{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"3ffb2bf9-fe8c-4433-aa15-333f218775bb","kind":"audit","nodes":[{"acceptedSubmissionHash":"803ff7702760baaa1f73087ffd4ffd74e800df934166b1ec9e0fdc65a5d11062","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_economics","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"a33f6da4239de819b983e4f275bc3153d1afeaab88c81bb98dc5163394179864","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_flow","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"33d044b5b6f3aebd2a3644abbc01635cb14cbb942b0222d2af370588bb35cab7","dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","tools":[]},"key":"audit_judge","kind":"code","role":"review","skillHash":"3014f1ea5961918ca059453a484bf4c8bcbbfc2248dbe31d94ac7c5cdf8f50bd","skillId":"audit-judge","state":"accepted"},{"acceptedSubmissionHash":"925684888386c2a8abcc612c39850d21bf27f2c5c51d03ab2abf635af2dfb866","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_math","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"3688f2176d8e9503a37de1e564b3107fa969ca299526b594608d828b1ac0bf20","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_permissions","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"}],"objective":"IMD Ember World - Audit12 source closure, World only\n\nExact immutable review snapshot: https://github.com/tungweb3/imd-ember-world-review/tree/2f21b74cf61fe8fed9e3700d082b2dab38904b33\nPublic parent: 35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a. Private TEAM source pin: 3a1ea7d0cabd40aaf1bd171d64fa64edeb6a2548 (not a request for private access).\nPeriod: this fixed snapshot prepared October 6, 2026 Taiwan time, compared with the latest completed Audit11/Report11.\n\nQuestion: Are the two remaining Audit11 scheduled-clock findings closed in this exact source without regressions in the previously closed Auth, ownership, Member M1, artifact or request-lane boundaries?\n\nUnofficial community project; NO Solidity in scope. TypeScript Cloudflare Worker / React SIWE; Member M1 writes persistent public profiles, so World is not wholly read-only. Genesis mint/contracts, Ember Coin functionality, 3D models/media/full frontend and live deployment are excluded. Use source/ and Submission12/FinalClosure/ as delivered; do not infer withheld runtime configuration or production state.\n\nCurrent closure matrix: exactly two rows.\n1. A11-L1 (Low): scheduled non-finite clock reaching destructive housekeeping. Check NaN, +Infinity and -Infinity at EACH of the three sampled positions. All three samples must be finite before any DB helper, SQL or waitUntil work starts. Verify sessions, challenges, presence, member requests/history, probes/lanes/candidates and total DB changes unchanged; signed cookie stays readable after return to finite time. No partial cleanup may occur before a later invalid sample.\n2. A11-I1 (Info): non-finite clock deleting a live 30-second probe, refunding backoff and admitting another lane request. Verify probe timestamps, budget, lane acquisitions and RPC calls at t+1ms remain unchanged after invalid scheduled input. Trace refused-lane probe retention as well as successful work. Confirm finite recovery at +10m/+60m.\n\nOnly worker/app.ts changes production behavior. tests/scheduled-audit11.test.mjs is added; review runner registration/count tests are updated. Helpers, SQL/schema/migrations, dependencies, Auth lifecycle, ownership and request-lane implementation are unchanged. The previous six issues are previously closed unchanged context; challenge any regression you reproduce, regardless of severity.\n\nFinite controls must preserve three distinct advancing clock inputs, strict presence vs inclusive member/probe expiry boundaries, independent 200-row cleanup caps, independent missing-schema jobs, and no-DB no-clock behavior. A single shared finite timestamp would change existing helper inputs and is not equivalent.\n\nSources: README.md, Submission12/REVIEW_INPUTS.md, Submission12/BOUNDARY_CHECK.json, Submission12/FinalClosure/CLOSURE_MATRIX.md, TEST_RESULTS.json, REVIEWER_EVIDENCE.json, SOURCE_MANIFEST.json, BUILD_DEPLOYMENT.json, SERVED_READBACK.json, and manifests/submission12-published-source.json; resolve these at the exact containing pin above. Prior final Audit11: https://github.com/Identity-md/research/blob/e7c4bb596a725863a8c23992926f6d2c59040005/jobs/63c31e2b-5d52-4a3b-a94c-21ef15f52e90/files/AUDIT.md\nPrior Report11: https://github.com/Identity-md/research/blob/193d49fca202162f17206af81aa8db6f1f7bda48/jobs/260746ad-ac5f-4013-89e1-2d70eb6dfc47/files/artifacts/report.md\n\nReproduce offline from a clean exact checkout using real Node24.x, locked viem2.56.9 and migration-backed node:sqlite. In source/: npm ci --ignore-scripts; node scripts/review-tests.mjs --check; node --test --test-reporter=tap tests/scheduled-audit11.test.mjs; npm run test:review; node scripts/verify-artifact-closure.mjs. Supported runner selects29 files and clears inherited *_SOURCE selectors. Real Windows symlink permission is needed; EPERM is a failed/unavailable prerequisite, not a PASS. Do not replace crypto/Worker/SQLite, remove assertions, hide skips or insert arbitrary waits.