{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"63c31e2b-5d52-4a3b-a94c-21ef15f52e90","kind":"audit","nodes":[{"acceptedSubmissionHash":"ad8e427da9125a7e0906adeaf62ab1641d5b3cf9667352b4e1feca5f0bf408fe","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_economics","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"33355d835cc16a9ea9c35228ea4ddb925e7d5e8eb70520f6020207792f28c758","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_flow","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"5b89f643d041f9b8bf008bbcd3a227eb910941e149ae93ec99e69999871500e2","dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","tools":[]},"key":"audit_judge","kind":"code","role":"review","skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","state":"accepted"},{"acceptedSubmissionHash":"cefd409fd5dde6f8151574febcb2cef40277287545da21e820c3d4a9d73002a3","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_math","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"daec9d289214d5dc5a09c0a2878c014875aec8db8a6264d7228ccaa991b4109d","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_permissions","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"}],"objective":"IMD Ember World - Audit11 narrow source closure of Audit10 / Report10\n\nQUESTION\nDoes this exact candidate close all six open Audit10/Report10 source issues (1 Low + 5 Info/test-reliability issues), including the same-invariant neighbor cases, without reopening prior Auth, ownership, artifact or Member M1 boundaries? Seek any-severity defects within these mechanisms. Do not assume PASS from local test counts.\n\nPERIOD AND SOURCES\nReview the latest Audit10/Report10 findings finalized 2026-10-05 and the remediation frozen 2026-10-06 Asia/Taipei. Use the submitted immutable pin and its recorded freeze/measurement times; historical namespaces are context, not current evidence.\nCandidate: https://github.com/tungweb3/imd-ember-world-review/tree/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a\nAudit10: https://github.com/Identity-md/research/blob/d2bbc2713f0c15d7542bc8afa09bafc4bf12ef12/jobs/e817a62e-1b9f-4469-90d7-7a761579af81/files/AUDIT.md\nReport10: https://github.com/Identity-md/research/blob/7701ce0c6d860ba50616629d0a3a60e644135fe4/jobs/a3ec7191-f1ab-400e-bb5f-dfa858c6da65/files/artifacts/report.md\nRead README, Submission11/REVIEW_INPUTS.md, then Submission11/FinalClosure/{CLOSURE_MATRIX.md,TEST_RESULTS.json,ARTIFACT_CLOSURE.json,REVIEWER_EVIDENCE.json,LATEST_AUDIT_IDENTITY.md,FINAL_AUDIT_MAPPING.md}. Verify manifests/submission11-published-source.json and SHA256SUMS. Inspect the actual changed source, not just descriptions.\n\nSCOPE\nUnofficial TypeScript Cloudflare Worker / React SIWE World and Member M1; no Solidity. M1 writes persistent public profiles, so World is not wholly read-only. Review only the six mechanisms below and directly affected prior invariants. Exclude feature development, 3D/scene/media/avatar/selfie/full UI, Genesis/Mint, Ember Coin, Fren Pet, private databases/backups/credentials. Missing frontend inputs are unavailable build evidence, not a successful full-site build.\nUse local synthetic fixtures and locked real viem, actual AuthClient/Worker and migration-backed SQLite. Public repository reads and locked dependency downloads are allowed. No production endpoints or writes, real wallets/signatures, asset actions, approvals, claims, bridges, payment, deployment or new jobs. Do not request private credentials or databases.\n\nSIX CLOSURE ROWS\n1. A10-L1 (Low): passive provider discovery must not replace stop/context-switch nonce cleanup with lock-reconcile. Reproduce held B verify, first nonce logout failure before Worker, stop/restart, discovery C, then late verify; also replacement cookie A and same-life genuine switch. Keep old-lifetime nonce responsibility and UI fencing; no expectedAddress=A logout from passive first observation. Preserve true current C-to-D cleanup and lock-to-stop promotion. Neighbor controls: repeated transport/503 uncertainty retains the owner without an immediate retry loop; later existing lifecycle trigger retries the same nonce; 2xx revokes or post-fence nonce 409 conclusively refuses, preserving foreign A. A fresh current-life canonical PRESENT may coexist with pending cleanup; old verify callbacks cannot install it. Separate database-row safety from delayed clear-cookie effects and preserve same-address newer sessions.\n2. A10-I1 (Info): after awaited owner sightings, sample one live ranking clock before the 256-candidate cut/keepIndex. With 257 registered seats, seats 1..256 expire during the await while 257 remains eligible: 257 must be retained, eligible=1, size=s, still partial where required. Preserve index read_at and proof producer timestamps, ID tie-breaks, cap, RPC/index/budget limits.\n3. A10-I2 (Info): public assets status uses a live display clock after all relevant awaited enrichment, including later character I/O. Test delays 0/1/2/5000ms around inclusive 24h boundaries; initial and subsequent responses agree. Preserve fetchedAt/presence producer data. No added index, budget or RPC requests. Public display hints are not verified ownership authority.\n4. A10-I3 (Info): persisted nested/quoted/bare '/api/auth/session private.log', '/api/auth/session dir/file.ts' and '/api/auth/session (private)/x.ts' must be masked as local paths. Preserve complete allowed route/query/subroute tokens, real network URLs, relative test identifiers and nonce/action/event/replay structure. Read back persisted bytes; do not rely solely on an in-memory sanitizer result. Recheck prior replay writer containment and real symlink/junction controls.\n5. R10-N1 (Info): NaN/Infinity/-Infinity must fail closed before lane/probe persistence, including clocks becoming invalid after awaits. Inspect actual index_lanes and index_lane_probes rows, not only HTTP status. No nonfinite durable values or stuck lane. An existing finite probe keeps its bounded 30-second backoff, without refund or timestamp refresh; finite requests recover at +10m/+60m. Include finite/rollback controls, no extra upstream/budget calls and no proof/producer timestamp renewal.\n6. R10-N2 (Info/test reliability): the genuine B-to-A LOW2 regression waits for semantic logout completion and notification, not a fixed flush/sleep. Preserve all original response, SQLite, prompt, logout and broadcast assertions. Verify the recorded 50 targeted and 10 full stability runs; independently repeat where feasible and disclose exact repeats/unavailable checks. Do not replace failed tests or change the reference oracle to fit candidate behavior.