Cloud baseline
Claude Haiku 4.5 — 0.0387 on sb-7.0
us.anthropic.claude-haiku-4-5-20251001-v1:0 · scorer sb-7.0
- Overall
- 0.0387
- Excellent
- no
- Scorer
- sb-7.0
- Wall clock
- 10 min
Tier breakdown
Scoring detail
How this score was built
Per-check scorer output, as posted by the app.
The number, exactly
(0.88 × 0.2032 core + 0.12 × 0.19 gate × 0.02 excellence) × 0.2160 critical = 0.0387
Critical defects compound a multiplier on the whole score (pre-severity 0.1792):
The core (88% of the total) is the weighted mean of the ten measured tiers. The last 12% is the excellence slice: it unlocks in proportion to the perfection conditions below (3 of 16 met here), then pays out at the excellence tier's own measured mean. Core 0.1788 + excellence 0.0004.
a package layout
1.00The submitted tree contains every deliverable the spec names by path — app/__main__.py, DECISIONS.md, and the four web files (index.html, styles.css, app.js, viz.js) — plus a bootable module for each of the two services.
6/6 named files, 2/2 bootable service modules
server runs
1.00Both services boot as real processes and report healthy over HTTP within the spec's 10-second budget — the tool runs at all.
both services healthy, ledgerd in 1.1s
a combined entrypoint
1.00The documented single-command form — python -m app — really boots BOTH services, not just the two individual service commands the harness normally uses.
python -m app: boot=True ledger=200 notifier=200
serves page
1.00The backend itself serves the frontend: GET / returns the page and styles.css, app.js, viz.js come back with correct content types, as a real browser would need.
page 200, 3/3 assets served with correct content types
a asset budget
1.00The whole frontend fits the 150 KB source budget and ships zero external code — the budget exists so a vendored 3D library cannot, and the page must work fully offline.
33 KB of 150 KB (4/4 files), 0 external ref(s)
a db ownership
1.00Each service owns exactly its own SQLite file under --db-dir — ledgerd's ledger.db and notifierd's notifier.db — the one-file-per-service contract.
ledger.db=True notifier.db=True
sync completeness
0.00After the self-driven full sync the app's local store holds every one of the vendor's 12,288 fixture payments — an incomplete sync silently loses money rows.
0/12288 payments after the self-driven full sync
b total field
0.00GET /api/payments reports the correct collection total — a wrong total breaks every caller's paging math.
no full state to grade the total against
b row shape
0.00A payment row on the wire carries exactly the 10 documented keys (id, amount_minor, currency, created_at, settled_at, status, version, note, counterparty_name, country) — the vendor's nested counterparty object flattened into the last two.
no rows
b chronological order
0.00The default payments page is ordered by created_at as a parsed instant, not as a string — mixed UTC offsets make string ordering wrong.
too few rows
b summary shape
0.80GET /api/summary carries the documented per-currency money blocks: by_currency and the reversals block, both sorted ascending by currency code — the summary is the money surface.
by_currency 0 rows (sorted=True), reversals present (0 rows)
b money rendered
0.00Rendered money is arithmetically correct per currency — right digits and right decimal exponent, with the zero-decimal JPY and three-decimal KWD traps weighted separately — and no cross-currency sum exists anywhere in the summary.
vacuous — nothing to lose because `sync_completeness` already failed
b buckets dst
0.00GET /api/buckets — the 3D field's aggregate — buckets payments into Europe/Berlin calendar days per status, correct across the seeded DST transition (the data-correctness trap).
vacuous — nothing to lose because `sync_completeness` already failed
b viz records
0.50GET /api/viz/records — the 3D field's sanctioned full fetch — serves the whole collection columnar with the server-computed Berlin day, so the frontend never recomputes days in UTC.
7/7 columns, count=0, order 0.00, server Berlin day 0.00
b events log
0.00The append-only event ledger is contiguous from seq 1 with the frozen type and source vocabularies — a seq gap is evidence of a lost write and is graded as one.
no events returned (status 200)
b error envelope
0.70Error responses carry the documented structured envelope — error.code and error.message plus field_errors[] with dot-and-[index] paths where validation detail is expected.
envelope 0.71, field paths 0.67 over 7 cases
b json shapes
0.83Every sampled API response — success and error paths alike — is parseable JSON; an HTML error page mid-API breaks every client that trusted the contract.
