{
  "checkedAt": "2026-09-13T05:15:33.212590+00:00",
  "solver": "Z3 4.13.3.0",
  "scope": "Abstract integer refund-budget model. Each transition is atomic. No deployed software or independently verified proof certificate.",
  "results": [
    {
      "name": "01_initialization",
      "kind": "proof_obligation",
      "expected": "unsat",
      "claim": "No nonnegative captured amount violates Inv at refunded=reserved=0.",
      "file": "queries/01_initialization.smt2",
      "actual": "unsat",
      "matches_expected": true,
      "sha256": "22c2b4d4ff35c420ba8c4e94909e3e9fd11bb65ec723c0ff6589b23a6910d047",
      "solver_output": "unsat\n"
    },
    {
      "name": "02_reserve_preserves",
      "kind": "proof_obligation",
      "expected": "unsat",
      "claim": "An atomic reservation including existing reservations preserves Inv.",
      "file": "queries/02_reserve_preserves.smt2",
      "actual": "unsat",
      "matches_expected": true,
      "sha256": "60b296c9b6691e7030e365ca59a2f5cd68001b37fe176a56443ab403673b28ff",
      "solver_output": "unsat\n"
    },
    {
      "name": "03_settle_preserves",
      "kind": "proof_obligation",
      "expected": "unsat",
      "claim": "Moving an amount from reserved to refunded preserves Inv.",
      "file": "queries/03_settle_preserves.smt2",
      "actual": "unsat",
      "matches_expected": true,
      "sha256": "9cc98eaf4d882f42d97c9e451c3c9c079dbf544d051c5107fd1d653651c32d19",
      "solver_output": "unsat\n"
    },
    {
      "name": "04_release_preserves",
      "kind": "proof_obligation",
      "expected": "unsat",
      "claim": "Releasing no more than the reserved amount preserves Inv.",
      "file": "queries/04_release_preserves.smt2",
      "actual": "unsat",
      "matches_expected": true,
      "sha256": "a23c14a78a729fbf7706039ff913e86cf878fa712f194f4e4e20b3825ebffe21",
      "solver_output": "unsat\n"
    },
    {
      "name": "05_invariant_has_a_model",
      "kind": "nonvacuity_witness",
      "expected": "sat",
      "claim": "The budget invariant is satisfiable and a positive reservation is possible.",
      "file": "queries/05_invariant_has_a_model.smt2",
      "actual": "sat",
      "matches_expected": true,
      "sha256": "21f720f7853abd8fc8e4065beb52c87bbfa9ecd2774bc9da7589a5d9194b64e0",
      "solver_output": "sat\n(\n  (define-fun captured () Int\n    1)\n  (define-fun reserved () Int\n    0)\n  (define-fun amount () Int\n    1)\n  (define-fun refunded () Int\n    0)\n)\n"
    },
    {
      "name": "06_weakened_guard_counterexample",
      "kind": "deliberate_bug",
      "expected": "sat",
      "claim": "Ignoring reserved amounts admits an invariant-violating reservation.",
      "file": "queries/06_weakened_guard_counterexample.smt2",
      "actual": "sat",
      "matches_expected": true,
      "sha256": "331a12d716936755ad2d808f6a5c5da2f4aeb9a894941ea14ed9ae2e4b66b5b3",
      "solver_output": "sat\n(\n  (define-fun captured () Int\n    1)\n  (define-fun reserved () Int\n    1)\n  (define-fun amount () Int\n    1)\n  (define-fun refunded () Int\n    0)\n)\n"
    },
    {
      "name": "07_concrete_counterexample",
      "kind": "counterexample_replay",
      "expected": "sat",
      "claim": "With captured=100, reserved=60, refund=0, another reservation of 60 is unsafe.",
      "file": "queries/07_concrete_counterexample.smt2",
      "actual": "sat",
      "matches_expected": true,
      "sha256": "cff3fdc1291d1274559aa082a1fe8fb5f6db52a638ef1e09436e728cdd6115dc",
      "solver_output": "sat\n(\n  (define-fun refunded () Int\n    0)\n  (define-fun amount () Int\n    60)\n  (define-fun reserved () Int\n    60)\n  (define-fun captured () Int\n    100)\n)\n"
    },
    {
      "name": "08_inconsistent_premises",
      "kind": "specification_error_example",
      "expected": "unsat",
      "claim": "A negative refunded balance contradicts Inv: these premises are empty, not a useful guarantee.",
      "file": "queries/08_inconsistent_premises.smt2",
      "actual": "unsat",
      "matches_expected": true,
      "sha256": "fadf29e035639b2608f93fb72136d642a5e94c18aa2f97d1021b01844645a4a3",
      "solver_output": "unsat\n"
    }
  ]
}