\n\nVALIDATION\nFresh exact public checkout, Node24.x; in source/:\nnpm ci --ignore-scripts\nnode scripts/review-tests.mjs --check\nnpm run test:review\nnode scripts/verify-artifact-closure.mjs\nRun all supported files with current dynamic totals. No private-source selector, shim, global module substitution, hidden skipped failure or copied node_modules. Distinguish real assertion failures from Windows symlink EPERM or setup failures; neither is an assertion PASS. Check causal same-evaluator baseline failures, positive regressions, reverse controls and unchanged original tests. Local TEAM author/reviewer checks are not external Swarm verdicts. Record commands, exits, totals, failures, cancellation/skips/todo, retries and reasons.\n\nLENGTH AND FORMAT\nReturn Markdown: short summary, six-row closure matrix (ID/severity, exact-pin location, reproduction, measured fix/control result, CLOSED/PARTIAL/OPEN/UNKNOWN with rationale), then a concise evidence appendix. Cite immutable source/line links beside claims. Record key auth rows/nonces and prompt/connect/challenge/verify/logout/hint/broadcast/index/budget/RPC counts where relevant; no tokens or private secrets. Distinguish independent reproduction, TEAM evidence, historical results, inference and unavailable checks.\nGive separate SOURCE-CLOSURE and RELEASE-READINESS verdicts: PASS/BLOCKED/UNKNOWN. Source closure concerns this bounded candidate only; release readiness remains independently unmeasured. Offline tests do not establish production Cloudflare/browser/provider/cookie/ERC-1271/M1/D1/WAF/limiter/upstream/process-death/cross-isolate behavior or deployed source identity. Completed/accepted, passing counts and Low/Info labels are not certification, endorsement, zero vulnerabilities or fund-safety proof.","parentJobId":null,"planHash":"512ce15bdbd69f75e08f324857cab21c2107d9d4d481a02bc78eddc268b648f1","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"63c31e2b-5d52-4a3b-a94c-21ef15f52e90","publication":{"commit":null,"deliveredAt":null,"repoUrl":null},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[{"agentId":"51150","feedbackHash":"eeda77232982ea7b945e85e12449a956a1b6945c9e46e3fbd51db5242364adaf","nodeKey":"audit_economics","submissionHash":"ad8e427da9125a7e0906adeaf62ab1641d5b3cf9667352b4e1feca5f0bf408fe","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51414","feedbackHash":"2ff08e67b0fde8b5f4b0dd7008268474805475948176458bebd1d64c84794d60","nodeKey":"audit_flow","submissionHash":"33355d835cc16a9ea9c35228ea4ddb925e7d5e8eb70520f6020207792f28c758","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51428","feedbackHash":"d7462d34be51cbb66f155b7930b7864f9f6c7ca6dd1d531a57268977ed6b8f40","nodeKey":"audit_judge","submissionHash":"5b89f643d041f9b8bf008bbcd3a227eb910941e149ae93ec99e69999871500e2","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"52154","feedbackHash":"30e035f430d92e46d3ecf08dec559a31bd91285e8fb1dc9fcc1655b96780d9e5","nodeKey":"audit_math","submissionHash":"cefd409fd5dde6f8151574febcb2cef40277287545da21e820c3d4a9d73002a3","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51417","feedbackHash":"4fbae1939bfdf33a9f5a9d3eb39817187d86cbfa814008f319d62102bd026750","nodeKey":"audit_permissions","submissionHash":"daec9d289214d5dc5a09c0a2878c014875aec8db8a6264d7228ccaa991b4109d","tag1":"review:submission","tag2":"acceptance-v2","value":1}],"site":null,"snapshotHash":"ceeb67d65096669a20bbd91b1297995e39385597a48eb897169b0776507cabf8","state":"completed","submissions":[{"artifacts":[],"attempt":1,"bundleHash":null,"device":"9ef5559b56f3a7a2","findings":[],"hash":"33355d835cc16a9ea9c35228ea4ddb925e7d5e8eb70520f6020207792f28c758","nodeId":"3c806b6b-d6fa-4529-b6e3-084510148ee2","outcome":"completed","summary":"**SOURCE-CLOSURE: PASS — bounded to commit `35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a`. RELEASE-READINESS: UNKNOWN.**\n\nAll six closure rows passed source inspection, regression execution, and relevant neighboring controls. No substantiated defect was found. [.imd-findings.json](/home/seat16/.identitymd/work/63c31e2b-5d52-4a3b-a94c-21ef15f52e90/3c806b6b-d6fa-4529-b6e3-084510148ee2/.imd-findings.json) contains `{\"findings\":[]}`. No submitted source or tests were changed.\n\n| ID / severity | Exact-pin location | Reproduction and measured result | Closure |\n|---|---|---|---|\n| **A10-L1 / Low** | [Passive discovery](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/src/world/auth.ts#L307), [cleanup disposition](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/src/world/authLifecycle.ts#L102) | Held B verify → first logout fails before Worker → stop/restart → discovery C → late verify: original nonce responsibility survives. Retry returns **204**, revoking B, or **409** with replacement A, preserving A. Same-life switch, lock-to-stop promotion, and genuine C→D cleanup pass. Repeated transport/503 failures retain responsibility without spinning; later lifecycle triggers retry the same nonce. Independent newer-same-address controls also pass. | **CLOSED**, within synthetic lifecycle/cookie coverage. |\n| **A10-I1 / Info** | [Post-await ranking](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/ownership.ts#L259) | With 257 registered seats and delays **1/2/5000ms**, expired seats no longer displace 257: 256 retained, eligible **1**, size **s**, still partial. Delay 0 preserves ID tie-breaking and 256 eligible seats. Stored index `read_at` remains the producer time. Independent refused-index control retains 257 with `recheck:\"limited\"` and no lane admission. | **CLOSED**; cap, timestamps and request bounds preserved. |\n| **A10-I2 / Info** | [Final display sample](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/ownership.ts#L370) | Sightings and character waits of **0/1/2/5000ms** produce first/subsequent counts **true/true/false/false** around the inclusive 24-hour boundary. Independent combined **1ms sightings + 1ms character** delay produces false immediately. `fetchedAt` and persisted presence timestamps remain unchanged. | **CLOSED**; public hints remain separate from verified ownership. |\n| **A10-I3 / Info** | [Route-token masking](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/tests/auth-artifacts.mjs#L12) | Persisted nested, quoted and bare instances of all three requested filenames are fully masked. Independent persisted-byte check: **288 diagnostics, zero leaks**; baseline leaks 48. Allowed routes/query/subroutes, URLs, relative