\n\nTEAM measurements, not reviewer reproduction: target13/13; supported review728/728; private full1778/1778; artifact20/20; fresh private728/728+20/20; typecheck exit0. Final committed public checkout was freshly installed and measured preflight29, target13/13, review728/728, artifact20/20; zero failed/skipped/cancelled/todo. Public commit/object/content privacy passed316 text files,315 checksums,147 selected sources (131 exact,16 masked files,57 preserved mask lines), zero private commit intersection and zero unreachable stored objects. Raw private receipts are withheld. Public metadata records the earlier nine-stage phase; later same-pin public tests are additional TEAM records, not self-certifying committed verdicts.\n\nCalibration: identical published13-test evaluator on the unpatched baseline produced4 passes and9 actual assertion failures. A separate private offline-probe control produced1 candidate pass and1 baseline assertion failure, measuring old third-Infinity probe deletion/lane reacquisition. The combined fixture has an online owned seat for presence observability, which can mask extra baseline lane admission; do not conflate it with that separate private control or claim all its bytes were published.\n\nNative cleanup provider still reports BLOCK on manual-only update-coverage REVIEW, with sync-unconfigured and README-version NOT_CHECKED; no native FAIL. This is explicitly retained as a bounded source-only exception, not provider PASS or release approval. No production deployment/readback occurred; full frontend/browser/production D1, secrets, bindings, WAF, limiter and upstream behavior remain unmeasured release gates. Do not contact production, request private data, use real wallets/signatures, transact, pay, deploy or create jobs. Public repository/report reads and locked dependency downloads are permitted.\n\nOutput: concise English Markdown, roughly1200-1800 words plus exactly two current closure rows and an evidence appendix. Rank any reproduced regression. For each row cite containing-pin source lines, reproduction/order, expected/actual mutations, SQL/tasks/RPC/budget/lane counts and residual bounded impact. Record commands/exits/errors/skips/shims and checks you could not run. Give SOURCE-CLOSURE and RELEASE-READINESS separately as PASS/BLOCKED/UNKNOWN with rationale. Separate reviewer measurements, TEAM claims, inference and unknowns. Completed/accepted means output delivery; tests, Low/Info labels and acceptance do not certify safety, endorsement, zero vulnerabilities or fund security.","parentJobId":null,"planHash":"a75910af254b6122ea96f2ab0d5efb58c1f9f78b2d02e5ac80d14421f0023910","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"3ffb2bf9-fe8c-4433-aa15-333f218775bb","publication":{"commit":null,"deliveredAt":null,"repoUrl":null},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[{"agentId":"52164","feedbackHash":"420b032d835d877b02e02d2765d8d2445578119ce9df8dfc8e728ca5bb365f7e","nodeKey":"audit_economics","submissionHash":"803ff7702760baaa1f73087ffd4ffd74e800df934166b1ec9e0fdc65a5d11062","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"52166","feedbackHash":"97ec7c760af54e943112154ca650abacd1d237618aad66b36db7bcd8e4af1070","nodeKey":"audit_flow","submissionHash":"a33f6da4239de819b983e4f275bc3153d1afeaab88c81bb98dc5163394179864","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51307","feedbackHash":"0fa8b5b9fda2b48fae6494bc27bef0e02674ae3014f04368a4c2af2484a52cab","nodeKey":"audit_judge","submissionHash":"33d044b5b6f3aebd2a3644abbc01635cb14cbb942b0222d2af370588bb35cab7","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51479","feedbackHash":"51ca2ea280a59523eac696630e902a96e1d4cdebdd261eaffe7ba2768bf6d5ba","nodeKey":"audit_math","submissionHash":"925684888386c2a8abcc612c39850d21bf27f2c5c51d03ab2abf635af2dfb866","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51741","feedbackHash":"be4b5aa2bf494a497dbe7ebc9e7dc2971ea8f7e7bd39daecf905ca374173b8e0","nodeKey":"audit_permissions","submissionHash":"3688f2176d8e9503a37de1e564b3107fa969ca299526b594608d828b1ac0bf20","tag1":"review:submission","tag2":"acceptance-v2","value":1}],"site":null,"snapshotHash":"fd548972f7bd358c6e472c50777ee5bb03cddb5c9a288691ab1021a36321bfc6","state":"completed","submissions":[{"artifacts":[],"attempt":1,"bundleHash":null,"device":"51908b9b0306f441","findings":[],"hash":"33d044b5b6f3aebd2a3644abbc01635cb14cbb942b0222d2af370588bb35cab7","nodeId":"0a62a331-d690-43f2-b7d8-45b223b0d328","outcome":"completed","summary":"**SOURCE-CLOSURE: PASS, bounded to A11-L1 and A11-I1. RELEASE-READINESS: UNKNOWN.** Both specified non-finite clock findings are closed at `2f21b74cf61fe8fed9e3700d082b2dab38904b33`. I reproduced no regression in the affected Auth, ownership, Member M1, artifact, or request-lane boundaries.\n\nThe two specialist reports describe the same unchanged finite-clock behavior. I reproduced their material effects but do not retain them as violations of these explicitly non-finite closure requirements. The required [.imd-findings.json](/home/seat15/.identitymd/work/3ffb2bf9-fe8c-4433-aa15-333f218775bb/0a62a331-d690-43f2-b7d8-45b223b0d328/.imd-findings.json) contains `{\"findings\":[]}`. No source or configuration files were changed.\n\nThe controlling comparison is the public parent `35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a`. Audit11 identified the two scheduled-path defects after the earlier six mechanisms were assessed; Report11’s bounded conclusion about those earlier mechanisms does not negate Audit11’s subsequent findings. The private source pin is provenance metadata, not independently inspected source. [Audit11](https://github.com/Identity-md/research/blob/e7c4bb596a725863a8c23992926f6d2c59040005/jobs/63c31e2b-5d52-4a3b-a94c-21ef15f52e90/files/AUDIT.md), [Report11](https://github.com/Identity-md/research/blob/193d49fca202162f17206af81aa8db6f1f7bda48/jobs/260746ad-ac5f-4013-89e1-2d70eb6dfc47/files/artifacts/report.md).