{
  "policy": {
    "version": 5,
    "patterns": {
      "version": 1,
      "method": "CURATED_PRACTICE_TOPIC",
      "notice": "Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned."
    },
    "fieldMix": {
      "version": 1,
      "method": "CURATED_ESTIMATE",
      "notice": "Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence."
    },
    "contentStatus": "PRACTICE_BRIEF",
    "assessmentStatus": "NOT_QUALIFIED",
    "evidenceUse": "NONE",
    "aiPolicy": "AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.",
    "notice": "Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.",
    "outcomeEvidence": "Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.",
    "ownershipEvidence": "Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence."
  },
  "patternTopics": [
    {
      "id": "factory-method",
      "label": "Factory Method",
      "group": "Creational"
    },
    {
      "id": "abstract-factory",
      "label": "Abstract Factory",
      "group": "Creational"
    },
    {
      "id": "builder",
      "label": "Builder",
      "group": "Creational"
    },
    {
      "id": "prototype",
      "label": "Prototype",
      "group": "Creational"
    },
    {
      "id": "singleton",
      "label": "Singleton",
      "group": "Creational"
    },
    {
      "id": "adapter",
      "label": "Adapter",
      "group": "Structural"
    },
    {
      "id": "bridge",
      "label": "Bridge",
      "group": "Structural"
    },
    {
      "id": "composite",
      "label": "Composite",
      "group": "Structural"
    },
    {
      "id": "decorator",
      "label": "Decorator",
      "group": "Structural"
    },
    {
      "id": "facade",
      "label": "Facade",
      "group": "Structural"
    },
    {
      "id": "flyweight",
      "label": "Flyweight",
      "group": "Structural"
    },
    {
      "id": "proxy",
      "label": "Proxy",
      "group": "Structural"
    },
    {
      "id": "chain-of-responsibility",
      "label": "Chain of Responsibility",
      "group": "Behavioral"
    },
    {
      "id": "command",
      "label": "Command",
      "group": "Behavioral"
    },
    {
      "id": "interpreter",
      "label": "Interpreter",
      "group": "Behavioral"
    },
    {
      "id": "iterator",
      "label": "Iterator",
      "group": "Behavioral"
    },
    {
      "id": "mediator",
      "label": "Mediator",
      "group": "Behavioral"
    },
    {
      "id": "memento",
      "label": "Memento",
      "group": "Behavioral"
    },
    {
      "id": "observer",
      "label": "Observer",
      "group": "Behavioral"
    },
    {
      "id": "state",
      "label": "State",
      "group": "Behavioral"
    },
    {
      "id": "strategy",
      "label": "Strategy",
      "group": "Behavioral"
    },
    {
      "id": "template-method",
      "label": "Template Method",
      "group": "Behavioral"
    },
    {
      "id": "visitor",
      "label": "Visitor",
      "group": "Behavioral"
    },
    {
      "id": "ports-and-adapters",
      "label": "Ports and Adapters",
      "group": "Architectural"
    },
    {
      "id": "cqrs",
      "label": "CQRS",
      "group": "Architectural"
    },
    {
      "id": "strangler-fig",
      "label": "Strangler Fig",
      "group": "Architectural"
    },
    {
      "id": "saga",
      "label": "Saga",
      "group": "Distributed and reliability"
    },
    {
      "id": "transactional-outbox",
      "label": "Transactional Outbox",
      "group": "Distributed and reliability"
    },
    {
      "id": "circuit-breaker",
      "label": "Circuit Breaker",
      "group": "Distributed and reliability"
    },
    {
      "id": "bulkhead",
      "label": "Bulkhead",
      "group": "Distributed and reliability"
    }
  ],
  "projects": [
    {
      "key": "SKERNEL",
      "title": "Build an operating-system boundary that fails predictably",
      "field": "Systems programming",
      "summary": "Wrap files, timers and readiness notifications with explicit partial-result and portability behavior.",
      "context": "A fictional local agent watches generated inbox files and schedules bounded processing. Direct system calls are scattered across the code, mishandle interrupted operations, and make tests platform-dependent. Build a Rust OS adapter with temporary fixture directories; no kernel module, elevated privilege, or production host modification is required.",
      "stack": [
        "Rust",
        "Filesystem APIs",
        "Polling adapter",
        "Temporary directories"
      ],
      "prerequisites": [
        "System calls",
        "File descriptors",
        "Monotonic clocks"
      ],
      "developerValue": "Practice OS error semantics, partial I/O, portability and deterministic abstraction boundaries.",
      "companyValue": "Review host-facing code whose retries, resource limits, and platform differences are explicit before packaging it as a local agent.",
      "delivery": "Ten linked tickets across three phases. Use synthetic inputs and a local harness; provide source, focused tests, measurements where requested, and a recovery note.",
      "phases": [
        {
          "id": "model",
          "title": "Establish the machine contract",
          "goal": "Make representation, ownership and failure boundaries explicit."