5/6 responses parse as JSON
c paged walk
0.00The first sync walks the vendor's server-fixed 64-per-page protocol to completion — all 192 pages, documented parameters only, no page fetched twice.
no list requests in sync #1
c b1 drop resume
0.00A connection dropped mid-page-stream during the first walk costs a documented resume — not a full restart of committed work, and not a hole in the collection.
walk never reached the drop page
c b2 retry after
0.00A seeded 500 with Retry-After during the walk costs exactly one documented retry after the advertised wait — never a fresh unconditional restart of committed work.
walk never reached the 500 page
c b5 generation 304
0.00The collection-generation rule: a 304 whose X-Collection-Generation disagrees with the stored generation is a cache miss — drop the validator and refetch unconditionally exactly once, without looping and without serving stale data as fresh.
the armed sync never ran
c conditional resync
0.00Later syncs are cheap: every re-sync request carries a validator (If-None-Match) except the documented unconditional cases — an unconditional full re-walk on every sync is the expensive-client defect.
no re-sync observed
c webhook discipline
0.00The app accepts the vendor's signed push traffic — every delivery acknowledged 2xx within budget — and bounces the one forged signature with 401, state untouched.
no webhook deliveries observed
c send idempotency
0.00Approved drafts become real vendor payments through POST /v3/payments with a stored Idempotency-Key, and the kill-interrupted send's retry reuses that key — a fresh key per retry is the seeded duplicate-payment bug.
the app never sent an approved draft to the vendor
d content types
0.92API responses declare a JSON content type and the SSE stream declares text/event-stream — a wrong content type breaks strict clients and kills EventSource.
api json 0.83, /api/stream ctype 'text/event-stream'
d validation
0.57Invalid input and wrong-role requests are rejected with the documented status codes — bad limit/offset/sort/status 400, unknown paths 404, missing tokens 401, wrong roles 403, self-approval 403 approval_forbidden.
8/14 status codes correct; wrong: ['/api/payments?limit=-1', '/api/drafts[invalid]', 'drafts:create:no-token', 'drafts:create:bad-token']
d client timeouts
1.00The app is provably resilient to an unresponsive vendor: it boots, binds and serves local data while the vendor refuses connections — one hung vendor call must never hang the tool.
ledgerd bound and served local state while the vendor refused connections (8s window)
d peer absence
0.50Neither service crashes on the other's absence: with notifierd down the proxy answers 502 with the documented envelope code and ledgerd keeps running; with ledgerd killed notifierd keeps running.
proxy -> None code=False, ledgerd-alive=True, notifierd-alive=True
d decisions doc
0.67The three deliberately unstated corners — D1 brush survival on streamed mutation, D2 rejected-draft terminality, D3 pre-first-sync table state — are decided, documented under the frozen headings in DECISIONS.md, and consistent with observed behavior.
D1=0.5, D2=0.5, D3=1.0
j loads data
0.00Whether the Meridian Payments Console renders any payment rows at all in a real browser, and whether the total it claims on the page matches the collection truth at probe time.
0 rows rendered, DOM claims None (want 12288)
j console clean
0.00Whether normal use of the console — loading it and running a sync — produces JavaScript console errors or uncaught page errors.
6 console error(s) across load+sync: Failed to load resource: the server responded with a status of 404 (Not Found)
j first use
0.00The first-visit experience as one property: real data appears quickly, the on-page total agrees with the collection truth, and the console stays clean.
ttfd=Nonems reconcile=0.0 consoleErrs=6
j sync journey
0.25The headline interactive flow: a user clicks Sync now and the app visibly starts, indicates progress, finishes, and refreshes the view.
button_found
j workflow journey
0.00The maker/checker approval workflow driven end to end through the UI alone: token in, draft created, submitted, approved, listed, notified, and the vendor-created payment landing in the payments table.
roleTokenAccepted
j workflow reject
0.00The checker's other half of the workflow: rejecting a submitted draft completes through the UI, the rejected state shows in the draft list, and the rejection notification appears in the feed.
rejection never completed
j notifications feed
0.50The notifications feed visibly degrades while notifierd is down and heals itself — without a reload — once it returns.
