# Case facts for the storefront (the only facts allowed on the page)

Source: Build Guard Customer Zero run (Projects/noumenon-build-guard, docs/build-guard-standard-v0.1/P0_RESULTS.md,
tests/fixtures/review/notes-broken and notes-clean) and the dated records in Projects/latent-os docs/BUILD_SPEC.md section 9.
Everything below is a test result on a fixture app or a fix on one of the studio's own live apps. None is a client project. Say so on the page.

<a id="sample-repair-report"></a>

## Sample repair report: the "notes" app (a test app built to be broken, then fixed)
The app: a small Node 22 notes service with login, saving, reading and deleting notes, a health endpoint, JSON storage, zero third-party packages.
What was run, in this order, from a clean copy on a fresh checkout with its own data directory:
1. `npm ci --offline --ignore-scripts` (install exactly what is declared)
2. `npm run setup` (create empty storage and users A, B and admin)
3. `npm test` (two tests must be discovered and pass)
4. `npm start`, then `/health` must answer 200 with ok:true, and must answer 503 with ok:false when the storage file is unreadable
5. Journeys as user A and user B through the real interface: log in, save a note, read it, delete it, try to read the other user's note
6. Error paths: a missing route, malformed JSON to /login, an invalid note id

Before (notes-broken): verdict HOLD. Four release blockers, each with evidence:
- Duplicate idempotency mutation (BG-F-001): repeating the same save request created a second note instead of returning the first.
- Cross-user direct read (BG-F-002): user B could read user A's note by changing the id in the request.
- Documented setup fails (U03, U04): the README's setup command does not exist as documented; the app silently works around it.
- Delete journey failed (J2): the interface says the note is deleted; the note is still there after a refresh.
Login and saving (J1) and reading (J3) passed. Health checks passed.

After (notes-clean): verdict VERIFIED. The same six steps, no release blockers, no evidence blockers. Health, both journeys and the error paths pass.

How to re-check: run the six steps above on the delivered code with a fresh DATA_DIR and PORT. The report lists each command, its exit code, its output tail and the observed HTTP status, so anyone can repeat it.

<a id="studio-apps"></a>

## Fixes on the studio's own live apps (dated, from the records)
- Build Guard (buildguard.noumenon-ai.com): a desktop navigation was invisible on the live page and had passed review because nobody looked at the page. Found by looking at the page, fixed 2026-09-08. A 5 minute edge cache served stale sample routes; fixed by no-store on sample routes.
- LinkSelf (linkself.net): all eight demo pages shipped light text on no background; fixed 2026-08-31. An install flag (--omit=optional) caused a production outage on 2026-06-16; the fix was to never install without optional dependencies. Unknown slugs returned soft 404s until dynamicParams was set to false.
- Tiniary (iOS): App Review rejected 1.0 because an empty password produced a generic "could not complete that request" message that read as a server failure while the backend was healthy; fixed with field-level messages in build 11 (live since 2026-08-26).
- Duskline (iOS): subscription review stalled on a hidden MISSING_METADATA state that turned out to be territory availability; set through the API for 175 territories, 2026-08-24.
- noumenon-ai.com itself: down from 2026-09-08 to 2026-09-20 because its A record pointed at a dead host and nobody noticed. Fixed by repointing DNS and attaching the domain to the host.

## Public code the visitor can read
- https://github.com/Noumenon-ai/AutoMaxFix (a reliability layer for AI-built systems: detect failures, fix, verify)
- https://github.com/Noumenon-ai/hexis-mcp-guard (security scanner for MCP servers)
- https://github.com/Noumenon-ai/cve-guard (scan projects for CVEs in AI-generated dependencies)
Do not link claude-doctor: no public repository exists under that name.

## Open-source case (public record, 2026-09-24)
openchamber/openchamber (MIT, about 10,500 stars): issue 3906 "chat input: file mentions fail for paths containing spaces", opened 08:14 UTC by a user, confirmed by the maintainer. Root cause: the mention scanner regex stopped at whitespace. Our pull request 3925 (opened 12:14 UTC): 66 lines added, 5 removed, 5 files, including a regression test. The maintainer had commented "Fixed on our side" at 12:00 UTC, closed the PR at 17:12 UTC with "Thanks for the fix and the regression test, and sorry I didn't catch your PR." Not merged; the maintainer's own fix shipped in 2.0.1. Say exactly that. The private thank-you email is not quoted.