        },
        {
          "id": "control",
          "title": "Control resources and concurrency",
          "goal": "Implement bounded behavior under realistic interleavings."
        },
        {
          "id": "operate",
          "title": "Prove recovery and handoff",
          "goal": "Measure, diagnose and safely replace the component."
        }
      ],
      "tickets": [
        {
          "id": "151c3e66-8557-4dc3-a4d3-05856c347d91",
          "key": "SKERNEL-101",
          "title": "Read a file completely across short system calls",
          "type": "TASK",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 90,
          "phaseId": "model",
          "dependsOn": [],
          "scenario": "The adapter assumes one read fills the requested buffer and silently truncates a generated manifest after an injected short read.",
          "acceptanceCriteria": [
            "Loop until EOF, declared length, or typed error",
            "Return bytes already read only when the contract permits partial results",
            "Zero-progress reads cannot spin forever"
          ],
          "implementationNotes": [
            "Use a controllable local read adapter; never require privileged system-call interception."
          ],
          "verification": [
            "Read the same manifest through one-byte and irregular chunk schedules.",
            "Return zero progress before EOF and confirm bounded failure."
          ],
          "deliverables": [
            "Complete-read primitive and short-read tests"
          ],
          "rollout": "Route manifest reads through the helper before larger files.",
          "skills": [
            "System calls",
            "Partial I/O"
          ],
          "fieldMix": [
            {
              "field": "Systems programming",
              "percentage": 70
            },
            {
              "field": "Storage systems",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "421f63ac-b16f-4489-a9aa-005d9fb8c1f2",
          "key": "SKERNEL-102",
          "title": "Write a durable replacement without exposing a half file",
          "type": "BUG",
          "priority": "MEDIUM",
          "difficulty": "FOUNDATIONAL",
          "estimateMinutes": 90,
          "phaseId": "model",
          "dependsOn": [],
          "scenario": "A crash between truncation and write leaves the agent configuration empty.",
          "acceptanceCriteria": [
            "Write to a unique file in the destination directory",
            "Flush file content before atomic replacement where the platform supports it",
            "Document directory durability and unsupported-platform behavior"
          ],
          "implementationNotes": [
            "Preserve permissions intentionally and reject symlink destination surprises."
          ],
          "verification": [
            "Replace an existing fixture and observe either old or complete new content.",
            "Interrupt before rename and confirm the destination remains unchanged."
          ],
          "deliverables": [
            "Atomic-replace adapter and interruption cases"
          ],
          "rollout": "Retain backups only under an explicit bounded retention policy.",
          "skills": [
            "Filesystem durability",
            "Atomic replacement"
          ],
          "fieldMix": [
            {
              "field": "Systems programming",
              "percentage": 60
            },
            {
              "field": "Storage systems",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "0c01553a-b00d-40eb-a862-6026bd1828c6",
          "key": "SKERNEL-103",
          "title": "Retry interrupted calls without hiding cancellation",
          "type": "STORY",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "model",
          "dependsOn": [
            "SKERNEL-101"
          ],
          "scenario": "Every interrupted call is retried automatically, so a cancelled operation keeps waiting after shutdown begins.",
          "acceptanceCriteria": [
            "Retry only declared interrupt errors",
            "Check cancellation and deadline between attempts",
            "Preserve noninterrupt error identity"
          ],
          "implementationNotes": [
            "Retry policy belongs beside the operation contract, not in a catch-all error loop."
          ],
          "verification": [
            "Inject two interrupts followed by success before deadline.",
            "Cancel between interrupts and verify no further system call is attempted."
          ],
          "deliverables": [
            "Interrupt-aware retry helper and cancellation tests"
          ],
          "rollout": "Adopt per operation after its retry safety is reviewed.",
          "skills": [
            "Error handling",
            "Cancellation"
          ],
          "fieldMix": [
            {
              "field": "Systems programming",
              "percentage": 70
            },
            {
              "field": "Real-time systems",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "98330fc6-80e8-44e1-8ae6-d9014865a065",
          "key": "SKERNEL-104",
          "title": "Keep wall-clock changes out of elapsed-time deadlines",
          "type": "CHORE",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "control",
          "dependsOn": [],
          "scenario": "An NTP correction moves wall time backwards and extends a file-processing deadline by several minutes.",
          "acceptanceCriteria": [
            "Elapsed deadlines use an injected monotonic clock",
            "User-facing timestamps remain UTC wall time",
            "Conversion between the two clock domains is prohibited"
          ],
          "implementationNotes": [
            "Tests advance fake clocks; they do not alter the host clock."
