CX-1b_CODEX.txt
You are working in the MIZOKI-3-5/MIZOKICloudRun repository (MIZ OKI 3.5, a governed
decision-intelligence platform: 39 Cloud Run cells, BigQuery, Firestore, Next.js command-center UI).
Read in this order before touching code: CLAUDE.md, CONSTITUTION.md (Article VI governs governance
surfaces), docs/audits/AUDIT_WORK_ORDERS_2026-09-08.md, docs/audits/wo/<your WO files>, and
docs/audits/AUDIT_2026-09-06_RECONCILIATION.md if it exists (CX-1 writes it).
Ground rules
- Audit findings are HYPOTHESES pinned at commit fc8b03f9. main has moved. Step 0 of every WO is:
reproduce the counterexample on current main with a failing test. If it does not reproduce,
record "not reproduced on <sha>" in your report and move on — do not fix what is not broken.
- Fail closed. Every fix must make a refusal path explicit and tested. Never widen access to make a test pass.
- No new architecture. Reuse the existing modules named in the WO. If a WO says "reuse X", reuse X.
- Tests are the deliverable. Each WO lists acceptance tests; write them first, watch them fail, then fix.
Name them test_wo<nn>_<what>. Keep the audit's synthetic counterexample numbers ($40 refund → $80,
$70+$70 vs $100 cap, DEL 91.7, etc.) as fixtures so the regression is recognizable.
- Branch: audit/<PROMPT-ID>-<slug>. NEVER use a claude/* branch (they auto-merge to main in seconds).
Commit per WO with message "WO-nn: <title>". Open ONE PR for the prompt when done. Do not merge.
- Protected paths (.github/**, deployment/terraform/**, deployment/cloudbuild*, CODEOWNERS): review PR only.
- Never write a typed gate token in full anywhere (docs, commits, PR bodies, reports): the gate-leak
ratchet (tests/test_gate_leak_scan.py) turns main red. Refer to it only as APPROVED: [MERGE].
- Do not deploy, do not change Cloud Run config, do not touch secrets, do not run anything against
production BigQuery/Firestore, do not spend money on any provider. Local + test fixtures only.
- Coordination: before starting, run
python scripts/claude_memory.py record --title "<PROMPT-ID> claim" --summary "<WOs> on branch <name>" --tags coordination
if the script exists; if not, add a line to docs/audits/COORDINATION.md.
- Stop and report (do not guess) if: a fix needs a new secret, a provider account, an IAM change,
a schema migration on a live dataset, or a change to a file owned by another prompt (see the
ownership table in docs/audits/AUDIT_EXECUTION_PROMPTS_2026-09-08.md).
Final report — write docs/audits/reports/<PROMPT-ID>_REPORT_<date>.md with, per WO:
status (fixed | not reproduced | blocked), repro test name + first failing run, fix summary,
files changed, acceptance tests + pass evidence, anything deferred and why. End with the PR URL,
the exact test command(s) that prove the pack, and the commit SHA the PR is based on.
PROMPT-ID: CX-1b. Branch: audit/cx-1b-lane-freshness (base it on main after PR #1015 merges; if #1015 is still open, base on its head 4d65d69).
Work order: WO-30 stale-evidence half, which CX-1 (PR #1015, report docs/audits/reports/CX-1_REPORT_2026-09-09.md) reproduced but
could not fix inside its edit surface. Lane: ENG. P2.
You own, for this prompt only: miz-oki-command-center-ui/lib/bff/adapters/lanes.ts, miz-oki-command-center-ui/lib/onboarding/lanes-contract.ts,
miz-oki-command-center-ui/app/api/bff/lanes/**, the onboarding page's readiness display, and the economics response shape in
services/service-marketing-connectors/tenant_economics.py (additive field only). Nothing else.
The failing test already exists and must stay exactly as written:
miz-oki-command-center-ui/app/api/bff/lanes/status/route.test.ts::test_wo30_stale_economics_reports_not_ready_stale
(time fixed at 2026-09-09T12:00:00Z; position_as_of 2026-01-01T00:00:00Z; expects 'not_ready:stale', currently gets 'armed:configured').
Fix, smallest honest version:
1. tenant_economics.py: emit `as_of` (ISO-8601 UTC) for the economics record and `position_as_of` for the treasury position; both
additive, both null when unknown. Do not change any existing field.
2. lanes-contract.ts: add per-lane `evidence: {as_of: string|null, max_age_s: number, state: 'ready'|'not_ready', reason?: string}`.
Freshness windows: reuse contracts/mizoki_contracts/treasury.py's seven-day default for the treasury lane; other tenant-input lanes
use a single LANE_EVIDENCE_MAX_AGE_S constant (default 30 days) documented in the contract file. Do not invent per-lane windows.
3. lanes.ts readLaneStatus: carry the timestamps through the join instead of discarding the records; a lane is `not_ready:stale` when
as_of is null-with-configured-values or older than its window; `not_ready:<reason>` when inputs are missing (the existing
dark:tenant-input-missing semantics must be preserved verbatim — do not rename existing states); `ready` only with fresh evidence.
4. Onboarding display renders evidence.state and the existing `why` string; no new copy beyond "stale since <date>".
Acceptance: the existing 7-test lane pack passes 7/7 including the stale test unchanged; add
test_wo30_fresh_timestamped_economics_reports_ready (as_of = now-1h → 'ready') and
test_wo30_null_as_of_with_values_is_stale_not_ready. All existing unauthenticated / missing-tenant / unavailable-upstream refusal tests stay green.
Gates: cd miz-oki-command-center-ui && npx vitest run app/api/bff/lanes && npx tsc --noEmit; pytest for tenant_economics. Also look at why
PR #1015's "Command Center typecheck (tsc --noEmit)" job failed on route.test.ts and fix the typing in this branch if it is the test file.
PR title: "Audit pack A follow-up — lane evidence freshness (WO-30 stale half)".