\n\nReviewer reproduction used Linux, real Node **v24.21.0**, locally installed locked **viem 2.56.9**, the actual Worker, synthetic identities/upstreams, and migration-backed `node:sqlite`. No production endpoints, real wallets, deployment, or private data were used.\n\nFor the measurements below, `T=1790596800000`. Work counts are **index requests / ownership Multicall RPCs / index-budget calls / lane-limiter calls**. Sign-in activity precedes that measurement. Lane-limiter calls are distinguished from admitted database lane rows.\n\n| Current finding | Reproduction, expected versus actual, and disposition |\n|---|---|\n| **A11-L1 — Low: scheduled non-finite housekeeping** | **CLOSED.** The handler collects three separate samples before invoking any helper; any non-finite sample returns immediately. For each position in `[T+1,T+2,T+3]`, replacing that position with `NaN`, `Infinity`, or `-Infinity` produced the expected unchanged database snapshot: sessions **2→2**, challenges **2→2**, presence **1→1**, member requests/history **2→2 each**, probes **2→2**, lanes/candidates **1→1 each**. All nine cases had **0 Worker SQL prepares, 0 batches, 0 tasks, 0 upstream calls, and 0 total-change delta**. Thus a later invalid sample cannot follow partial cleanup. After returning to finite request time, the signed cookie remained readable and home returned 200. Work stayed **0/1/1/1**. The original effects—forced reauthentication and premature deletion of retained records—were absent under the specified inputs. [Guard, lines 150–163](https://github.com/tungweb3/imd-ember-world-review/blob/2f21b74cf61fe8fed9e3700d082b2dab38904b33/source/worker/app.ts#L150-L163); [regression, lines 80–113](https://github.com/tungweb3/imd-ember-world-review/blob/2f21b74cf61fe8fed9e3700d082b2dab38904b33/source/tests/scheduled-audit11.test.mjs#L80-L113). |\n| **A11-I1 — Info: premature probe deletion/backoff refund** | **CLOSED.** Independently keeping seat 7 offline, I created a refused-lane probe at **T**, expiring **T+30000**, then exercised all nine invalid sample combinations. Cron performed **0 SQL prepares/batches/tasks/mutations**; the +1 ms request preserved both timestamps and work **0/1/1/1**, with **0 admitted lane rows**. Nine additional admitted-lane cases denied the ordinary index budget but allowed `chain:index:lane`: the probe and **1 admitted lane row** remained unchanged, and work stayed **1/1/1/1**. On the parent, third-sample Infinity deleted the live probe and the +1 ms request recreated it at **T+1/T+30001**, increasing lane-limiter calls ","treeHash":null,"usage":{"cachedInputTokens":1532928,"inputTokens":135545,"model":"gpt-6-astra","outputTokens":15577,"runtime":"codex","turns":7,"wallClockMs":427637}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"523a0aade61e8902","findings":[],"hash":"3688f2176d8e9503a37de1e564b3107fa969ca299526b594608d828b1ac0bf20","nodeId":"ccf768d2-f2e5-43ce-940d-dc7935e8c778","outcome":"completed","summary":"**SOURCE-CLOSURE: PASS, bounded to this snapshot and the two scheduled-clock findings. RELEASE-READINESS: UNKNOWN.** I reproduced both closures and found no substantiated regression in the affected Auth, ownership, Member M1, artifact or request-lane boundaries.\n\nThe required [.imd-findings.json](/home/imd/agents/1571/data/work/3ffb2bf9-fe8c-4433-aa15-333f218775bb/ccf768d2-f2e5-43ce-940d-dc7935e8c778/.imd-findings.json) contains `{\"findings\":[]}`. No tracked repository file was changed.\n\nThe reviewed public identity is `2f21b74cf61fe8fed9e3700d082b2dab38904b33`. I compared its source with public parent `35ace952824ebf711fd9fa6cb7ea1cc83b75cd6a`, read the latest [Audit11](https://github.com/Identity-md/research/blob/e7c4bb596a725863a8c23992926f6d2c59040005/jobs/63c31e2b-5d52-4a3b-a94c-21ef15f52e90/files/AUDIT.md) and [Report11](https://github.com/Identity-md/research/blob/193d49fca202162f17206af81aa8db6f1f7bda48/jobs/260746ad-ac5f-4013-89e1-2d70eb6dfc47/files/artifacts/report.md), and treated private pin `3a1ea7d…` only as recorded provenance.\n\nThe comparison confirmed exactly three changed existing source files and one added test. Only `worker/app.ts` changes production behavior. Helpers, SQL, migrations, dependencies, Auth lifecycle, ownership and request-lane implementation are byte-identical to the public parent.\n\n**Current closure matrix — exactly two rows**\n\nHere, `t = 1790596800000`. Work counters distinguish lane-limiter calls from successfully persisted lane reservations.\n\n| Finding | Reproduction, expected versus actual, and evidence | Closure and bounded impact |\n|---|---|---|\n| **A11-L1 — Low** | Establish a synthetic signed-in session and M1 member; seed expired and live housekeeping records. Replace each position in `[t+1,t+2,t+3]` independently with `NaN`, `+Infinity` and `-Infinity`: nine cases. Expected: no helper, SQL, task or mutation before validating every sample. Actual: **3 samples, 0 SQL preparations, 0 batches, 0 tasks, 0 upstream calls, 0 total DB changes** in every case. Exact row snapshots remained equal; the sign-in cookie remained readable at finite time. Index/RPC/budget/lane-call totals stayed **0/1/1/1**. The controlling [guard and dispatch, lines 151–163](https://github.com/tungweb3/imd-ember-world-review/blob/2f21b74cf61fe8fed9e3700d082b2dab38904b33/source/worker/app.ts#L151-L163) precede all persistent work; [test lines 80–112](https://github.com/tungweb3/imd-ember-world-review/blob/2f21b74cf61fe8fed9e3700d082b2dab38904b33/source/tests/scheduled-audit11.test.mjs#L80-L112) exercise ordering and recovery. | **CLOSED, bounded.