          ],
          "verification": [
            "Expire a deadline through monotonic advancement.",
            "Move wall time forward and backward and prove elapsed behavior is unchanged."
          ],
          "deliverables": [
            "Clock boundary and time-jump tests"
          ],
          "rollout": "Migrate deadline call sites before changing displayed timestamps.",
          "skills": [
            "Clocks",
            "Time modeling"
          ],
          "fieldMix": [
            {
              "field": "Systems programming",
              "percentage": 70
            },
            {
              "field": "Real-time systems",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "78ac8352-98b8-4f0c-b718-823fae29f5fc",
          "key": "SKERNEL-105",
          "title": "Normalize watcher bursts into a bounded rescan request",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 240,
          "phaseId": "control",
          "dependsOn": [
            "SKERNEL-102",
            "SKERNEL-104"
          ],
          "scenario": "One editor save produces create, rename, and modify events; the agent processes the same file three times and misses changes after queue overflow.",
          "acceptanceCriteria": [
            "Events trigger idempotent directory reconciliation rather than direct truth",
            "Burst coalescing has a maximum delay",
            "Overflow schedules a full bounded rescan and remains visible"
          ],
          "implementationNotes": [
            "Do not promise identical watcher events across operating systems."
          ],
          "verification": [
            "Replay create-via-rename and direct-write event sequences with one final reconciliation.",
            "Overflow the event buffer and confirm a rescan restores the fixture state."
          ],
          "deliverables": [
            "Watcher reconciliation loop and platform event fixtures"
          ],
          "rollout": "Keep periodic scans as a fallback during watcher rollout.",
          "skills": [
            "Filesystem watchers",
            "Reconciliation",
            "Portability"
          ],
          "fieldMix": [
            {
              "field": "Systems programming",
              "percentage": 60
            },
            {
              "field": "Platform engineering",
              "percentage": 40
            }
          ],
          "patterns": []
        },
        {
          "id": "caccf725-e955-4cff-a109-f66448a660f8",
          "key": "SKERNEL-106",
          "title": "Bound open descriptors while scanning a deep inbox",
          "type": "BUG",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 240,
          "phaseId": "control",
          "dependsOn": [
            "SKERNEL-101",
            "SKERNEL-105"
          ],
          "scenario": "Recursive scanning opens every subdirectory before closing any, exhausting the process descriptor limit.",
          "acceptanceCriteria": [
            "Traversal has an explicit descriptor and work-queue bound",
            "Directory handles close on success, skip, and error",
            "Unreadable entries are reported without aborting unrelated roots"
          ],
          "implementationNotes": [
            "Use a generated tree and configured low limit; do not change host-wide limits."
          ],
          "verification": [
            "Scan a deep and wide tree while measuring peak open handles.",
            "Inject an unreadable directory and repeated short reads, then check cleanup."
          ],
          "deliverables": [
            "Bounded scanner and descriptor accounting test"
          ],
          "rollout": "Start with one configured root and expose incomplete scans.",
          "skills": [
            "Resource bounds",
            "Directory traversal",
            "Cleanup"
          ],
          "fieldMix": [
            {
              "field": "Systems programming",
              "percentage": 70
            },
            {
              "field": "Performance engineering",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "5fce6797-7c0f-451b-84b8-ee5e2ff1ab9d",
          "key": "SKERNEL-107",
          "title": "Prevent path traversal through a watched-root handle",
          "type": "STORY",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 360,
          "phaseId": "control",
          "dependsOn": [
            "SKERNEL-102",
            "SKERNEL-106"
          ],
          "scenario": "A path is validated under the inbox, then a directory is replaced with a symlink before open, escaping the allowed root.",
          "acceptanceCriteria": [
            "Operations resolve relative to an already opened trusted root",
            "Traversal rejects symlinks or verifies each component under declared policy",
            "Validation and use cannot be separated by an attacker-controlled rename"
          ],
          "implementationNotes": [
            "Use temporary synthetic directories and no elevated privileges."
          ],
          "verification": [
            "Open and replace normal nested fixture files through the root handle.",
            "Race a directory-to-symlink swap and confirm no outside file is read or changed."