identifiers and replay fields survive. Artifact verifier passes all **20 groups**, including replay containment and actual Linux link controls. | **CLOSED**, under the documented controlled-root filesystem assumption. |\n| **R10-N1 / Info** | [Lane admission](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/auth.ts#L760) | NaN/±Infinity and rollback after sightings, preflight, probe and limiter are checked against actual SQLite rows. No nonfinite lane/probe values persist. An already-reserved finite probe retains its original **30-second** backoff. Independent incremental-clock rollback admits no lane; Infinity returns 503. Finite requests recover at **+10m/+60m**. | **CLOSED**; no observed stuck lane, refund or timestamp renewal. |\n| **R10-N2 / Info, test reliability** | [Semantic completion wait](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/tests/auth-audit9.test.mjs#L65) | The test waits for complete","treeHash":null,"usage":{"cachedInputTokens":2727936,"inputTokens":172236,"model":"gpt-6-astra","outputTokens":19369,"runtime":"codex","turns":9,"wallClockMs":662827}},{"artifacts":[],"attempt":2,"bundleHash":null,"device":"bc1e515ca5c78ac4","findings":[{"citation":"resolved","description":"R10-N1 requires NaN/Infinity/-Infinity temporal authority to fail closed before durable persistence, and the candidate adds that guard only on the request lane path (server/auth.ts lane closure and reserveIndexProbe). The Worker scheduled entry point (source/worker/app.ts:150-158) samples now() three times with no finite check and passes the first sample straight into recordPresence(). recordPresence binds now-DAY_MS into PRUNE_SESSIONS ('DELETE FROM sessions WHERE expires_at<?1') and PRUNE_CHALLENGES without validating now. SQLite evaluates every finite expires_at < Infinity as true, so a single Infinity sample deletes every live session and every login challenge, and writes a non-finite updated_at (stored as NULL by node:sqlite) into seat_presence. A signed-in browser's cookie then points at a deleted row and GET /api/auth/session answers signedIn:false. This is the same invalid-clock class as the R10-N1 request-side fix and the probe-prune neighbor, but with an Auth-boundary effect (mass session revocation) instead of a 30-second backoff refund. Production reachability is not demonstrated: Date.now() ordinarily returns a finite value and no remote clock control exists; this is a synthetic robustness defect against the stated fail-closed requirement. NaN happens to fail closed because the comparisons are false and the presence batch rejects (the waitUntil promise for recordPresence has no catch); -Infinity deletes nothing but still writes a NULL updated_at. The second unguarded sample has the same shape: pruneMemberRecords(db,Infinity) (server/member.ts:42-50, called at worker/app.ts:153) deleted one unexpired profile_requests row and one unexpired profile_history row (expires_at t+1d and t+30d) in a direct helper run, while t, NaN and -Infinity deleted 0 (M1 boundary, bounded by MEMBER_CLEANUP_MAX_ROWS per run). Fix: reject non-finite now at the scheduled entry (one guard before all three waitUntil calls) or at the top of recordPresence/pruneMemberRecords/pruneIndexProbes, logging a fixed 'unavailable' status, and add a scheduled-path regression asserting sessions/login_challenges/seat_presence rows are byte-identical after an Infinity/NaN/-Infinity cron sample. Keep ordinary finite expiry pruning unchanged.","line":59,"path":"source/server/presence.ts","reproduction":"Independent reproduction at exact pin 35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a, Linux, Node v24.21.0, npm ci --ignore-scripts with locked viem 2.56.9, real createWorker and migration-backed node:sqlite via tests/wallet-harness.mjs; no production endpoints or real wallets. From source/ run with node --input-type=module (or save as a .mjs file in source/):\n\nimport {setup,newAccount,fakeImd,fakeChain} from './tests/wallet-harness.mjs';\nimport {createWorker} from './worker/app.ts';\nconst t=1790596800000;\nfor(const first of [t+1,Infinity,NaN,-Infinity]){\n  const account=newAccount(),A=account.address.toLowerCase(),owners=[];owners[7]=A;\n  const w=setup({chain:fakeChain({owners:{7:A}}),imd:fakeImd({seats:{7:'707'},owners,online:[7]})});w.clock.set(t);\n  const b=w.browser();const v=(await b.signIn(account)).verify.status;\n  const rows=()=>({sessions:w.db.raw.prepare('SELECT count(*) n FROM sessions').get().n,challenges:w.db.raw.prepare('SELECT count(*) n FROM login_challenges').get().n,presence:w.db.raw.prepare('SELECT token_id,last_online_at,updated_at FROM seat_presence').all()});\n  const before=rows();let samples=0;\n  const sched=createWorker(w.gateway,w.chain.fetcher,()=>{samples++;return samples===1?first:t+1;},[]);\n  const pending=[];const saved=console.log;console.log=()=>{};\n  try{await sched.scheduled({scheduledTime:t+1,cron:'*/15 * * * *'},w.env,{waitUntil:p=>pending.push(p)});await Promise.allSettled(pending);}finally{console.log=saved;}\n  const after=rows();const s=await b.get('/api/auth/session');\n  console.log(JSON.stringify({first:String(first),verify:v,before,after,sessionAfter:s.status,body:await s.json()}));\n}\n\nOnly the first now() sample (the one recordPresence receives) is replaced; the member and probe cleanups receive finite t+1. Measured output (exit 0):\n- first=t+1 (finite control): verify 200; before {sessions:1,challenges:1}; after {sessions:1,challenges:1, presence:[{token_id:7,last_online_at:t,updated_at:t+1}]}; /api/auth/session 200 signedIn:true.\n- first=Infinity: verify 200; before {sessions:1,challenges:1}; after {sessions:0,challenges:0, presence:[{token_id:7,last_online_at:t,updated_at:null}]}; /api/auth/session 200 {signedIn:false}. The cron log still reports presence {written:1,...}.\n- first=NaN: rows unchanged, no presence row written, no presence log line (the recordPresence promise rejected inside waitUntil).\n- first=-Infinity: sessions/challenges unchanged; presence row written with updated_at:null.