** Later invalid samples cannot permit earlier partial cleanup. On the parent, first-position Infinity deleted both sessions and challenges, produced **10 DB changes**, and returned `signedIn:false`; second-position Infinity deleted both live/expired member-request and history records. Those behaviors were absent here. Persistent invalid time postpones housekeeping; this does not establish production clock reliability. |\n| **A11-I1 — Info** | With owned seat 7 offline and its sighting older than 24 hours, create a live probe at **t / t+30,000** through `/api/me/home`. Invoke invalid scheduled input, then request home at **t+1 ms**. In nine refused-lane and nine admitted-lane cases, actual probe timestamps remained unchanged. Invalid cron performed **0 SQL, batches, tasks, upstream calls and DB changes**. Refused totals stayed index/RPC/budget/lane-calls/admitted-rows **0/1/1/1/0**; admitted totals stayed **1/1/1/1/1**. See the [scheduled guard](https://github.com/tungweb3/imd-ember-world-review/blob/2f21b74cf61fe8fed9e3700d082b2dab38904b33/source/worker/app.ts#L151-L163), [probe persistence, lines 264–294](https://github.com/tungweb3/imd-ember-world-review/blob/2f21b74cf61fe8fed9e3700d082b2dab38904b33/source/server/auth.ts#L264-L294), and [lane ordering, lines 760–775](https://github.com/tungweb3/imd-ember-world-review/blob/2f21b74cf61fe8fed9e3700d082b2dab38904b33/source/se","treeHash":null,"usage":{"cachedInputTokens":1740800,"inputTokens":149862,"model":"gpt-6-astra","outputTokens":13001,"runtime":"codex","turns":5,"wallClockMs":374294}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"63458a1bd2b2d376","findings":[{"citation":"resolved","description":"Not a regression and not a reopening of the literal A11-L1/A11-I1 rows: NaN, +Infinity and -Infinity are blocked at all three sample positions (reviewer-reproduced, zero SQL/tasks/mutations). This is the surviving same-invariant neighbour of those rows; the unpatched parent 35ace95 behaves identically for these inputs.\n\nThe new entry guard (worker/app.ts:153-156) defines an invalid housekeeping clock as 'not Number.isFinite' only. Any finite sample that is not a plausible epoch-millisecond time passes it and is bound unchanged into the same unchanged helpers: PRUNE_SESSIONS / PRUNE_CHALLENGES (server/presence.ts:59, 'expires_at<?1' with ?1=now-DAY_MS), pruneMemberRecords (server/member.ts:46-49, 'expires_at<=?1') and INDEX_PROBE_PRUNE (server/auth.ts:269-270,284, 'expires_at<=?1'). A finite value larger than every stored expiry is therefore exactly as destructive as +Infinity was in Audit11: sample 1 deletes all sessions and login challenges (a signed-in cookie then reads signedIn:false and /api/me/home is 401), prunes index_lanes/index_candidates, and with an online roster persists seat_presence.updated_at=1.7976931348623157e308; sample 2 deletes unexpired profile_requests/profile_history rows (up to the 200-row cap each); sample 3 deletes the live 30-second index probe so the request at t+1 ms calls the 'chain:index:lane' limiter a second time and rewrites probed_at/expires_at. No 'invalid_clock' line is logged. Inputs that reproduce: Number.MAX_VALUE, 1e21, 8.64e15+1 (one past the largest valid ECMAScript time value), 2**53, t*1000 (a microsecond-unit clock) and t+100 years. Backward finite values (0, t-1 day) delete nothing extra but overwrite seat_presence.updated_at with the regressed value.\n\nReachability is the same as Audit11 stated for the non-finite case: production wires createWorker with the default Date.now (worker/index.ts:5), which returns a finite integer, and no remote clock control exists. The trigger is an injected or defective clock source, so this is a robustness defect against the stated fail-closed housekeeping invariant, bounded per run by the helpers' caps (sessions/challenges/lanes/candidates uncapped; M1 and probe deletes 200 rows each). Severity mirrors the Low that Audit11 gave the identical session-deletion effect; the sample-3 lane refund alone is Info.\n\nThe published regression (tests/scheduled-audit11.test.mjs:80) only enumerates NaN/Infinity/-Infinity, so nothing in the 29-file runner exercises a finite implausible sample.\n\nFix (keeps finite behaviour, helpers and the three distinct samples): tighten the predicate at the same entry guard, e.g. require Number.isSafeInteger(x) && x>0 && x<=8.64e15 for each sample (closes MAX_VALUE, 1e21, 8.64e15+1, 2**53, 0 and negatives). That range check alone does not catch a microsecond-unit or far-future clock; closing those needs a reference, and the handler already receives one it ignores (_controller.scheduledTime, worker/app.ts:150): additionally reject any sample further than a small bound (for example one cron period) from a finite scheduledTime, and reject samples that go backwards relative to the previous one, as the request lane already does (server/auth.ts:764). Extend the scheduled regression with the finite cases below, asserting byte-identical rows, zero SQL/tasks and lane count 1.","line":154,"path":"source/worker/app.ts","reproduction":"Reviewer-run at exact pin 2f21b74cf61fe8fed9e3700d082b2dab38904b33 on Linux, Node v24.19.0, npm ci --ignore-scripts (locked viem 2.56.9), real createWorker and migration-backed node:sqlite via tests/wallet-harness.mjs; no production endpoints, real wallets or shims. From source/ pipe the script below into `node --input-type=module` (exit 0). It signs in a synthetic EOA owning offline seat 7 at t=1790596800000, makes CHAIN_LIMITER refuse (first /api/me/home -> 200, live probe {probed_at:t,expires_at:t+30000}, lane-limiter calls 1), then runs the real scheduled handler with samples [t+1,t+1,t+1] where one position is replaced, then reads /api/auth/session and requests /api/me/home at t+1 ms.