{"affected_cards": ["2026-07-31-dmr", "2026-07-31-sar", "2026-08-01-dmr", "2026-08-01-sar"], "contributing_factor": "CI checks out the public archive at a pinned commit that was 13 commits stale and predated all four cards, so the byte-identity test could not have caught this. The pin has been advanced and its licensed-data scan re-verified.", "correction_ts_utc": "2026-08-01T18:05:00+00:00", "defect_id": "PD-2026-08-01-01", "detection_ts_utc": "2026-08-01T16:40:00+00:00", "discovered_by": "SELF_FOUND", "discovery_route": "tests/test_complete_build.py::test_a_second_build_is_byte_identical reported non-deterministic output; investigating that failure surfaced the live rendering defect", "entry_type": "provenance_defect", "evidence_document": "docs/known_issues/build_writes_into_its_own_source_tree.md", "fix": "scripts/build_deployable_site.py now regenerates record.json, proof_status.json and proof_registry.json BEFORE rendering. Verified from a genuinely clean checkout -- site/ and all three regenerated files deleted -- that two consecutive builds differ in 0 of 208 files and all four cards render their block on the first build.", "not_the_cause": "Not a missing, invalid, expired or mis-targeted proof, and not a hash discrepancy. No card, ledger entry, recorded hash or timestamp proof was altered at any point.", "proofs_evidence": [{"artifact": "card.json.ots", "card": "2026-07-31-dmr", "committed_digest_prefix": "38a2c1953e", "ots_status": "CALENDAR_PENDING", "proof_targets_current_bytes": true}, {"artifact": "card.json.ots", "card": "2026-07-31-sar", "committed_digest_prefix": "6b6a065dc0", "ots_status": "CALENDAR_PENDING", "proof_targets_current_bytes": true}, {"artifact": "card.json.ots", "card": "2026-08-01-dmr", "committed_digest_prefix": "e8e8657c2f", "ots_status": "CALENDAR_PENDING", "proof_targets_current_bytes": true}, {"artifact": "card.json.ots", "card": "2026-08-01-sar", "committed_digest_prefix": "e4a0b565b4", "ots_status": "CALENDAR_PENDING", "proof_targets_current_bytes": true}], "proofs_existed": true, "record_impact": "NONE", "record_impact_note": "No selection, result, grade or published figure changed. The defect was entirely in what the page displayed about verification.", "root_cause": "The site build rendered pages BEFORE regenerating proof_status.json, and it writes that file into the same tree it reads its inputs from. A build on a clean checkout therefore rendered from whatever proof_status.json happened to be committed, and the committed copy covered 17 of 21 cards -- it did not yet list these four. The renderer found no proof entry for them and emitted no verification block. The build then overwrote the stale file, so a second build produced different bytes from the first.", "scheduled_fix": "The build still writes into its own source tree, which is the property that made this possible. Making the archive root read-only input is scheduled and recorded in docs/known_issues/build_writes_into_its_own_source_tree.md.", "schema": "provenance-defect-1.0", "severity": "PUBLIC_SURFACE_DISPLAY", "what_readers_saw": "These four card pages rendered with no 'Verifying this card' block: no downloadable artifact hash and no OpenTimestamps status. Cards from 07-25 and 07-26 displayed theirs normally, so the omission read as arbitrary rather than as a build stage that had not run.", "window_end_utc": "2026-08-01T18:05:00+00:00", "window_note": "approximately two days; began when the 07-31 cards published", "window_start_utc": "2026-07-31T00:00:00+00:00"}