\nExpected under R10-N1: an invalid scheduled clock sample must not delete or write any durable row; the live session must remain readable (signedIn:true) and seat_presence.updated_at must stay finite. Actual: Infinity revokes all sessions and challenges and both infinities persist a non-finite updated_at. Same-evaluator finite control passes, so this is a real assertion-level difference, not a setup failure.","severity":"low","snippet":"  const housekeeping=[db.prepare(PRUNE_CHALLENGES).bind(now-DAY_MS,now-UNUSED_CHALLENGE_KEEP_MS),db.prepare(PRUNE_SESSIONS).bind(now-DAY_MS)];","title":"R10-N1 neighbor: nonfinite scheduled clock sample reaches presence housekeeping and deletes every live session and challenge"},{"citation":"resolved","description":"Merged from three identical specialist findings (audit_math, audit_permissions, audit_economics); each was independently re-executed here and reproduces. The candidate's R10-N1 fix rejects non-finite clock samples in the request lane (server/auth.ts lane closure sample() and reserveIndexProbe's Number.isFinite(now) guard), but the other writer of index_lane_probes, pruneIndexProbes(), validates only the deletion limit and binds the unchecked now into INDEX_PROBE_PRUNE ('... WHERE expires_at<=?1 ...'). The real Worker scheduled handler calls it with an unguarded now() at source/worker/app.ts:157. With now=Infinity every finite expires_at satisfies the predicate, so a still-live finite probe is deleted (up to the 200-row cap), refunding the mandatory 30-second backoff that the request path promised. The next finite request then calls the local 'chain:index:lane' limiter again and replaces the original probed_at/expires_at before the original deadline. This violates the scoped R10-N1 invariant that an existing finite probe keeps its bounded backoff without refund or timestamp refresh. The request-side admission defect from Report10 is fixed; this is a surviving same-table temporal neighbor and the unguarded helper is also present in the prior public source c2f21a9 (unclosed neighbor, not a new regression). No production clock control or ownership bypass is demonstrated; Date.now() is ordinarily finite. Fix: return early (no DELETE) when !Number.isFinite(now) in pruneIndexProbes, keep the existing 0-200 cap and finite expiry pruning, and add a scheduled-path regression asserting the live probe row and the subsequent lane-limiter count are unchanged after Infinity/NaN/-Infinity cron samples.","line":284,"path":"source/server/auth.ts","reproduction":"Independent reproduction at exact pin 35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a, Linux, Node v24.21.0, locked viem 2.56.9, real createWorker and migration-backed node:sqlite; no production endpoints or real wallets. (1) Minimal helper-level assertion, run from source/ with node --input-type=module: import assert from 'node:assert/strict'; import {openD1} from './tests/d1-sqlite.mjs'; import {pruneIndexProbes} from './server/auth.ts'; const t=1790596800000; for(const now of [t+1,NaN,-Infinity,Infinity]){const db=openD1(); db.raw.prepare('INSERT INTO index_lane_probes(scope_key,net,sub,probed_at,expires_at) VALUES(?,?,NULL,?,?)').run('net:unknown|','net:unknown',t,t+30000); const r=await pruneIndexProbes(db,now); console.log(String(now),JSON.stringify(r),db.raw.prepare('SELECT count(*) n FROM index_lane_probes').get().n);} Measured: t+1 -> {cleaned,deleted:0} remaining 1; NaN -> deleted 0, remaining 1; -Infinity -> deleted 0, remaining 1; Infinity -> deleted 1, remaining 0. Asserting remaining===1 for Infinity fails with ERR_ASSERTION (actual 0, expected 1). (2) End-to-end through the real scheduled entry point: sign in a synthetic EOA A owning offline seat 7 (fakeChain owners {7:A}, fakeImd seats {7:'707'}, owners[7]=A, online []), insert seat_presence(7,A,t-ONLINE_WINDOW_MS-1,t-ONLINE_WINDOW_MS-1) at t=1790596800000, set env.CHAIN_LIMITER.limit to record keys and return {success:false}. GET /api/me/home -> 200 recheck:'limited'; work {index:0,rpc:1,budget:1,lane:1}; index_lanes []; index_lane_probes [{scope_key:'net:unknown|',probed_at:1790596800000,expires_at:1790596830000}]. Build createWorker(w.gateway,w.chain.fetcher,clock,[]) with clock returning t+1,t+1,THIRD for the handler's three samples, call scheduled({scheduledTime:t+1,cron:'*/15 * * * *'},w.env,{waitUntil:p=>pending.push(p)}) and await Promise.allSettled(pending). Then set the request clock to t+1 and GET /api/me/home again. Measured: THIRD=t+1, NaN, -Infinity: cron log index_probe_cleanup {cleaned,deleted:0}; probe row unchanged after cron and after the second request; lane-limiter calls total 1; second response 200 limited. THIRD=Infinity: cron log index_probe_cleanup {cleaned,deleted:1}; probe rows [] after cron; second request 200 limited re-inserts {probed_at:1790596800001,expires_at:1790596830001}; lane-limiter calls total 2 within 1 ms; index requests 0, budget calls 1, ownerOf RPC 1 across both requests, no admitted lane, session unrevoked. Expected: the original row retained at t/t+30000 and only 1 lane-limiter call before t+30000. All runs exit 0 with no setup/EPERM failures; the invariant check printed INVARIANT VIOLATED only for Infinity.","severity":"info","snippet":"  try{return {status:'cleaned',deleted:(await db.prepare(INDEX_PROBE_PRUNE).bind(now,cap).run()).meta.changes??0};}","title":"R10-N1 neighbor: nonfinite scheduled prune refunds an unexpired 30-second index-probe backoff"}],"hash":"5b89f643d041f9b8bf008bbcd3a227eb910941e149ae93ec99e69999871500e2","nodeId":"172d0e5b-4bd7-4fab-a228-9fd4db5fef80","outcome":"completed","summary":"Review complete. Findings are in `.imd-findings.json` (2 findings, valid JSON, no tracked files changed).\n\n## Summary\n\nPin `35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a` verified: manifest SHA-256 matches `4c82cd86…7b2fc` and every SHA256SUMS entry checks. Fresh `npm ci --ignore-scripts` on Node v24.21.0 with locked viem 2.56.9. All three required commands exit 0: review check (28 files), `test:review` 715/715 (0 fail/cancelled/skipped/todo), artifact verifier 20/20. Independent stability repeats: `auth-audit9` 50/50, full supported suite 10/10 at 715/715 each.\n\nFive of six rows close on the exact source. R10-N1 is PARTIAL: the request-lane fix is correct, but the Worker's scheduled handler samples `now()` three times with no finite guard, and both the probe prune and the presence housekeeping fail open on `Infinity`.\n\n**SOURCE-CLOSURE: BLOCKED** (R10-N1 same-invariant neighbors reproduce; nothing else reopened).\n**RELEASE-READINESS: UNKNOWN** (offline synthetic only; no Cloudflare/D1/browser/provider/ERC-1271/WAF/limiter/process-death evidence).