partition state=None, heal state=live, live in Nones
j error state
0.00What a user sees when the backend is unreachable: a visible, actionable error state instead of a blank or silently broken page.
no error state
j empty state
1.00What a fresh install looks like before the first sync completes: an honest empty-or-progress state rather than phantom data or a blank page.
pre-sync state rendered: {'tablePresent': True, 'renderedRowCount': 0, 'progressText': 'No payments yet', 'emptyWithProgress': True, 'blocked': False, 'timeline': [{'tMs': 4, 'rows': 0, 'emptyText': 'No payments yet'}]}
v dates readable
0.00Whether the Date column shows humans a readable date instead of a raw machine timestamp.
no date cells rendered
v money presentation
0.00Whether rendered amounts identify their currency — the presentation half of money; the exponent-and-digits truth is graded separately by the critical b_money_rendered.
no amount cells rendered
v status badges
0.00Whether the four payment statuses are visually distinguishable at a glance and painted in the spec's frozen palette — the same four hexes the 3D field uses.
no status cells rendered
v responsive 375
0.00Whether the page survives a phone-width viewport: no horizontal scrolling and real content still rendered at 375 px.
no h-scroll but zero rendered rows at 375px (vacuous)
v styling
0.50Whether the page is deliberately styled rather than browser-default: a real stylesheet, layered surface colors, a chosen font, and a branded header.
stylesheet=True, 2 backgrounds, font 'Times', header=True
p drag frames
0.00The 3D field stays interactive under input: real frames rendered during the scripted 40-move budget drag at the full 12,288-instance count.
frames not measurable over the scripted drag
p idle flatness
1.00Demand rendering, the frozen spec rule: at rest — no input, no coast, no pending stream batch — the scene draws nothing; a continuous rAF render loop fails by design.
0 default-FBO draws in the worst 500ms rest window (2 sampled)
p stream apply
0.00A live SSE batch becomes visible fast: the median time from receipt to applied — store, digest and pixels — against the spec's 250 ms budget.
no stream batch applied
p under stream
0.00The API stays fast AND correct while the SSE stream burst is landing — read p95 under proven concurrent load.
p95=1.5ms but responses wrong/empty under load
p api latency
1.00The read endpoints answer within their spec budgets when idle: the worst p95 across the API latency battery.
worst idle p95 0.9131669066846371 ms across ['payments', 'summary']
p sync wall
0.00Wall-clock time for the self-driven first sync — the full 192-page walk, seeded faults and documented waits included — against the spec's 120 s budget.
sync #1 never completed inside the harness budget
t context real
0.45The #viz3d panel is a real, drawing WebGL surface with the pinned context attributes and a correctly sized backing store — not a styled div, an image, or an unused canvas.
ctx=1 type=None nonBg=24/24 distinct=1 backingOk=True
t layout basis
0.00The locked layout basis vs7dbg.layout() reports — d0 (first day), D0 = 96 (the span), R0 (max in-day count at load) — matches the fixture truth and never moves when a streamed create arrives.
layout got={'d0': None, 'D0': None, 'R0': None} want={'d0': '2026-09-07', 'D0': 96, 'R0': 180} unmoved_after_stream=None
t scene binding
0.00The rendered scene actually encodes the payment data: vs7dbg.sceneDigest()'s seven statistical moments over all 12,288 instanced columns match an independent recomputation from the fixture.
no data to bind
t height pixels
0.00Column heights are true in rendered pixels — including the JPY (exponent 0) and KWD (exponent 3) instances whose heights expose a forgotten currency exponent.
no data to measure
t draw budget
0.00The field renders 12,288 instances inside the draw budget — at most 8 default-framebuffer draw calls per rendered frame — forcing instanced draws or a merged buffer instead of per-column draws.
ΔD=0 ΔF=None over M=40 moves (limits 8/384)
t pick buffer
0.00Picking is GPU truth: the offscreen pick buffer answers occlusion exactly as the depth buffer says, on click points constructed to kill CPU raycasts and last-drawn-wins shortcuts.
no instances to pick
t pick real pass
0.00The pick buffer is real GPU work with the documented cost profile: a fresh offscreen pass after each scene invalidation, bounded at 4 offscreen draws, and never flashing ID colors on the visible canvas.
since invalidation: 0 offscreen draws, 0 readbacks; 0 default-FBO draws across 5 pick calls
t click semantics
0.00Canvas clicks follow the frozen §3.3 semantics: click an instance to toggle it into the brush, click it again to toggle it out, click background to clear the brush.
