ENGINEERING PROOF 019 / PROJECT-AUTHORED RUN

One grant.
Two processes.
One callback.

Two separate Node workers race to use the same host-issued approval. An exclusive claim on a shared local filesystem lets one reach the simulated tool callback. The replay is blocked.

This is a recorded, reproducible project run. It does not authenticate a person, send a message, prove delivery, or establish behavior on network filesystems.

Illustration of the observed outcome. The winning process is nondeterministic; the callback count is the invariant.

2separate Node processes
1exclusive claim marker
1simulated tool callback

What the recorded race showed

Each worker received the same proposal and grant. Only the host store could decide which claim won.

CLAIM ACCEPTED · ONE WORKER

Loading…

Reading the checked-in run report.

1×

Shared grant

Local filesystem
exclusive claim

CLAIM REJECTED · OTHER WORKER

Loading…

Reading the checked-in run report.

“Dispatched” means the local callback returned. It does not mean a message was delivered.

Reproduce the run

From the repository root, this command issues a short-lived grant, starts two child processes, and asserts exactly one callback:

node pilots/action-boundary/file-grant-race-demo.mjs

The demo makes a temporary host directory and removes it at the end. It performs no external action.

Read the executable source ↗

What is bound

  • Both workers use the same SHA-256 proposal digest and host-owned policy.
  • A short-lived grant ID maps to that digest in the trusted store.
  • Exclusive creation of the claim marker is the one-use decision point.
  • Expiry, digest mismatch, storage error, and reuse stop before the callback.

Proposal digest:

Loading…
Inspect the recorded JSON
Loading…