          ],
          "deliverables": [
            "Root-relative filesystem adapter and race regression"
          ],
          "rollout": "Fail closed on platforms where the required safe primitive is unavailable.",
          "skills": [
            "Filesystem security",
            "TOCTOU",
            "Path handling"
          ],
          "fieldMix": [
            {
              "field": "Systems programming",
              "percentage": 65
            },
            {
              "field": "Security",
              "percentage": 35
            }
          ],
          "patterns": []
        },
        {
          "id": "e34489e6-9281-463d-a64d-613056a4f8cd",
          "key": "SKERNEL-108",
          "title": "Expose platform capability instead of silently changing semantics",
          "type": "CHORE",
          "priority": "HIGH",
          "difficulty": "ADVANCED",
          "estimateMinutes": 240,
          "phaseId": "operate",
          "dependsOn": [
            "SKERNEL-102",
            "SKERNEL-105"
          ],
          "scenario": "The Windows fixture cannot provide the same directory-flush guarantee as the Unix adapter, but both report durable replacement.",
          "acceptanceCriteria": [
            "Adapter reports exact supported capabilities",
            "Callers can require a capability and fail before mutation",
            "Fallback semantics have distinct result codes and documentation"
          ],
          "implementationNotes": [
            "Do not erase platform differences behind a boolean success value."
          ],
          "verification": [
            "Run the shared contract against two declared capability fixtures.",
            "Require directory durability from an unsupported fixture and confirm no replacement starts."
          ],
          "deliverables": [
            "OS capability model and cross-adapter contract suite"
          ],
          "rollout": "Gate each deployment profile on its required capability set.",
          "skills": [
            "Portability",
            "Capability modeling",
            "Contract testing"
          ],
          "fieldMix": [
            {
              "field": "Systems programming",
              "percentage": 70
            },
            {
              "field": "Platform engineering",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "09c90ea3-c784-4dac-b27d-082534c5dbe3",
          "key": "SKERNEL-109",
          "title": "Recover an orphaned temporary replacement after restart",
          "type": "TASK",
          "priority": "HIGH",
          "difficulty": "EXPERT",
          "estimateMinutes": 360,
          "phaseId": "operate",
          "dependsOn": [
            "SKERNEL-102",
            "SKERNEL-107",
            "SKERNEL-108"
          ],
          "scenario": "A crash leaves temporary files beside the destination; startup cannot tell whether they are incomplete writes or a replacement ready to finish.",
          "acceptanceCriteria": [
            "Temporary name binds operation identity and expected content hash",
            "Recovery verifies destination and temporary content before action",
            "Ambiguous or foreign files remain untouched and visible"
          ],
          "implementationNotes": [
            "Cleanup is scoped to the opened trusted root and never follows links."
          ],
          "verification": [
            "Recover before-rename and after-rename crash fixtures idempotently.",
            "Place a foreign matching-looking file and confirm the agent records but does not delete it."
          ],
          "deliverables": [
            "Replacement journal and startup reconciliation drill"
          ],
          "rollout": "Run recovery in report-only mode before enabling scoped cleanup.",
          "skills": [
            "Crash consistency",
            "Reconciliation",
            "Filesystem safety"
          ],
          "fieldMix": [
            {
              "field": "Systems programming",
              "percentage": 70
            },
            {
              "field": "Site reliability",
              "percentage": 30
            }
          ],
          "patterns": []
        },
        {
          "id": "2ecab357-7137-4aa9-a3ae-991a3b30a03e",
          "key": "SKERNEL-110",
          "title": "Package the OS adapter without requesting unnecessary privilege",
          "type": "BUG",
          "priority": "MEDIUM",
          "difficulty": "INTERMEDIATE",
          "estimateMinutes": 150,
          "phaseId": "operate",
          "dependsOn": [
            "SKERNEL-107",
            "SKERNEL-108",
            "SKERNEL-109"
          ],
          "scenario": "An installer manifest requests administrator access even though the agent operates only inside a user-selected directory.",
          "acceptanceCriteria": [
            "Document required paths, handles, notifications, and permissions",
            "Default installation runs as an unprivileged user",
            "Unavailable optional watcher capability falls back visibly to polling"
          ],
          "implementationNotes": [
            "Do not install services, modify the registry, or request real privilege in the exercise."
          ],
          "verification": [
            "Run the packaged local fixture under a restricted temporary account profile.",
            "Remove watcher capability and verify bounded polling without elevated fallback."
          ],
          "deliverables": [
            "Privilege inventory, packaging manifest, and fallback test"
          ],
          "rollout": "Keep installation local and reversible until platform review is complete.",
          "skills": [
            "Least privilege",
            "Packaging",
            "Operational documentation"
          ],
          "fieldMix": [
            {
              "field": "Systems programming",
              "percentage": 70
            },
            {
              "field": "DevOps",
              "percentage": 30
            }
          ],
          "patterns": []
        }
      ],
      "id": "4b77692b-e1a3-4649-874d-e84670d9a8ce"
    }
  ]
}