\n\nMeasured on the candidate:\n- control, sample1=t+1: sessions 1->1, challenges 1->1, probe unchanged, lane 1->1, signedIn true, home 200.\n- sample1=Number.MAX_VALUE: sessions 1->0, challenges 1->0, signedIn false, home 401; no invalid_clock log.\n- sample1=8640000000000001 (8.64e15+1): sessions 1->0, challenges 1->0, signedIn false, home 401.\n- sample1=1790596800000000 (t*1000, microseconds): sessions 1->0, challenges 1->0, signedIn false, home 401.\n- sample3=Number.MAX_VALUE: sessions 1->1, probe row deleted by the cron then re-created by the t+1 ms request as {probed_at:t+1,expires_at:t+30001}, 'chain:index:lane' calls 1->2, home 200.\n- sample3=t*1000: same as the previous line (lane 1->2, probe refreshed to t+1/t+30001).\nExpected under the A11-L1/A11-I1 invariant (an implausible scheduled clock sample must not start destructive housekeeping): sessions/challenges 1->1, signedIn true, probe {t,t+30000} retained, lane calls 1->1, and a fixed invalid_clock status. Actual: as listed. The unpatched parent 35ace95 prints the same six lines, so the candidate neither introduces nor closes this. A wider reviewer probe over all three positions also measured sample2=Number.MAX_VALUE deleting the unexpired profile_requests row (expires t+1d) and profile_history row (expires t+30d), 2->0 each, and with an online roster seat_presence.updated_at=1.7976931348623157e+308 persisted.\n\nScript:\nimport {setup,newAccount,fakeImd,fakeChain} from './tests/wallet-harness.mjs';\nimport {createWorker} from './worker/app.ts';\nimport {ONLINE_WINDOW_MS} from './server/ownership.ts';\nconst t=1790596800000;\nfor(const [pos,bad] of [[0,t+1],[0,Number.MAX_VALUE],[0,8.64e15+1],[0,t*1000],[2,Number.MAX_VALUE],[2,t*1000]]){\n  const account=newAccount(),A=account.address.toLowerCase(),owners=[];owners[7]=A;\n  const w=setup({chain:fakeChain({owners:{7:A}}),imd:fakeImd({seats:{7:'707'},owners,online:[]}),collections:[]});w.clock.set(t);\n  const b=w.browser();await b.signIn(account);\n  w.db.raw.prepare('INSERT INTO seat_presence(token_id,owner,last_online_at,updated_at) VALUES(?,?,?,?)').run(7,A,t-ONLINE_WINDOW_MS-1,t-ONLINE_WINDOW_MS-1);\n  const keys=[];w.env.CHAIN_LIMITER={limit:async({key})=>{keys.push(key);return {success:false};}};\n  await (await b.get('/api/me/home')).json();await Promise.allSettled(w.kept);\n  const n=q=>w.db.raw.prepare(q).get().n,lane=()=>keys.filter(k=>k==='chain:index:lane').length;\n  const probe=()=>JSON.stringify(w.db.raw.prepare('SELECT probed_at-? p,expires_at-? e FROM index_lane_probes').all(t,t));\n  const before={sessions:n('SELECT count(*) n FROM sessions'),challenges:n('SELECT count(*) n FROM login_challenges'),probe:probe(),lane:lane()};\n  const samples=[t+1,t+1,t+1];samples[pos]=bad;let i=0;const pending=[],logs=[],saved=console.log;\n  const sched=createWorker(w.gateway,w.chain.fetcher,()=>samples[i++],[]);console.log=(...a)=>logs.push(a.join(' '));\n  try{await sched.scheduled({scheduledTime:t+1,cron:'*/15 * * * *'},w.env,{waitUntil:p=>pending.push(p)});await Promise.allSettled(pending);}finally{console.log=saved;}\n  const s=await (await b.get('/api/auth/session')).json();w.clock.set(t+1);const h=await b.get('/api/me/home');await Promise.allSettled(w.kept);\n  console.log(JSON.stringify({sample:pos+1,value:String(bad),before,after:{sessions:n('SELEC","severity":"low","snippet":"      if(![presenceNow,memberNow,probeNow].every(Number.isFinite)){","title":"Scheduled clock guard accepts finite out-of-range samples: Number.MAX_VALUE (or a microsecond-unit timestamp) still deletes every live session/challenge and refunds the live 30 s probe"}],"hash":"803ff7702760baaa1f73087ffd4ffd74e800df934166b1ec9e0fdc65a5d11062","nodeId":"5ef53ced-4b48-4a7f-a223-75b1b39f9b7f","outcome":"completed","summary":"# Audit12 economics review: IMD Ember World, scheduled-clock closure\n\nPin `2f21b74cf61fe8fed9e3700d082b2dab38904b33` (tree `05bb14d9…`, parent `35ace95`), matching the public remote `main`. Offline synthetic review; no repository files were changed. The one finding is in `.imd-findings.json`.\n\n## Summary\n\nBoth Audit11 rows are closed as written. NaN, +Infinity and −Infinity at each of the three sampled positions now stop the scheduled handler before any helper, SQL, upstream read or `waitUntil` work. I reproduced this with the published commands and with my own probes.\n\nNo regression was reproduced in the Auth, ownership, Member M1, artifact or request-lane boundaries. One same-class neighbour survives and is reported as a Low finding. It is not a regression and is outside the literal \"non-finite\" wording.\n\n- **SOURCE-CLOSURE: PASS (bounded).