# noCV engineering task library

Content version 5

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.

## COBJS — Resumable object uploads with verified completion

Fictional document archive Fern stores synthetic byte objects. Use a local S3-compatible adapter or deterministic in-memory provider; no cloud credentials are needed.

**Field:** Storage systems. **Suggested stack:** TypeScript, S3-compatible adapter, PostgreSQL adapter, Vitest.

**Engineer value:** Practice object lifecycle, retry semantics and integrity verification.

**Company value:** Inspect whether uploads avoid corruption, orphan cost and tenant crossover.

**Delivery agreement:** Submit bounded coordinator changes; external cloud rollout is separate.

### Setup prerequisites

- Generate small deterministic byte fixtures.

- Implement local multipart provider responses including timeout and missing parts.

### Define upload ownership

Specify keys, parts and quotas.

#### COBJS-101 — Normalize object names without treating them as filesystem paths

**Task · Medium priority · Foundational**

noCV practice brief v5 · COBJS-101 · Resumable object uploads with verified completion

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Define upload ownership. Depends on: No preceding ticket.

Difficulty: Foundational. Estimated focused work: 75 minutes; setup and prerequisite tickets are additional.

Estimated field mix: API design 60% · Storage systems 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The upload API accepts ambiguous separators and empty names. Define an opaque object-name contract.

Acceptance criteria

- Valid names retain documented characters

- Empty and oversized names fail

- Normalization collisions are rejected

Implementation constraints

- Object keys are not local file paths.

Verification

- Store valid unicode name

- Reject colliding normalized names

Deliverables

- Name validator and examples

Rollout and recovery: Reject new ambiguous names while keeping existing reads.

Project prerequisites: Generate small deterministic byte fixtures. Implement local multipart provider responses including timeout and missing parts.

Engineer value: Practice object lifecycle, retry semantics and integrity verification.

Company value: Inspect whether uploads avoid corruption, orphan cost and tenant crossover.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### COBJS-102 — Bind multipart upload sessions to organization and object identity

**Bug · High priority · Intermediate**

noCV practice brief v5 · COBJS-102 · Resumable object uploads with verified completion

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Define upload ownership. Depends on: COBJS-101.

Difficulty: Intermediate. Estimated focused work: 120 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 60% · Storage systems 40%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A session ID can currently be reused against a different object. Require its original scope on every part operation.

Acceptance criteria

- Matching owner uploads

- Foreign organization is denied

- Changed object identity is rejected

Implementation constraints

- Enforce scope in the repository/provider boundary.

Verification

- Upload own part

- Reuse session against foreign object

Deliverables

- Scoped session adapter and denial cases

Rollout and recovery: Pause multipart writes if scope is uncertain.

Project prerequisites: Generate small deterministic byte fixtures. Implement local multipart provider responses including timeout and missing parts.

Engineer value: Practice object lifecycle, retry semantics and integrity verification.

Company value: Inspect whether uploads avoid corruption, orphan cost and tenant crossover.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### COBJS-103 — Reject multipart uploads exceeding declared size limits

**Task · High priority · Foundational**

noCV practice brief v5 · COBJS-103 · Resumable object uploads with verified completion

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Define upload ownership. Depends on: COBJS-102.

Difficulty: Foundational. Estimated focused work: 75 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Storage systems 50% · API design 30% · Performance engineering 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

The coordinator accepts an unlimited part list. Bound declared object size and per-session part count.

Acceptance criteria

- Valid declared sizes pass

- Part count has explicit maximum

- Rejected admission creates no provider session

Implementation constraints

- Limits must be checked before remote allocation.

Verification

- Admit small fixture

- Reject oversized declaration

Deliverables

- Admission policy and allocation checks

Rollout and recovery: Lower admission to a documented safe cap if accounting fails.

Project prerequisites: Generate small deterministic byte fixtures. Implement local multipart provider responses including timeout and missing parts.

Engineer value: Practice object lifecycle, retry semantics and integrity verification.

