01 // what
Replace a system with no code and no documentation with a deterministic, byte-for-byte replica, against cases we don't know.
movingparticle@caja-negra:~$ cat ./SYSTEM_DESIGN.txt
.~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.
/ \
/ \
/ \
/ \
+---------------------------------------------------------------------------------+
| |
| ██████╗ ██╗ █████╗ ██████╗ ██╗ ██╗ ██████╗ ██████╗ ██╗ ██╗ |
| ██╔══██╗ ██║ ██╔══██╗ ██╔════╝ ██║ ██╔╝ ██╔══██╗ ██╔═══██╗ ╚██╗██╔╝ |
| ██████╔╝ ██║ ███████║ ██║ █████╔╝ ██████╔╝ ██║ ██║ ╚███╔╝ |
| ██╔══██╗ ██║ ██╔══██║ ██║ ██╔═██╗ ██╔══██╗ ██║ ██║ ██╔██╗ |
| ██████╔╝ ███████╗ ██║ ██║ ╚██████╗ ██║ ██╗ ██████╔╝ ╚██████╔╝ ██╔╝ ██╗ |
| ╚═════╝ ╚══════╝ ╚═╝ ╚═╝ ╚═════╝ ╚═╝ ╚═╝ ╚═════╝ ╚═════╝ ╚═╝ ╚═╝ |
+---------------------------------------------------------------------------------+
FRONTIER Bogotá 2026 · Challenge 2 · 12:00 milestone.
A service has been running in production for 10 years and nobody knows how it works. We'll discover its behavior by observing it and build a replica that responds exactly the same — errors included — without ever calling it at runtime.
Replace a system with no code and no documentation with a deterministic, byte-for-byte replica, against cases we don't know.
Hypothesis-driven probing to infer the real rule, and a Cloudflare Worker (with a Durable Object for a single state) that emulates commands, states and errors.
Differential comparison oracle vs. replica, an adversarial battery, and exact parity of status and body.
A 30-second read. The technical detail is further down, in the same document.
The inside is unknown. We only see INPUT → BOX → OUTPUT. We must reconstruct the rule, not memorize examples.
A discovery harness that queries the original, and an HTTP entrypoint (Cloudflare Worker + Durable Object) that responds the same way.
Every behavior cites a line of the log. Every response is compared against the original. Nothing is claimed without proof.
| critical point | status | resolution |
|---|---|---|
| Replica not implemented | resolved | 6 commands + 17 errors in src/engine.mjs; parity 20/20. |
| Unknown control algorithm | resolved | ISO 7064 Mod 97-10 (16/16 cases + edge probes). |
| State not isolated / multi-instance | resolved | Single Durable Object global-caja-negra (one state). |
| Entrypoint not deployed | resolved | Cloudflare Workers: https://caja-negra-reemplazo.parsec-ai-labs.workers.dev. |
| 15:30 incident | open | Frozen baseline + adaptation with no regression (INCIDENT.md). |
GET /health requires a token: without one → 401 E001 (the harness sends a token on every call). The body of /__reset is {"ok":true} and is not compared by the harness. Both remain assumptions until verified against the original.Two sources side by side: green = 20 public examples (pruebas/ejemplos.jsonl) · cyan = 14 live probes against the oracle (experimentos.jsonl). Block bars, sorted, with visible n. No pies.
BASELINE (20) n bar PRUEBAS (14) n bar 200 OK 11 ███████████ 400 BAD 9 █████████ 400 BAD 4 ████ 404 MISS 3 ███ 201 NEW 2 ██ 200 OK 2 ██ 422 LIM 2 ██ 404 MISS 1 █
experimentos.jsonl). Probing settled error precedence (E303→E304→E401→E506), amount limits and the control algorithm (mod 97 checksum).arc42 §1–3 and the rubric's understanding criterion: goal, boundaries, assumptions, what is out of scope and why.
An autonomous, deterministic, public replica that responds the same as the original — same status and bodies — against a hidden set of 100 tests.
POST /msg with {"m":"CMD;arg;...;ctrl"} + Bearer token.GET /health, POST /__reset.;./__reset goes back to zero.Production on Cloudflare Workers with a Durable Object that guarantees a single global state; the same engine runs on a local Node server. Integrity with ISO 7064 Mod 97-10.
Public entrypoint: https://caja-negra-reemplazo.parsec-ai-labs.workers.dev
Each ADR states what was discarded, why, what is gained, what is sacrificed and when it would change.
npm ci && npm test && npm start in a clean environment./__reset before each of 100 tests and assumes a single process/state.global-caja-negra Durable Object guarantees a single logical state, with an in-memory reset (< 1 ms) and no disk.How we'll know it works before building it. No number, no defense.
After /__reset, the 20 examples give 20/20 on status and body (automated test).
| test | what it tries to break | expected | prio |
|---|---|---|---|
| happy path | PING → ALTA → DEPOSITO → CONSULTA | exact status and balances | P0 |
| empty | /msg with no body | same error as the original | P0 |
| unknown | SALDOS;... | 400 E301 | P0 |
| arity | too many or too few ; | 400 E302 | P0 |
| control | non-numeric field | 400 E201 / E202 | P0 |
| account | CONSULTA;AC-9999 | 404 E401 | P0 |
| limit | transfer over the threshold | 422 E506 | P1 |
| balance | transferring more than available | 422 E507 | P1 |
| void x2 | ANULA of an already voided operation | ok:false, ya anulada | P1 |
| bad route | GET /msg, unknown path | same 404/405 | P1 |
| payload | large body or broken encoding | rejection with the exact code | P1 |
| reset | /__reset without a token | like the original, without leaking the mechanism | P0 |
| incident | the case that changes at 15:30 | adapted, with no regression | P0 |
| latency | each step | < 5 s | P2 |
confirmed repeats · likely seen once or inferred · assumption is the replacement's default.
| id | behavior | evidence | confidence |
|---|---|---|---|
| C1 | PING → {pong:true} with no state | #1 | confirmed |
| C2 | command is case-insensitive | #11 CONSULTa | confirmed |
| C3 | ALTA creates an incremental AC-#### | #3 #4 | confirmed |
| C4 | the control is validated before acting | #2 #17 | likely |
| C5 | DEPOSITO credits and returns operacionId | #6 #18 #19 | confirmed |
| C6 | TRANSFER moves balance | #7 #8 | confirmed |
| C7 | there is a cap E506 and balance E507 | #9 #16 | confirmed |
| C8 | ANULA is idempotent | #13 #14 | confirmed |
| C9 | unknown command → literal 400 E301 | #12 | confirmed |
| C10 | invalid arity → 400 E302 | #20 | confirmed |
| C11 | control = ISO 7064 Mod 97-10 (A=1…Z=26, no padding, CD = 98 − (N·100) mod 97) | 16/16 + probes | confirmed |
| H1 | the control is a check digit of the payload | confirmed as ISO 7064 | confirmed |
| H2 | order: shape → control → resource → business | #15 vs #9 | likely |
| H3 | IDs are per process, they reset with reset | #3 #6 | likely |
| S1 | large payload or invalid encoding → stable error | contract | assumption |
| S2 | unknown route → same 404 | contract | assumption |
/health /__reset /*experimentos.jsonl)/saldo) exist in the original?Pattern: we chose X for A and B; we discarded Y for C; the trade-off is D; if E changes, we move to Y.