** The two rows are closed for non-finite inputs, with the neighbour below left open.\n- **RELEASE-READINESS: UNKNOWN.** Nothing was deployed or read back; the native cleanup provider still reports BLOCK.\n\n## Closure matrix\n\nCitations are to the pin, e.g. `https://github.com/tungweb3/imd-ember-world-review/blob/2f21b74cf61fe8fed9e3700d082b2dab38904b33/source/worker/app.ts#L150-L164`.\n\n| ID / severity | Location at pin | Reproduction and order | Measured result | Verdict |\n|---|---|---|---|---|\n| **A11-L1** (Low): non-finite scheduled clock reaching destructive housekeeping | Guard `source/worker/app.ts:153-156`; unchanged sinks `server/presence.ts:59-66`, `server/member.ts:42-50` | Sign in, bootstrap M1, seed one expired and one live row per cleanup table, run real `scheduled` with `[T+1,T+2,T+3]` and one position replaced by NaN/+Inf/−Inf, read `/api/auth/session`, request home at T+1 ms, then finite crons at +10 m and +60 m | Candidate, all 9 cases: 3 samples, 0 tasks, 0 SQL, 0 batches, 0 upstream, `total_changes` +0, every table identical, `signedIn:true`, one fixed `invalid_clock` log line. Baseline: 9 assertion failures; +Inf at sample 1 takes sessions 2→0, challenges 2→0, `signedIn:false`, home 401 | **CLOSED** for non-finite inputs; see finding 1 |\n| **A11-I1** (Info): non-finite clock deleting a live 30 s probe and refunding the lane | Same guard; unchanged sinks `server/auth.ts:269-270`, `281-286`; request lane `server/auth.ts:760-774` | Own offline refused-lane control (seat stays offline), plus an admitted-lane variant where `chain:index` refuses and `chain:index:lane` allows | Candidate, all 9 cases: probe stays `{T, T+30000}` after cron and after the T+1 ms request; work (index/rpc/budget/lane) 0/1/1/1 → 0/1/1/1. Admitted lane: lane row `at=T`, probe and stored index answer retained; 1/1/1/1 → 1/1/1/1. Baseline +Inf at sample 3: probe deleted, re-created at `{T+1, T+30001}`, lane 1 → **2** | **CLOSED** for non-finite inputs; see finding 1 |\n\n## Row detail\n\n**A11-L1.** The handler takes three samples in the original order (`presenceNow`, `memberNow`, `probeNow`) and returns before the first `ctx.waitUntil` unless all three pass `Number.isFinite`. That rules out partial cleanup ahead of a later invalid sample.\n\n- **Mutation check:** I ran 11 mutants of the guard against the published test file and all were killed. They included first-only, first-two, last-two, `some`, NaN-only, no guard, a prune before the guard, a shared timestamp, swapped samples 2/3, an extra sample, and guard-before-DB-check.\n- **Finite controls:** the published controls pass. They cover distinct inputs `[T+10,T+20,T+30]`, the strict presence cutoff, inclusive member/probe expiry, independent 200-row caps over two runs, missing-schema independence, and no-DB with zero samples.\n- **Non-number samples:** `undefined`, `null`, string, BigInt, `Date` and boxed Number are also rejected with zero work.\n- **Residual:** an invalid cycle skips all three helpers, including ones whose own sample was valid, and returns normally. A persistently invalid clock would stop housekeeping with only a log line as signal.\n\n**A11-I1","treeHash":null,"usage":{"cachedInputTokens":4546079,"inputTokens":78,"model":"claude-fable-5-1","outputTokens":45181,"runtime":"claude","turns":43,"wallClockMs":597656}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"49abac41ee211059","findings":[],"hash":"925684888386c2a8abcc612c39850d21bf27f2c5c51d03ab2abf635af2dfb866","nodeId":"9cf34426-2b69-4731-92a9-9b22fad327ab","outcome":"completed","summary":"**SOURCE-CLOSURE: PASS, bounded to the two scheduled-clock findings at `2f21b74cf61fe8fed9e3700d082b2dab38904b33`. RELEASE-READINESS: UNKNOWN.** Both findings are closed in the reviewed source. I reproduced no regression in the tested Auth, ownership, Member M1, artifact or request-lane boundaries.\n\nThe required [.imd-findings.json](/home/imd/agents/273/data/work/3ffb2bf9-fe8c-4433-aa15-333f218775bb/9cf34426-2b69-4731-92a9-9b22fad327ab/.imd-findings.json) contains `{\"findings\":[]}`. No tracked repository files were changed.\n\nThe review used the exact checkout and a clean temporary export of its committed files, with Node **24.21.0**, locked **viem 2.56.9**, and migration-backed **node:sqlite 3.53.4**. All 147 selected source hashes and 315 root checksums matched. The tested source hashes still matched after execution. Public-parent comparison confirmed exactly four changed source files: Worker implementation, scheduled tests, runner registration and runner tests. Helpers, SQL, migrations, dependencies and other production implementations were byte-identical.\n\n[Audit11][audit11] established the two scheduled-clock defects. [Report11][report11] assessed the earlier six closures, including request-side clock handling. Its bounded PASS did not cover away the subsequently reproduced scheduled neighbors. Those six issues remain regression context, not additional current closure rows.\n\n| Current finding | Exact-pin location, reproduction and measured result | Closure and residual impact |\n|---|---|---|\n| **A11-L1 — Low:** non-finite scheduled time reaches destructive housekeeping | [Worker lines 150–163][worker]; affected [presence cleanup][presence] and [member cleanup][member]. At `T=1790596800000`, replace each position in `[T+1,T+2,T+3]` separately with `NaN`, `+Infinity`, or `-Infinity`: nine cases. **Expected and actual:** three samples; zero SQL preparations, batches, tasks, upstream calls and database changes. Full rows remain equal across all eight observed tables. The signed session remains readable at finite time. Index/RPC/budget/lane-call totals remain **0/1/1/1** through the +1 ms request. | **CLOSED.