Company value: Inspect whether uploads avoid corruption, orphan cost and tenant crossover.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Complete reliably

Handle retries and integrity boundaries.

#### COBJS-104 — Retry the same multipart part without creating contradictory receipts

**Bug · High priority · Advanced**

noCV practice brief v5 · COBJS-104 · Resumable object uploads with verified completion

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Complete reliably. Depends on: COBJS-102, COBJS-103.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Storage systems 50% · Distributed systems 50%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A timeout after part acceptance leads to duplicate receipts with different checksums. Bind retries to part number and digest.

Acceptance criteria

- Same bytes return stable receipt

- Different bytes require explicit replacement

- Uncertain responses reconcile with provider state

Implementation constraints

- Provider ETag is opaque unless contract says otherwise.

Verification

- Retry identical part

- Retry changed bytes under same operation

Deliverables

- Part-retry coordinator and cases

Rollout and recovery: Stop retries and expose reconciliation status.

Project prerequisites: Generate small deterministic byte fixtures. Implement local multipart provider responses including timeout and missing parts.

Engineer value: Practice object lifecycle, retry semantics and integrity verification.

Company value: Inspect whether uploads avoid corruption, orphan cost and tenant crossover.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### COBJS-105 — Validate ordered multipart completion against acknowledged parts

**Task · High priority · Advanced**

noCV practice brief v5 · COBJS-105 · Resumable object uploads with verified completion

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Complete reliably. Depends on: COBJS-104.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Storage systems 80% · API design 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Completion silently omits a middle part and produces a shorter object. Check the requested manifest before finalization.

Acceptance criteria

- Required part numbers are contiguous

- Receipts match acknowledged digests

- Missing parts prevent completion

Implementation constraints

- Define final-part size exception explicitly.

Verification

- Complete ordered fixture

- Omit or duplicate middle part

Deliverables

- Completion validator and negative cases

Rollout and recovery: Disable completion until manifest validation recovers.

Project prerequisites: Generate small deterministic byte fixtures. Implement local multipart provider responses including timeout and missing parts.

Engineer value: Practice object lifecycle, retry semantics and integrity verification.

Company value: Inspect whether uploads avoid corruption, orphan cost and tenant crossover.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### COBJS-106 — Verify completed object content before marking it available

**Story · High priority · Advanced**

noCV practice brief v5 · COBJS-106 · Resumable object uploads with verified completion

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Complete reliably. Depends on: COBJS-105.

Difficulty: Advanced. Estimated focused work: 180 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Storage systems 80% · Backend 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Provider completion succeeds but the assembled bytes differ from the expected digest. Introduce a verification state.

Acceptance criteria

- Available requires digest agreement

- Mismatch quarantines the object

- Verification retries do not republish

Implementation constraints

- Use bounded streaming hashing, not full-memory buffering.

Verification

- Verify matching bytes

- Flip one completed byte

Deliverables

- Post-completion verifier and corruption cases

Rollout and recovery: Keep newly completed objects unavailable if verification fails.

Project prerequisites: Generate small deterministic byte fixtures. Implement local multipart provider responses including timeout and missing parts.

Engineer value: Practice object lifecycle, retry semantics and integrity verification.

Company value: Inspect whether uploads avoid corruption, orphan cost and tenant crossover.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### COBJS-107 — Recover a timeout between multipart finalization and metadata commit

**Bug · High priority · Expert**

noCV practice brief v5 · COBJS-107 · Resumable object uploads with verified completion

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Complete reliably. Depends on: COBJS-105, COBJS-106.

Difficulty: Expert. Estimated focused work: 240 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Storage systems 50% · Distributed systems 30% · Database engineering 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

A crash after provider completion leaves the session looking incomplete. Reconcile provider outcome without creating another object.

Acceptance criteria

- Recovery locates the finalized identity

- Metadata transition repeats safely

- Ambiguous provider state stays unresolved

Implementation constraints

- Persist the completion operation before dispatch.