\n\n## Closure matrix\n\n| ID | Pin location | Reproduction | Measured result | Status |\n|---|---|---|---|---|\n| A10-L1 Low | `source/src/world/auth.ts:270-272, 311-313, 635-648, 676-680`; `authLifecycle.ts:102-117` | Ran `tests/auth-audit10.test.mjs` (12 tests: stop-B/stop-A/same-life-switch failed first cleanup ± discovery, lock→stop promotion, passive first observation preserving A then C→D cleanup, post-fence transport/503 with B and foreign-A cookie); lifecycle model tests. Read server `expectedNonce` path (`server/auth.ts:630-650`): revokes only the token-matching session, 409 otherwise. | 12/12 pass. `cleanupDone` consumes only on 2xx or post-fence conclusive 409; transport/5xx returns no retry (`!attemptObserved&&responseObserved`), so no loop. Discovery abandons only current-life owners with `lock-reconcile`, and `abandon()` cannot downgrade a stronger reason. | CLOSED (independent run of TEAM regression + code trace) |\n| A10-I1 Info | `source/server/ownership.ts:262-266` | `ownership-audit10` I1 tests, delays 0/1/2/5000 ms with 257 seats. | 257 retained when delay>0, eligible=1, size=s, recheck partial, `read_at`=t, checkedAt=t+delay, index/rpc/budget 1/2/1. | CLOSED |\n| A10-I2 Info | `source/server/ownership.ts:374-377`; `server/auth.ts:736` threads `clock` | I2 tests (sightings/characters × 0/1/2/5000 ms), inclusive 24h controls, nonfinite adjacent. | First and subsequent responses agree; fetchedAt/lastOnlineAt preserved; no lane/probe/index rows; nonfinite → 503 with no side effects. | CLOSED |\n| A10-I3 Info | `source/tests/auth-artifacts.mjs:12-31` | Independent persisted-bytes readback via `createArtifactStore` with the three required paths plus NBSP, `GET … private.log 200`, `GET … 200 private.log`, `route … private.log`, Windows drive, `.log` suffix, comma-joined path; controls. | All variants masked in nested/quoted/bare/key positions; exact routes, log line, route listing, network URL, relative ID preserved. Verifier H-S5 20/20. | CLOSED |\n| R10-N1 Info | Fix: `source/server/auth.ts:290, 761-770`. Gap: `server/auth.ts:284` via `worker/app.ts:157`; `server/presence.ts:59` via `app.ts:152`; `server/member.ts:45-49` via `app.ts:153` | Request path: N1 tests ×4 changes ×3 phases pass. Cron path: real `createWorker(...).scheduled` with one sample replaced. | Request lane: no Inf/NaN rows, finite probe keeps 30 s, +10m/+60m recover. Cron Infinity: live probe deleted (`deleted:1`), next request re-probes at t+1, lane-limiter calls 1→2. Cron Infinity on first sample: sessions 1→0, challenges 1→0, `/api/auth/session` → `signedIn:false`, `seat_presence.updated_at` NULL. Member prune Infinity deletes unexpired rows. Finite/NaN/-Infinity controls retain rows. | PARTIAL |\n| R10-N2 Info | `source/tests/auth-audit9.test.mjs:65-67` (`until` bounded 500×2 ms, assertion on timeout) | 50 single-file runs; 10 full runs. | 50/50 and 10/10, 11 and 715 tests each; original response/SQLite/logout/b","treeHash":null,"usage":{"cachedInputTokens":2197953,"inputTokens":610,"model":"claude-fable-5-1","outputTokens":33470,"runtime":"claude","turns":52,"wallClockMs":764727}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"7e929507773df661","findings":[],"hash":"5cbc89e063562f1fd0249c110bb7030e6bd3169d2494ca12495c19e25c844b52","nodeId":"172d0e5b-4bd7-4fab-a228-9fd4db5fef80","outcome":"failed","summary":"base commit unavailable: error: RPC failed; curl 92 HTTP/2 stream 3 was not closed cleanly: CANCEL (err 8)\nerror: 8212 bytes of body are still expected\nfetch-pack: unexpected disconnect while reading sideband packet\nfatal: early EOF\nfatal: fetch-pack: invalid index-pack output\nfatal: could not fetch 433a6756db693e99b484a325f8994fae09892c02 from promisor remote\n","treeHash":null,"usage":{"cachedInputTokens":0,"inputTokens":0,"model":null,"outputTokens":0,"runtime":"claude","turns":0,"wallClockMs":298786}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"4a019e19ac096894","findings":[{"citation":"resolved","description":"The request lane now rejects non-finite clock samples, but the independent scheduled probe cleanup still binds its now argument directly to INDEX_PROBE_PRUNE. With now=Infinity, every finite expires_at satisfies expires_at<=now. A still-live finite 30-second probe is deleted (up to the 200-row cron cap), so the next finite request can retry the location limiter and index immediately. This violates the scoped invariant that an existing finite probe retains its original bounded backoff without refund. Reachable from the real Worker scheduled entry at source/worker/app.ts:157. This is an Info synthetic invalid-clock robustness defect, not a demonstrated attacker-controlled production clock, ownership bypass, or fund loss. The original request-admission Infinity/stuck-lane reproduction is fixed; this is a surviving same-table temporal neighbor, also present in the earlier implementation. Reject non-finite cleanup timestamps before any DELETE and add a scheduled-path regression preserving unexpired rows and subsequent request counts.","line":284,"path":"source/server/auth.ts","reproduction":"Independently reproduced on exact 35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a, Linux Node24.21.0, npm-ci locked viem2.56.9, actual createWorker and migration-backed node:sqlite. Use tests/wallet-harness.mjs setup({chain:fakeChain({owners:{7:A}}),imd:fakeImd({seats:{7:\"707\"},owners:[...,A at index 7],online:[]})}), sign in a synthetic account A, and insert seat_presence(7,A,t-86400001,t-86400001), t=1790596800000. Set CHAIN_LIMITER to deny chain:index and chain:index:lane. GET /api/me/home returns 200 limited and stores index_lane_probes(net:unknown|,probed_at=t,expires_at=t+30000), with no admitted lane. Instantiate the real createWorker(w.gateway,w.chain.fetcher,clock,[]) over the same DB; clock returns [t,t,Infinity] for the three samples in scheduled(). Call scheduled({scheduledTime:t,cron:\"*/15 * * * *\"},env,{waitUntil:p=>jobs.push(p)}) and await all jobs. Presence/member cleanup use finite t; only probe cleanup receives Infinity. Expected: existing probe unchanged and no early retry. Actual: index_probe_cleanup reports deleted:1 and SELECT scope_key,probed_at,expires_at FROM index_lane_probes returns []. Restore/use finite t (no elapsed time), allow only chain:index:lane, and GET /api/me/home again. It returns 200 with no limited marker, writes index_lanes(net:unknown,NULL,t), and sends one index call. Across the two home requests: index/budget/RPC=1/1/1 and lane-limiter calls=2. Controls substituting finite t, NaN or -Infinity for that third cron sample preserve the exact probe row; second response remains 200 limited with index/budget/RPC=0/1/1, lane calls=1, and no admitted lane. All four concrete observations were asserted; command node --input-type=module exited 0. No production endpoints or real-wallet signatures were used. A second minimal node --input-type=module run asserted deepEqual(probeRowsAfterCron,probeRowsBeforeCron) and exited 1 ERR_ASSERTION: actual [] versus expected [{scope_key:\"net:unknown|\",probed_at:1790596800000,expires_at:1790596830000}]. This was an intentional negative reproduction, not a suite/setup failure.","severity":"info","snippet":"  try{return {status:'cleaned',deleted:(await db.prepare(INDEX_PROBE_PRUNE).bind(now,cap).run()).meta.changes??0};}","title":"R10-N1 neighbor: non-finite cron pruning refunds an unexpired index probe"}],"hash":"ad8e427da9125a7e0906adeaf62ab1641d5b3cf9667352b4e1feca5f0bf408fe","nodeId":"a6c5930b-e37e-4734-9246-aca75321e40d","outcome":"completed","summary":"**SOURCE-CLOSURE: BLOCKED. RELEASE-READINESS: UNKNOWN.