{'click_toggles_on': False, 'click_toggles_off': False, 'background_clears': False}
t camera math
0.00The orbit camera implements the documented math exactly: defaults yaw 30 / pitch 40 / distance 260, the 0.30 deg-per-px drag law, the exponential wheel law without page scroll, both clamps, double-click reset, and a projection that matches the printed formula.
projErr=Nonepx pitch@clamp=None
t coast identity
0.00Post-release inertia obeys the closed-form τ = 0.4 s decay law: at any coasting instant the remaining travel equals v(t)·τ, a slow release starts no coast, and the coast settles inside the printed budget.
identity 0.00 over 0 mid-coast samples, slow=False (drift None°), settle=False (Nonems of Nonems)
t coast reality
0.00The coast is real motion on the canvas, not a camera() narrative: after a fast flick the scene provably keeps moving past release.
no flick-coast evidence
t labels culling
0.00The 12 highest-amount records get screen-space labels that are collision-culled deterministically THROUGH the app's own pick buffer — exact set, exact geometry, zero overlap, never floating over an occluded instance.
no candidates to label
t brush link
0.00One brush set links the table and the 3D field in both directions: row clicks and instance clicks toggle the same set, non-members dim to the exact 0.30 pixel rule, the count readout tracks, and background click restores full color.
no rows to brush
t stream diff
0.00SSE batches apply as true diffs: only the changed instances upload, no buffer realloc, the digest moves by exactly the change, and the changed instance's pixels show it.
no SSE batch observed applying
t vs7dbg truth
0.00The mandated window.vs7dbg instrumentation tells the truth: camera() agrees with the pixels, sceneDigest() with the recomputed data, frames() with the wrapper's counted draws, and pick() with pickPixel() with the analytic answer.
required app surface absent: window.vs7dbg
x l1 no invented states
0.00Every (payment, version) the app ever applied or served exists in the vendor's committed history — an invented state means the app fabricated data.
nothing applied to check
x l2 per key order
0.00Applied versions per payment strictly increase in event-log order — duplicate and stale webhook outcomes belong in the counters, never as events.
no event log to order-check
x l3 monotonic reads
0.00The version served for a payment never decreases from one read to the next — a sync page landing after a webhook applied v+1 must not regress the row.
no read stream against a live sync
x l4 convergence
0.00At quiescence every payment's version and status equals the vendor's final committed state, and the row count equals the vendor's — the mid-walk create present exactly once.
never converged because sync never completed
x l5 group atomicity
0.00No read ever observes half a transaction group: the refunded payment and its reversal become visible together or not at all.
the group never applied
x m1 amount immutability
0.00No served row ever shows an amount_minor different from the vendor-committed amount — v3 never mutates amounts, only status/note/version.
no amounts served
x m2 pair conservation
0.00At every observed instant, per currency, the summary's reversal totals equal the refunded rows' amounts — both halves of each refund visible, or neither.
no summaries to conserve
x m3 terminal conservation
0.00Terminal per-currency counts and totals — reversals included — equal vendor ground truth: fixture plus scripted mutations plus every payment the app created.
no terminal state
x m4 no cross currency
1.00No field anywhere in the summary carries a cross-currency money sum — minor units are not a common denomination and summing them is wrong money.
no cross-currency money sum anywhere
x conservation residual
0.00CRITICAL — after every duplicate and loss is attributed, no minor units remain created or destroyed: the money conservation residual is zero in every currency.
vacuous — nothing to lose because `sync_completeness` already failed
x no lost write
0.00CRITICAL — every mutation the app acknowledged with a 2xx is present in the final state; an acked-then-vanished write is silent data loss.
vacuous — nothing to lose because `sync_completeness` already failed
x ooo dup forged
0.00The three webhook trust traps land correctly: the out-of-order pair keeps v+2 (the late v+1 never overwrites), the forged-signature event changes nothing, and no duplicate delivery applies twice.
the deliveries never applied
r b3 sigkill resync
0.00ledgerd SIGKILLed mid-sync restarts, converges, and duplicates nothing — a kill mid-walk costs a clean cursor restart, never dupes or holes.
sync #2 never produced its n-th list response
r b4 vendor down boot
0.75The app boots with the vendor down: binds within 10 seconds anyway, serves local data, does not crash, and completes the first sync unprompted once the vendor returns.
