{
  "version": "1",
  "updated": "2026-09-03",
  "entries": [
    {
      "id": "D-01",
      "title": "VF-1 sealed target says LOWER; the chain and checklist say RAISE",
      "cls": "QA defect (case content)",
      "severity": "high",
      "status": "open — fix specified",
      "found_by": "origin-blind adversarial review (model-run), 2026-09-01",
      "verified_in_code": "2026-09-01",
      "affects": [
        "Q1",
        "Q2"
      ],
      "fix": "Correct the VF-1 sealed target to match the chain and checklist; re-run the case's leakage review after the change."
    },
    {
      "id": "D-02",
      "title": "Sandbox \"Question/framing\" control writes a field no delegate path reads",
      "cls": "ineffective stated control",
      "severity": "high",
      "status": "open — fix specified",
      "found_by": "adversarial review, 2026-09-01",
      "verified_in_code": "2026-09-01",
      "affects": [
        "Sandbox"
      ],
      "fix": "Add a Sandbox-only framing field wired to the delegate path; do not wire the existing field, which would leak the sealed target into Q1/Q2."
    },
    {
      "id": "D-03",
      "title": "Intervention turn-index drift: interventions after the first spawn are misplaced in provenance",
      "cls": "provenance",
      "severity": "medium",
      "status": "open — fix specified",
      "found_by": "session verification, 2026-09-01 (missed by the review)",
      "verified_in_code": "2026-09-01",
      "affects": [
        "provenance export"
      ],
      "fix": "Index interventions against the recorder's turn counter at emission time."
    },
    {
      "id": "D-04",
      "title": "independent_giveaway_check exports not_done for TB-2, RF-3, VF-1 although the round-2 leakage review ran",
      "cls": "provenance (understated control)",
      "severity": "medium",
      "status": "open — fix specified",
      "found_by": "session verification, 2026-09-01 (missed by the review)",
      "verified_in_code": "2026-09-01",
      "affects": [
        "provenance export"
      ],
      "fix": "Populate the export from the round-2 review record; add the record's date."
    },
    {
      "id": "D-05",
      "title": "Q2 meta.purpose claims the pair \"flips ONLY the Verify phase\"; phaseForTurn re-slices exposure when Verify is enabled",
      "cls": "overclaim in metadata",
      "severity": "low",
      "status": "open — fix specified",
      "found_by": "adversarial review, 2026-09-01",
      "verified_in_code": "2026-09-01",
      "affects": [
        "Q2"
      ],
      "fix": "Rewrite the purpose string to describe what phaseForTurn does."
    },
    {
      "id": "D-06",
      "title": "B-alone Q1 arm required by spec §4.2/§6.3 is not built (solo-A only)",
      "cls": "spec conformance gap",
      "severity": "high",
      "status": "open — fix specified",
      "found_by": "adversarial review, 2026-09-01",
      "verified_in_code": "2026-09-01",
      "affects": [
        "Q1"
      ],
      "fix": "Build the B-alone arm from the same scenario source so the matched-pair invariant holds."
    },
    {
      "id": "R-07",
      "title": "Grader independence: both grader calls run on the Recorder agent, so the Recorder grades its own recognition (spec §6.1 requires a different model or instance)",
      "cls": "independence (design decision)",
      "severity": "high",
      "status": "decision — fourth agent slot specified",
      "found_by": "session verification, 2026-09-01",
      "verified_in_code": "2026-09-01",
      "affects": [
        "Q1",
        "Q2"
      ],
      "fix": "Add a fourth agent slot for grading, provider-independent of the Recorder."
    },
    {
      "id": "R-08",
      "title": "Single-context leak probe on TB-2 and RF-3 not run",
      "cls": "unrun check",
      "severity": "medium",
      "status": "decision — to run",
      "found_by": "session verification, 2026-09-01",
      "verified_in_code": "n/a",
      "affects": [
        "Q1"
      ],
      "fix": "Run the probe; record the result here either way."
    },
    {
      "id": "R-09",
      "title": "Versioned defect register to travel with the artifact, disclosing that the review was model-run and origin-blind",
      "cls": "disclosure",
      "severity": "—",
      "status": "done — this register (v1, 2026-09-03)",
      "found_by": "session decision, 2026-09-01",
      "verified_in_code": "n/a",
      "affects": [
        "disclosure"
      ],
      "fix": "This page and data/register.json."
    },
    {
      "id": "N-11",
      "title": "Test-count resolution: the Block 2 build transcript (2026-06-24) records 89/89 logic-invariant tests green (context isolation, recorder non-self-attribution, spawn isolation, independence of the two grader calls); the harness and its run output do not survive as artifacts and no hash of the graded file was recorded, so the figure rests on the transcript alone. The site states the invariants and not a count. Supersedes N-10.",
      "cls": "documentation",
      "severity": "low",
      "status": "closed — number withheld by decision; invariants stated",
      "found_by": "evidence audit, 2026-09-01; principal's challenge",
      "verified_in_code": "invariants re-checkable in the artifact",
      "affects": [
        "materials"
      ],
      "fix": "None; disclosure entry."
    },
    {
      "id": "N-10",
      "title": "Documentation: the test-count figure cited in draft materials (28) does not match the build record (89); the harness file and a dated run record are not yet hosted",
      "cls": "documentation",
      "severity": "low",
      "status": "superseded by N-11 (2026-09-03)",
      "found_by": "session verification, 2026-09-01; site build 2026-09-03",
      "verified_in_code": "n/a",
      "affects": [
        "materials"
      ],
      "fix": "Host the harness beside the artifact with its run output; then cite N of 89."
    }
  ]
}