**\n\nThe six original reproductions are fixed, but one **Info-level R10-N1 neighbor remains open**: scheduled cleanup accepts `Infinity` and deletes an unexpired finite probe, allowing an early lane/index retry. I recorded it in [the findings JSON](/home/seat8/.identitymd/work/63c31e2b-5d52-4a3b-a94c-21ef15f52e90/a6c5930b-e37e-4734-9246-aca75321e40d/.imd-findings.json). Source files remain unchanged.\n\nAll locations below reference candidate `35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a`. “CLOSED” means bounded source closure under the tested assumptions.\n\n| ID / severity | Exact-pin location | Reproduction | Independently measured fix and controls | Verdict |\n|---|---|---|---|---|\n| **A10-L1 / Low** | [Provider discovery](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/src/world/auth.ts#L307), [cleanup ownership](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/src/world/authLifecycle.ts#L102) | Hold committed B verify; fail first nonce logout before Worker; stop/restart; discover C; release verify. Repeat with replacement A and same-life switch. | Original nonce and revoking reason survive discovery. Two attempts finish with 204 for B or 409 preserving A. No passive address logout or old signed-in broadcast. Genuine C→D cleanup and lock→stop promotion pass. Repeated transport/503 failures retain responsibility without spinning; later lifecycle triggers retry. Independent same-address tests preserve the newer database row. | **CLOSED** |\n| **A10-I1 / Info** | [Post-await ranking](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/ownership.ts#L259) | With 257 registered seats, expire seats 1–256 during sightings I/O; keep 257 eligible. | At delays 1/2/5000 ms, retain 257: 256 selected, eligible=1, size=`s`, `partial`. Delay 0 preserves ID tie-breaking. Index `read_at=t` remains unchanged; index/budget/RPC=1/1/2. Independently denying discovery still retains 257 with `limited`, counts 0/1/2. | **CLOSED** |\n| **A10-I2 / Info** | [Final display sample](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/ownership.ts#L370), [live clock supplied](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/auth.ts#L733) | Delay sightings or later character enrichment by 0/1/2/5000 ms around the inclusive 24-hour boundary. | Initial/subsequent counts agree: true/true/false/false. Independent 1 ms sightings + 1 ms character delay also returns false. `fetchedAt` and persisted presence dates remain unchanged. Without characters: index/budget/RPC=0/0/0; configured characters add one character-index read and one assets-budget admission. | **CLOSED** |\n| **A10-I3 / Info** | [Complete route grammar](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/tests/auth-artifacts.mjs#L12) | Persist nested bare/quoted route-prefixed filenames, including spaces, parentheses, tabs and Unicode whitespace; read bytes back. | Required filenames mask completely. Exact allowed routes, queries, subroutes, URLs, relative identifiers and replay structure survive. Artifact verifier passes 20/20, including actual replay and Linux symlink/containment controls. H-S5 persisted 1,237 bytes with the recorded matching SHA-256. | **CLOSED** |\n| **R10-N1 / Info** | [Admission guards](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/auth.ts#L760); remaining defect: [probe pruning](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/auth.ts#L281) | Inject NaN/±Infinity/rollback after sightings, preflight, probe and limiter waits; inspect rows and recovery. Additionally inject In","treeHash":null,"usage":{"cachedInputTokens":2590336,"inputTokens":160846,"model":"gpt-6-astra","outputTokens":20565,"runtime":"codex","turns":8,"wallClockMs":684111}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"24282732aac890f7","findings":[{"citation":"resolved","description":"R10-N1 remains partial at the same durable-probe invariant. reserveIndexProbe and the request lane now reject nonfinite clocks, but pruneIndexProbes checks only the deletion limit and binds its unchecked now into expires_at<=?1. The actual Worker scheduled handler calls this helper at source/worker/app.ts:157. With Infinity, SQLite deletes a still-live finite reservation, refunding its mandatory 30-second backoff and allowing another local lane-limiter call immediately after the clock recovers. This is an invalid-clock resilience defect within the requested synthetic model, not a demonstrated production clock manipulation or ownership bypass. Reject nonfinite now before issuing the prune, retaining existing finite rows and timestamps; add a scheduled-cleanup regression alongside the admission checks. The unchecked scheduled helper is also present in the prior public source; this is an unclosed neighboring path, not a newly introduced production regression.","line":284,"path":"source/server/auth.ts","reproduction":"Independently executed at exact pin 35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a with Linux Node24.21.0, locked viem2.56.9, actual Worker and migration-backed node:sqlite. Using tests/wallet-harness.mjs setup/newAccount/fakeImd/fakeChain, give a synthetic signed-in A an offline registered seat7, and set CHAIN_LIMITER.limit to record its key and return success:false. At t=1790596800000, GET /api/me/home returns 200 limited and writes index_lane_probes(scope_key='net:unknown|',probed_at=t,expires_at=t+30000); index_lanes stays empty. Invoke createWorker(w.gateway,w.chain.fetcher, clock, []).scheduled with the same env/DB, where clock returns [t,t,Infinity] for the handler's three clock samples, and await all waitUntil promises. The first two finite samples isolate presence/M1 housekeeping; the third reaches the real probe-prune call. Actual probe rows become [] and cleanup reports deleted:1. Return the request clock to t+1 and GET /api/me/home again: another probe is written at t+1, expiry=t+30001, and chain:index:lane calls total2 within1ms. Expected: original row retained at t/t+30000 and only1 lane call. Identical finite t+1, NaN and -Infinity prune controls retain the original row and only1 lane call. All four runs: index upstream0, ownerOf RPC1, ordinary index budget1, no admitted lane; both home responses200 limited. No real endpoints/wallets used. Minimal confirming assertion, run with Node24 from source/: import assert from 'node:assert/strict'; import {openD1} from './tests/d1-sqlite.mjs'; import {pruneIndexProbes} from './server/auth.ts'; const db=openD1(),t=1790596800000; db.raw.prepare('INSERT INTO index_lane_probes(scope_key,net,sub,probed_at,expires_at) VALUES(?,?,NULL,?,?)').run('net:unknown|','net:unknown',t,t+30000); await pruneIndexProbes(db,Infinity); assert.equal(db.raw.prepare('SELECT count(*) n FROM index_lane_probes').get().n,1); Executed as node --input-type=module, exit1 ERR_ASSERTION (actual0 expected1).","severity":"info","snippet":"  try{return {status:'cleaned',deleted:(await db.prepare(INDEX_PROBE_PRUNE).bind(now,cap).run()).meta.changes??0};}","title":"Nonfinite scheduled prune refunds a live index-probe backoff"}],"hash":"cefd409fd5dde6f8151574febcb2cef40277287545da21e820c3d4a9d73002a3","nodeId":"553f3104-e566-4562-ab94-0a782e6c727d","outcome":"completed","summary":"**SOURCE-CLOSURE: BLOCKED. RELEASE-READINESS: UNKNOWN.**\n\nFive rows are closed within the tested scope. R10-N1 remains **PARTIAL**: request admission rejects nonfinite clocks, but scheduled pruning accepts `Infinity` and prematurely deletes an existing probe reservation. One substantiated Info finding is recorded in [.imd-findings.json](/home/imd/.identitymd/work/63c31e2b-5d52-4a3b-a94c-21ef15f52e90/553f3104-e566-4562-ab94-0a782e6c727d/.imd-findings.json). No source files were changed.\n\nAll source links below identify candidate `35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a`.\n\n| ID / severity | Exact-pin location | Reproduction and measured fix/control result | Closure |\n|---|---|---|---|\n| **A10-L1 / Low** | [Discovery](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/src/world/auth.ts#L308), [cleanup disposition](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/src/world/authLifecycle.ts#L102) | Held B verify → failed first nonce logout → stop/restart → discovery C → late verify retains the original cancellation reason and retries the same nonce. B-cookie cleanup returns 204; replacement-A returns 409 without revoking A. Same-life switches, C→D cleanup and lock→stop controls pass. Independent newer-same-address and repeated-503 probes also pass. | **CLOSED**, bounded. No passive first-observation address logout or old-verify acceptance observed. |\n| **A10-I1 / Info** | [Live ranking sample](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/ownership.ts#L259) | With 257 seats and delays 1/2/5000ms, seat257 survives both cuts: eligible=1, size=`s`, 256 selected, still partial. Delay0 preserves ID tie-breaking. Index `read_at` remains the original producer time. Independently refusing ordinary index discovery still retains257 with index/budget/RPC=0/1/2 and no lane. | **CLOSED**. Caps and proof dating preserved. |\n| **A10-I2 / Info** | [Final display clock](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/ownership.ts#L371), [route clock](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/auth.ts#L736) | Delays 0/1/2/5000ms around inclusive24h produce true/true/false/false consistently across initial/subsequent responses. Independent sightings1ms + character1ms also returns false twice. Original `fetchedAt` and persisted presence timestamps remain unchanged; character index1, RPC0. | **CLOSED**. These remain public display hints, not ownership authority. |\n| **A10-I3 / Info** | [Route/path grammar](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/tests/auth-artifacts.mjs#L12) | Persisted bytes mask the requested spaced filenames in nested, quoted and bare diagnostics. Allowed route/query/subroute, URL, relative identifiers and replay structure survive. Artifact verifier passes20/20, including actual Linux symlinks, input aliases, replacement and CLI containment. | **CLOSED**, under the controlled-root assumption. Windows junction behavior was not independently measured. |\n| **R10-N1 / Info** | [Admission guards](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/auth.ts#L760), **[unchecked prune](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/auth.ts#L284)** | Admission-side NaN/±Infinity and rollback controls pass, with finite probe timestamps retained and +10m/+60m recovery. **Scheduled `Infinity` pruning deletes an unexpired finite probe**, allowing another lane-limiter call at +1ms. | **PARTIAL**. Original poisoning path closes; the same-invariant no-refund neighbor remains open. |\n| **R10-N2 / Info** | [Semantic completion gate](https://github.com/tungweb3/imd-embe","treeHash":null,"usage":{"cachedInputTokens":2835584,"inputTokens":168490,"model":"gpt-6-astra","outputTokens":21079,"runtime":"codex","turns":7,"wallClockMs":679574}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"163f8bc7d28274e2","findings":[{"citation":"resolved","description":"The request-side fix rejects nonfinite samples before reserving a lane/probe, but the other writer of index_lane_probes, pruneIndexProbes(), validates only limit and binds now without a finite check. The actual Worker scheduled entry point calls it with now() at source/worker/app.ts:157. SQLite considers every finite expires_at <= Infinity, so this path deletes an unexpired finite probe and refunds its promised 30-second backoff. The next ordinary request can call the local lane limiter again and replace the original probe timestamp before the original deadline. This is a same-invariant R10-N1 neighbor, not the original Inf-insertion defect: invalid admission is fixed, but preservation of existing finite reservations is incomplete. Independently reproduced on exact pin 35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a with Node24.19.0, locked viem2.56.9, actual Worker and migration-backed SQLite, including the real scheduled entry point. Date.now() ordinarily produces a finite value; no remote clock control or production exploit is demonstrated. Add a nonfinite guard before any prune SQL and a regression proving existing finite rows and subsequent limiter counts remain unchanged; retain ordinary finite expiry pruning and the deletion cap.","line":284,"path":"source/server/auth.ts","reproduction":"From