** Validation precedes every helper invocation, preventing partial cleanup before a later invalid sample. Historical first-sample Infinity deleted sessions/challenges; second-sample Infinity deleted live member records. Neither occurs now. Invalid cycles defer maintenance until finite recovery; no remote ability to control production time was demonstrated. |\n| **A11-I1 — Info:** non-finite scheduled prune deletes a live probe and refunds backoff | [Worker guard][worker]; [probe expiry SQL and reservation][probe]; [request-lane order][lane]. After creating a probe at `T`, expiring at `T+30000`, execute invalid cron and request home at `T+1`. All nine published cases preserve both timestamps. Independent offline refused/admitted fixtures also pass all **18 combinations**: cron SQL/tasks/mutations **0/0/0**; work totals remain respectively **0/1/1/1** and **1/1/1/1**. Persisted admitted lanes remain **0** and **1**, respectively. | **CLOSED.** The probe survives refusal and successful lane work without refresh or refund. At +10m/+60m, ordinary expiry and requests resume. Direct cleanup helpers still rely on their caller for valid time; this closure protects the scheduled entry point. No ownership bypass, monetary loss or production exploitability was established. |\n\nThe numerical failure mechanism matters independently of test totals. Positive Infinity makes every finite expiry satisfy the destructive comparison. NaN and negative Infinity behave differently, but neither guarantees an entirely unchanged cycle when other jobs receive finite samples. The original handler started independent asynchronous jobs as it sampled time; rejection or failure in one job could not undo another job’s changes.\n\nThe candidate instead obtains `presenceNow`, `memberNow` and `probeNow` synchronously, checks all three with `Number.isFinite`, then s","treeHash":null,"usage":{"cachedInputTokens":2131712,"inputTokens":138816,"model":"gpt-6-astra","outputTokens":14304,"runtime":"codex","turns":7,"wallClockMs":421950}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"7f1dec5ffcbde1d8","findings":[{"citation":"resolved","description":"Not a regression (the unpatched parent 35ace95 behaves identically) and it does not reopen the two rows as worded: NaN/+Infinity/-Infinity at each of the three positions are refused before any DB helper, SQL or waitUntil (reviewer-reproduced, 9/9). It is the residual of the same root cause. worker/app.ts:153-154 accepts any finite number as temporal authority, so a finite but implausible sample passes the guard and reaches recordPresence (server/presence.ts:61-69: PRUNE_SESSIONS expires_at<now-DAY, PRUNE_CHALLENGES, PRUNE_INDEX, PRUNE_INDEX_LANES, UPSERT updated_at=now), pruneMemberRecords (server/member.ts:46-49, expires_at<=now) and pruneIndexProbes (server/auth.ts:284, expires_at<=now). The outcome is the same as the Infinity case Audit11 rated Low/Info: every live session and challenge deleted (signed cookie no longer readable), live idempotency/history rows deleted, a live 30-second probe deleted with the backoff refunded and one extra chain:index:lane limiter acquisition at t+1ms, and seat_presence.updated_at persisted as 1.7976931348623157e+308 (a durable value later max()/freshness logic and any JS Date conversion cannot interpret). Reachability is the same as the original findings: only through the injected `now` parameter of createWorker (worker/app.ts:131) or a broken runtime clock; production Date.now() does not return these values, and no remote caller controls the cron clock. Impact is bounded to forced re-sign-in, loss of 24h idempotency replay records/history rows, and one refunded lane probe per scope per bad cycle; no funds, ownership or profile-name authority is involved. The published scheduled-audit11 tests exercise only the three non-finite values, so this edge is untested. Fix that preserves the three distinct finite samples: replace the predicate with a plausibility check on each sample, e.g. Number.isSafeInteger(v)&&v>0&&v<=8.64e15 (optionally also bound each against controller.scheduledTime, which is currently ignored), and add the three positions x {Number.MAX_VALUE, 8.64e15+1} to the regression.","line":154,"path":"source/worker/app.ts","reproduction":"Node v24.21.0, viem 2.56.9, real createWorker + migration-backed node:sqlite, using the published fixture()/cron() from source/tests/scheduled-audit11.test.mjs unchanged except for the sample values (T=Date.UTC(2026,8,28,12); fixture holds 2 sessions, 2 challenges, 2 profile_requests, 2 profile_history, live probe net:unknown| {probed_at:T,expires_at:T+30000} plus one expired probe, 1 index_lanes, 1 index_candidates). Expected for an invalid clock (as for NaN/Infinity): log scheduled {\"status\":\"invalid_clock\"}, tasks 0, SQL 0, total_changes delta 0, session signedIn:true. Actual on candidate 2f21b74: (a) samples [Number.MAX_VALUE,T+2,T+3]: tasks 5, SQL prepares 9, batches 2, total_changes +10; sessions 2->0, login_challenges 2->0, index_lanes 1->0, index_candidates 1->0; GET /api/auth/session signedIn:false, GET /api/me/home 401; seat_presence.updated_at=1.7976931348623157e+308. (b) samples [T+1,Number.MAX_VALUE,T+3]: profile_requests 2->0 and profile_history 2->0 (live-request expiring T+86400000 and history expiring T+30d deleted). (c) samples [T+1,T+2,Number.MAX_VALUE] with the roster offline (online=[]): index_probe_cleanup deleted 2 including the live probe; the next /api/me/home at T+1ms returns 200 recheck:limited but chain:index:lane limiter calls go 1->2 (budget 1, rpc 1 unchanged) and the probe is re-created as {probed_at:T+1,expires_at:T+30001}. (d) [8.64e15+1 x3] and [T*1000 x3] (microseconds mistaken for milliseconds): total_changes +13, all eight housekeeping tables emptied except seat_presence, signedIn:false, 401. Same inputs on parent 35ace95 give identical results, so the fix neither introduced nor removed this.","severity":"low","snippet":"      if(![presenceNow,memberNow,probeNow].every(Number.isFinite)){","title":"Scheduled clock guard checks finiteness only: a finite out-of-range sample (Number.MAX_VALUE, 8.64e15+1, ms*1000) still runs the destructive housekeeping A11-L1/A11-I1 describe"}],"hash":"a33f6da4239de819b983e4f275bc3153d1afeaab88c81bb98dc5163394179864","nodeId":"87683ea1-e11a-4ee6-9dd3-02ed165ae7d4","outcome":"completed","summary":"# Audit12 review: IMD Ember World, scheduled-clock source closure (World only)\n\nSnapshot `2f21b74cf61fe8fed9e3700d082b2dab38904b33`, parent `35ace952`. No Solidity is in scope, so no Foundry proof applies. One finding is written to `.imd-findings.json`; no repository files were changed.\n\n## Verdicts\n\n| Gate | Verdict | Rationale |\n|---|---|---|\n| SOURCE-CLOSURE | **PASS (bounded)** | Both rows are closed as worded: every non-finite sample at every position is refused before any work starts, and I reproduced no regression. One Low residual remains for finite out-of-range clocks; it predates this change. |\n| RELEASE-READINESS | **UNKNOWN** | Nothing was deployed or read back. Production D1, secrets, bindings, WAF, limiter, upstream and frontend are unmeasured. The native cleanup provider still reports BLOCK (TEAM-stated), and I could not reproduce the typecheck on the public tree. |\n\n## Current closure matrix\n\n| Row | Severity | Source (containing pin) | Reviewer result | Status |\n|---|---|---|---|---|\n| A11-L1: non-finite scheduled clock reaching destructive housekeeping | Low | `source/worker/app.ts:151-156` | 9/9 invalid cases: 3 samples taken, 0 tasks, 0 SQL prepares, 0 batches, 0 total DB changes, session still readable | CLOSED for NaN/±Infinity; finite-extreme residual below |\n| A11-I1: non-finite clock deleting a live 30-second probe and refunding backoff | Info | same guard, `app.ts:153-156`; helper `server/auth.ts:281-286` unchanged | Live probe timestamps unchanged; at t+1ms budget, lane and RPC counts stay 1/1/1; recovery at +10m/+60m works | CLOSED for NaN/±Infinity; same residual |\n\n## Execution trace\n\n**Entry point.** `scheduled` at `app.ts:150` returns at line 151 when there is no DB, before any clock read. Line 153 takes three samples in order (`presenceNow`, `memberNow`, `probeNow`). Line 154 requires all three to pass `Number.isFinite`; otherwise line 155 logs a fixed `invalid_clock` status and returns.\n\n**Why no partial cleanup is possible.** Nothing touches the DB, the gateway or `ctx.waitUntil` between lines 151 and 156. The first helper starts at line 157. In the parent, each `now()` sat inside a helper's argument list, so presence work had already started before the second sample was taken.\n\n**Types.** `Number.isFinite` does not coerce, so a string, `null`, `undefined` or BigInt sample is also refused (measured: 0 tasks, 0 SQL). The parent accepted these.\n\n**Throwing clock.** A clock that throws at sample 2 now propagates with zero mutations. On the parent it threw after presence cleanup had already been registered.\n\n**Finite path.** Each helper still receives its own sample (lines 157, 158, 162). A single shared timestamp was not introduced.\n\n## Row 1: A11-L1\n\n- **Reproduction.** Published fixture with real `createWorker`, viem EOA sign-in and migration-backed `node:sqlite`. Samples were `[T+1, T+2, T+3]` with one position replaced by NaN, +Infinity or −Infinity.\n- **Expected and actual agree** in all nine cases:\n  - 3 samples taken, 0 tasks, 0 SQL prepares, 0 batches, 0 rejected, total-changes delta 0, 0 upstream calls.\n  - Snapshots of all eight tables (sessions, challenges, presence, member requests, history, probes, lanes, candidates) are deep-equal before and after.\n  - `/api/auth/session` returns 200 with `signedIn:true` after returning to finite time.\n  - The only log line is `scheduled {\"status\":\"invalid_clock\"}`.\n- **Calibration.** The same 13-test file run against the parent source gives 4 pass and 9 assertion failures, matching the TEAM claim.\n- **Residual.** See finding F1.\n\n## Row 2: A11-I1\n\n- **Refused-lane retention.** The fixture's limiter refuses the lane, leaving probe `net:unknown|` at `{probed_at:T, expires_at:T+30000}` and no `index_lanes` row for it. After each invalid cycle and a `/api/me/home` request at T+1ms, the probe row is identical and work counters stay at index 0, RPC 1, budget 1, lane 1.\n- **Independent offline control.** The combined fixture has an online seat that can m","treeHash":null,"usage":{"cachedInputTokens":498272,"inputTokens":18,"model":"claude-fable-5-1","outputTokens":11764,"runtime":"claude","turns":9,"wallClockMs":140416}}],"verification":[]}