Verification

- Crash after finalization

- Return inconclusive provider lookup

Deliverables

- Completion journal and crash schedule

Rollout and recovery: Pause automatic completion recovery and retain session metadata.

Project prerequisites: Generate small deterministic byte fixtures. Implement local multipart provider responses including timeout and missing parts.

Engineer value: Practice object lifecycle, retry semantics and integrity verification.

Company value: Inspect whether uploads avoid corruption, orphan cost and tenant crossover.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

### Recover abandoned work

Reclaim resources and inspect outcomes.

#### COBJS-108 — Abort expired multipart sessions without touching completed objects

**Chore · Medium priority · Intermediate**

noCV practice brief v5 · COBJS-108 · Resumable object uploads with verified completion

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Recover abandoned work. Depends on: COBJS-107.

Difficulty: Intermediate. Estimated focused work: 135 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Storage systems 70% · Site reliability 30%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Abandoned sessions retain billable parts. Add expiry cleanup with a guarded session transition.

Acceptance criteria

- Only expired open sessions abort

- Completed objects remain readable

- Repeated abort is harmless

Implementation constraints

- Compare session state immediately before provider action.

Verification

- Clean abandoned fixture

- Race cleanup with completion

Deliverables

- Session cleanup and race case

Rollout and recovery: Disable cleanup if finalization state is uncertain.

Project prerequisites: Generate small deterministic byte fixtures. Implement local multipart provider responses including timeout and missing parts.

Engineer value: Practice object lifecycle, retry semantics and integrity verification.

Company value: Inspect whether uploads avoid corruption, orphan cost and tenant crossover.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### COBJS-109 — Expose multipart upload progress from acknowledged bytes

**Story · Medium priority · Intermediate**

noCV practice brief v5 · COBJS-109 · Resumable object uploads with verified completion

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Recover abandoned work. Depends on: COBJS-104, COBJS-108.

Difficulty: Intermediate. Estimated focused work: 105 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Frontend 50% · Storage systems 30% · API design 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Progress reaches 100 percent before the provider accepts the final part. Count acknowledged bytes separately from verification state.

Acceptance criteria

- Progress uses accepted parts

- Completion remains pending verification

- Retransmission does not double-count

Implementation constraints

- Do not treat socket bytes sent as durable storage.

Verification

- Upload three parts

- Timeout accepted part and reconcile

Deliverables

- Progress projection and cases

Rollout and recovery: Display state-only progress if byte accounting diverges.

Project prerequisites: Generate small deterministic byte fixtures. Implement local multipart provider responses including timeout and missing parts.

Engineer value: Practice object lifecycle, retry semantics and integrity verification.

Company value: Inspect whether uploads avoid corruption, orphan cost and tenant crossover.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.

#### COBJS-110 — Export multipart failure diagnostics without signed URLs

**Chore · Low priority · Intermediate**

noCV practice brief v5 · COBJS-110 · Resumable object uploads with verified completion

Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.

Phase: Recover abandoned work. Depends on: COBJS-109.

Difficulty: Intermediate. Estimated focused work: 90 minutes; setup and prerequisite tickets are additional.

Estimated field mix: Security 50% · Site reliability 30% · Storage systems 20%.

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Support dumps provider receipts containing temporary access URLs. Add an allowlisted diagnostic projection.

Acceptance criteria

- Includes operation and part counts

- Omits signatures and object content

- Errors use bounded categories

Implementation constraints

- Signed URLs are bearer capabilities.

Verification

- Export failed session

- Inject signed URL in provider error

Deliverables

- Diagnostic schema and redaction checks

Rollout and recovery: Disable exports if bearer data appears.

Project prerequisites: Generate small deterministic byte fixtures. Implement local multipart provider responses including timeout and missing parts.

Engineer value: Practice object lifecycle, retry semantics and integrity verification.

Company value: Inspect whether uploads avoid corruption, orphan cost and tenant crossover.

AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.

Planning status does not create Outcome Evidence or Ownership Evidence.
