
    "id": "benchee",
    "repository_url": "https://github.com/smykla-skalski/benchee",
    "version": "1"
  },
  "reviewer": {
    "id": "afi",
    "label": "afi review",
    "repository_url": "https://github.com/smykla-skalski/afi",
    "tool": {
      "interface": "cli",
      "name": "afi"
    }
  },
  "run_id": "afi/fable-5/20260831T172436Z",
  "runtime": {
    "architecture": "arm64",
    "cache_mode": null,
    "cpus": 14,
    "memory_bytes": 38654705664,
    "os": "Darwin",
    "provider_route": "openrouter",
    "region": null,
    "runner_image": null
  },
  "schema": "benchee-run-1",
  "stamp": "20260831T172436Z",
  "status": {
    "reason": null,
    "state": "completed"
  },
  "target": {
    "base_sha": null,
    "diff_digest": "sha256:8b6acd80424c8af9017d7db2e1ceeaca4da5cf1f29e87c3559b2e5ea55782cfe",
    "pull_request": 8,
    "repository_url": "https://github.com/smykla-skalski/cairn",
    "reviewed_sha": "9b51f95ef609a219e211e37b082cd2e6913190e0"
  },
  "usage": {
    "reason": null,
    "state": "measured",
    "value": {
      "cached_input_tokens": 0,
      "input_tokens": 106515,
      "models": null,
      "output_tokens": 2121,
      "reasoning_tokens": 10709,
      "requests": 3,
      "stages": []
    }
  }
}