source/, run Node24 with --input-type=module and import setup/newAccount/fakeImd/fakeChain from ./tests/wallet-harness.mjs, createWorker from ./worker/app.ts, and ONLINE_WINDOW_MS from ./server/ownership.ts. Create a synthetic EOA, registered offline seat 7 owned by it in both fakeImd and fakeChain, and a real browser session. Set CHAIN_LIMITER.limit to record keys and return {success:false}. At t=1790596800000 insert seat_presence(7,address,t-ONLINE_WINDOW_MS-1,t-ONLINE_WINDOW_MS-1). GET /api/me/home returns 200 limited, with index_lanes empty and index_lane_probes=(scope_key net:unknown|,probed_at 1790596800000,expires_at 1790596830000). Construct the actual scheduler with createWorker(w.gateway,w.chain.fetcher,()=>++samples===3?Infinity:t+1,[]); call scheduled({scheduledTime:t+1,cron:'*/15 * * * *'},w.env,{waitUntil:p=>pending.push(p)}) and await all pending promises. The first two finite samples keep presence/member housekeeping unchanged; the third sample reaches the actual probe cleanup. Actual: index_probe_cleanup reports cleaned/deleted=1 and SELECT scope_key,probed_at,expires_at FROM index_lane_probes returns []. Restore the request clock to t+1 and GET /api/me/home again. It returns 200 limited and re-inserts probed_at=1790596800001/expires_at=1790596830001; total chain:index:lane calls rise from 1 to 2. Expected: the original finite row survives the invalid cleanup, retaining the original dates, and total lane calls remain 1 until t+30000. In both executions chain:index budget calls=1, index requests=0, ownerOf RPC=1, checkedAt=t, and the session remains unrevoked. Finite scheduler control (all three samples t+1) deletes 0, preserves the original row, and leaves lane calls=1. Direct helper controls with NaN and -Infinity likewise delete 0; Infinity alone deletes the finite row. All probe runs exited 0 with assertions confirming these measured differences. No source or test file was modified. A separate expected-invariant run through the same real scheduler used assert.deepEqual(probes(),before,\"nonfinite scheduled time must not refund a finite unexpired 30-second probe\") and exited 1 with ERR_ASSERTION (actual [], expected the unexpired row); this was a genuine assertion failure, not setup/EPERM.","severity":"info","snippet":"  try{return {status:'cleaned',deleted:(await db.prepare(INDEX_PROBE_PRUNE).bind(now,cap).run()).meta.changes??0};}","title":"R10-N1 neighbor: nonfinite scheduled cleanup refunds an unexpired probe"}],"hash":"daec9d289214d5dc5a09c0a2878c014875aec8db8a6264d7228ccaa991b4109d","nodeId":"acdd4011-f304-487f-97bf-596a2f85ec9c","outcome":"completed","summary":"**SOURCE-CLOSURE: BLOCKED. RELEASE-READINESS: UNKNOWN.**\n\nFive closure rows passed the bounded checks. R10-N1 remains **PARTIAL**: admission rejects nonfinite clocks, but scheduled cleanup accepts `Infinity` and deletes an unexpired finite probe, bypassing its 30-second backoff. One substantiated **Info** finding is recorded in [.imd-findings.json](/home/seat19/.identitymd/work/63c31e2b-5d52-4a3b-a94c-21ef15f52e90/acdd4011-f304-487f-97bf-596a2f85ec9c/.imd-findings.json). No reviewed source was changed.\n\n| ID / severity | Exact-pin location | Reproduction and measured result | Closure |\n|---|---|---|---|\n| **A10-L1 / Low** | [Discovery handling](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/src/world/auth.ts#L307), [cleanup ownership](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/src/world/authLifecycle.ts#L102) | Held B verification → failed nonce cleanup → stop/restart → discovery C → late verification retained the original revocation reason. Two nonce attempts ended in 204 for B or 409 with replacement A; no passive address logout. Current C→D cleanup and lock→stop promotion passed. Repeated transport/503 uncertainty retained responsibility without an immediate retry loop. | **CLOSED, bounded.** Additional same-address/newer-session checks preserved the newer database row and fenced old callbacks. |\n| **A10-I1 / Info** | [Candidate ranking](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/ownership.ts#L259) | With 257 seats and delayed sightings, expired seats 1–256 no longer displaced eligible 257. Positive-delay cases returned 256 candidates, eligible=1, size=`s`, partial; index `read_at` remained unchanged. Successful discovery used index/budget/RPC counts **1/1/2**. Independent refused-discovery control retained 257 with **0/1/2**, no lane; a 30,000 ms proof delay failed closed. | **CLOSED, bounded.** Cap, tie-breaks, producer dates and proof deadline remained enforced. |\n| **A10-I2 / Info** | [Final display clock](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/ownership.ts#L370) | Sightings and character delays of 0/1/2/5000 ms produced `counts=true,true,false,false` from initial age 24h−1 ms; subsequent responses agreed. Producer timestamps stayed unchanged. Independent combined awaits crossed the boundary correctly. Character control used one assets-budget/index request and zero RPCs. | **CLOSED, bounded.** Public hints remained separate from verified ownership. |\n| **A10-I3 / Info** | [Route-token masking](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/tests/auth-artifacts.mjs#L12) | Read-back tests masked nested bare/quoted spaced filenames while preserving routes, URLs, relative identifiers and replay structure. An independent identical 360-case persisted fixture found **72 bare-path leaks on the prior public module, zero on this candidate**. Artifact verifier passed 20/20, including real Linux symlinks and replay containment. | **CLOSED, bounded.** Windows junction behavior was not independently measured. |\n| **R10-N1 / Info** | [Admission guards](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/auth.ts#L760), [unguarded prune](https://github.com/tungweb3/imd-ember-world-review/blob/35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a/source/server/auth.ts#L281) | Request-side NaN/±Infinity/rollback cases preserved finite probe dates, avoided nonfinite rows and recovered at +10m/+60m. **Neighbor failure:** actual scheduled cleanup receiving `Infinity` deleted a finite unexpired probe; a request 1 ms later called the lane limiter again and replaced its timestamps. | **PARTIAL.** Original insertion defect is fixed; invalid-clock deletion still violates the same backoff inva","treeHash":null,"usage":{"cachedInputTokens":3085696,"inputTokens":197221,"model":"gpt-6-astra","outputTokens":22154,"runtime":"codex","turns":7,"wallClockMs":713726}}],"verification":[]}