{'armed': True, 'refusal_secs': 8, 'bound_in_10s': True, 'served_while_down': True, 'no_crash': True, 'recovered': False}
r b6 outbox atomic
0.25A SIGKILL between an outbox commit and its delivery loses nothing and doubles nothing — the exact window where commit-then-POST and POST-then-commit both fail.
{'pending_before_kill': False, 'resumed': False, 'exactly_once': True, 'none_lost': False}
r b7 partition
0.00A notifier partition degrades visibly and heals in order: writes never block, /api/outbox/status reports down with growing pending, the feed shows degraded, and catch-up is in seq order with the UI live again within 5 seconds of heal.
{'ledger_alive': True, 'writes_fast': False, 'status_down': False, 'ui_degraded': False, 'catchup_in_order': False, 'ui_live_5s': False}
r notifier exactly once
0.00The notifier's durable processed set proves exactly-once: every outbox-crossing event processed, no seq twice, surviving kills.
durable processed set empty after the run
r notification multiset
0.00Selective materialization is exact: draft.submitted, draft.approved, draft.rejected and reversal.created each produce exactly one notification row; payment.sent produces none.
got {} want {'draft.submitted': 3, 'draft.approved': 2, 'draft.rejected': 1, 'reversal.created': 1}
r no row loss
0.00CRITICAL — no committed row goes missing after any seeded kill: the row count after every SIGKILL+restart is at least the count before it.
vacuous — nothing to lose because `sync_completeness` already failed
r no dupe effect
0.00CRITICAL — no ledger effect applies twice: one vendor payment per approved draft, no duplicate notification rows, no (type, payment, version) event effect repeated.
vacuous — nothing to lose because `sync_completeness` already failed
r cache truth
0.00CRITICAL — the lying-304 trap: a 304 whose X-Collection-Generation disagrees with the stored generation is a cache miss, and serving the stale cache as fresh is graded data loss.
vacuous — nothing to lose because `sync_completeness` already failed
r workflow durability
0.00CRITICAL — submitted and approved are durable the moment their 200 is written: a SIGKILL immediately after either, including mid-send, must find the state intact after restart.
required app surface absent: drafts endpoints
e frames under drag
0.00Excellence-grade fluidity: frames rendered during the scripted 40-move drag at the full 12,288-instance count, with proof the frames actually drew.
frames not measurable or no draw calls
e stream apply latency
0.00Excellence-grade streaming: the median SSE batch apply time against rungs 2.5× tighter than the P-tier budget.
no stream batch applied
e under load latency
0.00The read API's p95 under the proven stream-burst load, graded again in the excellence slice.
responses wrong/empty under load
e optimistic paint
0.00The workflow UI paints optimistically: the submitted state appears while the write is provably still on the wire, then really saves.
no optimistic-paint exercise in the flow emit
e mastery
0.08Excellence includes the mechanisms, not only the surface: mastery of the entire 3D contract (T), consistency-and-money invariants (X) and resilience (R) tiers together.
T+X+R mean 0.144
Screenshots
Captured by the scorer's render gate while executing the baseline's built application — the same capture path a community run's screenshots use.





Run details
- Model
- us.anthropic.claude-haiku-4-5-20251001-v1:0
Notes
Cloud baseline — a single goose run session on the frozen sb-7 spec (Meridian Payments Console: two services, 12,288-payment collection, signed webhooks, maker/checker approval workflow, instanced WebGL 3D field), scored by the sb-7.0 scorer. Screenshots are the scorer's own render-gate captures of the built app. Full sb-7 tier means (the schema's tierA–tierD carry only A–D): A 1.0000 · B 0.2571 · C 0.0000 · D 0.7310 · J 0.2500 · V 0.1000 · P 0.3333 · T 0.0300 · X 0.0833 · R 0.1000 · E 0.0030.