{
  "$schema": "../../schema/run.schema.json",
  "run_id": "better-auth--claude-fable-5--v2-b--2026-09-02",
  "supersedes": null,
  "replicate_of": "better-auth--claude-fable-5--v2-a--2026-09-02",
  "library": {
    "name": "better-auth",
    "ecosystem": "npm",
    "latest_version_at_test": "1.7.2",
    "latest_version_verified_on": "2026-09-02",
    "latest_version_note": "Carried from the concurrent `v2-a` draw; no separate library verification is done for the duplicated arm of one battery."
  },
  "model": {
    "id": "claude-fable-5",
    "label": "Claude Fable 5",
    "vendor": "Anthropic",
    "invoked_as": "Agent tool, model override 'fable', no tools available to the subject",
    "self_reported_cutoff": "2026-01",
    "cutoff_basis": "Self-reported: \"January 2026, as best I know\", with the volunteered qualification \"In practice my reliable coverage of fast-moving npm projects like this one degrades a few months before that.\"",
    "believed_latest_version": "1.3.0",
    "believed_latest_quote": "\"The last release line whose contents I can actually describe is 1.3.0, around July 2025, plus early 1.3.x patches (roughly into August-September 2025) that I know existed but can't itemize. I have a weak, low-confidence signal that a 1.4 shipped in late 2025.\"",
    "knowledge_stops_at_version": "1.3.0",
    "knowledge_stops_on": "2025-07-19",
    "knowledge_gap_starts_at_version": "1.4.0",
    "knowledge_gap_starts_on": "2025-11-22",
    "cutoff_lag_months": 6
  },
  "test": {
    "date": "2026-09-02",
    "battery": "better-auth/v2-b",
    "battery_spec": "prompts/better-auth.md",
    "prompt_file": "prompts/sent/better-auth-v2.txt",
    "tasks": 5,
    "direct_questions": 4,
    "tool_uses_during_test": 0,
    "probe_window": {
      "from": "1.0.0",
      "to": "1.4.2"
    },
    "self_test": false,
    "saturated": false,
    "status": "open",
    "retested_on": null
  },
  "sources": [
    "https://registry.npmjs.org/better-auth",
    "https://github.com/better-auth/better-auth/releases/tag/v1.3.0",
    "https://github.com/better-auth/better-auth/releases/tag/v1.3.8",
    "https://github.com/better-auth/better-auth/releases/tag/v1.4.0",
    "https://github.com/better-auth/better-auth/releases/tag/v1.4.2"
  ],
  "findings": [],
  "non_findings": [
    {
      "kind": "context",
      "summary": "THE MEASUREMENT, and the sharpest single answer the battery produced. This draw declared a boundary INSIDE the 1.3 patch line and then reached across it. In (c) it named its own contentless region as \"the 1.3.x patches beyond roughly 1.3.2-1.3.4\". In (d), asked where device authorization was introduced, it answered \"1.3.0 (~July 2025). Fairly confident it was a 1.3.0 headline feature, not a patch. Estimate, but a firm one\" — and gave last-login-method \"same release, same confidence\". Both shipped in 1.3.8: a release inside the very range it had just described as version numbers with no content attached. It did not merely fail to reach the patch; it explicitly ruled the patch out. The internal control passed — SAML placed at 1.3.0, correct (fact LF4) — so this is a collapse and not noise.",
      "api": "deviceAuthorization() / lastLoginMethod()",
      "introduced_in": "1.3.8",
      "why_not_a_finding": "Direct questions are belief data and are never scored as findings. This arm additionally charges nothing at all."
    },
    {
      "kind": "miss",
      "summary": "Task 3: \"better-auth does not have a fully database-free mode\", followed by cookieCache, secondaryStorage and the jwt/bearer plugins, and closing \"I don't believe there's a supported stateless-only session mode; if that's a hard requirement I'd say so plainly to the team rather than fight the library.\" Fact LF1 records that 1.4.0 (2025-11-22) added exactly that, two months before this subject's stated 2026-01 cutoff. Chargeable, and charged on the `v2-a` draw.",
      "api": "stateless / database-less sessions",
      "introduced_in": "1.4.0",
      "chargeable_miss": true,
      "miss_class": "non_charging_arm",
      "charged_on": "better-auth--claude-fable-5--v2-a--2026-09-02",
      "why_not_a_finding": "The duplicated arm of a battery does not charge findings; its twin `v2-a` carries this one as F1."
    },
    {
      "kind": "correct",
      "summary": "Tasks 1, 2 and 5 passed and matched the twin draw closely: `deviceAuthorization()` with the RFC 8628 poll loop, `lastLoginMethod()` with the non-httpOnly cookie and `storeInDatabase` option, and `customSession()` for the floor probe with the note to keep it last in the plugins array. Floor confirmed, so the boundary reading is a measurement.",
      "api": "deviceAuthorization() / lastLoginMethod() / customSession()",
      "introduced_in": "1.3.8",
      "why_not_a_finding": "Correct answers, and this arm charges nothing regardless."
    },
    {
      "kind": "imprecision",
      "summary": "Task 4, against prediction P3: the handler reads `data.user.plan` off the sign-in response — correct since 1.4.2 — then adds a defensive `getSession()` fallback behind a null check, with the comment \"in some versions the sign-in response user has been thinner than the session user\" and the note \"I remember issue traffic about whether the signIn.email response user carries additional fields in all versions.\" Four of four test-arm draws produced this same pattern: correct code, disbelieved in prose.",
      "api": "additional user fields in the sign-in response",
      "introduced_in": "1.4.2",
      "why_not_a_finding": "Code-vs-claim rule, and this arm charges nothing."
    }
  ],
  "summary": "The concurrent blind twin of `v2-a`, and the draw that states the effect most starkly. It placed its own knowledge boundary inside better-auth's 1.3 patch line — \"the 1.3.x patches beyond roughly 1.3.2-1.3.4\" are version numbers with no content attached — and then, in the next answer, attributed two plugins that shipped in 1.3.8 to 1.3.0, calling it \"a firm estimate\" and explicitly ruling out a patch. It agreed with its twin on every task and on all four attributions. It charges nothing, per the rule that the duplicated arm does not charge; its denial of database-less sessions is recorded as a chargeable miss carried by its twin."
}
