Audit
Read-only inspection established the real failure modes before source changes.
A hardcoded repository-root assumption became a bounded delivery program: audit, contract, implementation, adversarial review, correction, negative control, independent acceptance, controlled integration, and claims reconciliation.
Multiple modules inferred “where is this checkout?” from one home-directory convention. A launcher combined a fixed checkout assumption with a relative Python import. A relocated clone could fail, import from the wrong tree, or redirect file access only after a normally closed write gate opened.
For a buyer, the work was not a mechanical search-and-replace. It crossed configuration, imports, launchers, safety gates, historical branches, test design, security handling, and the language used to describe success.
Read-only inspection established the real failure modes before source changes.
Two tickets bounded the resolver and the companion launcher repair.
One fail-safe root resolver replaced distributed path guesses across 15 sites.
Review separated passing syntax from the actual relocation property.
A cwd-dependent launcher fix was exposed, repaired, and preserved in history.
The pre-fix bytes failed under the same conditions that the correction passed.
History convergence, portability, and claims reconciliation landed in order.
Unexercised runtime and data behavior remained explicitly unverified.
The initial launcher repair inserted a relative core path. A first attempted negative control also changed into the relocated checkout, accidentally making that relative path valid. Review discarded the result.
Executed from an unrelated working directory against relocated bytes.
The launcher derives its directory from its own file and passes an absolute core path.
The control discriminates the cwd-relative import defect. It does not prove the write-enabled sealing path, which was deliberately not invoked.
A canonical HOUSE_ROOT resolver and root-relative SCRIBE launcher exist in reviewed commits.
Four resolver scenarios, relocated import, and a discriminating negative control passed.
Independent reviews issued bounded verdicts and retained the open evidence gaps.
Three genuine merge commits preserve convergence, correction, and claim discipline.
This page is the first public artifact; the underlying evidence repository remains private.
A single fail-safe contract replaced distributed assumptions.
Defect discovery and repair remain legible in history.
Convergence, portability, and claim discipline integrated in order.
Integration did not silently become deployment authority.
This sequence demonstrates the work an FDE performs in a brownfield environment: isolate an implicit operational assumption, convert it into a testable contract, protect live state, challenge the test, repair the repair, reconcile history, and communicate only what the evidence supports.
“A green test inherits only the scope of what it asserts.”
Available for bounded field-engineering engagements involving local-first agents, brownfield integration, portability, governance, and evidence-led delivery.
hello@dopenoun.dev ↗