Summary
After generating a disposable asset and deleting its file, the identical request returned success=true, is_cached=true, and the old asset URL; the runner was called only once. creative_runner.py:211 trusts cache.py:120 without checking output availability.
Environment and evidence
- Review finding: F11 (2026-10-05 product/technical review).
- Baseline: Windows,
dev at c1c5dbe. The remote dev matched this commit when filing.
- Evidence: Reproduced.
- Priority recommendation: P1 - proposed first-release blocker. This is review triage, not a production-incident severity declaration.
- No real credentials, paid inference, engine installation, or unrelated process termination were used for review probes. Mocked observations establish the stated code behavior, not live-provider/GPU acceptance.
Reproduction or validation
- In a disposable asset/cache database, execute a seed=42 request with the engine mocked to return a managed fixture asset.
- Delete only that fixture's output file.
- Submit the identical request.
Observed: success=True, is_cached=True, old asset URL, and only one engine call although the file is absent.
User impact
Users see a successful result that cannot be displayed or exported; R09 and R16 require valid output reuse.
Proposed approach
Validate cache output references and files, invalidate broken entries, and recompute or report an actionable missing-output state. Add startup reconciliation and tests for deleted/corrupt assets.
Acceptance criteria
Verification scope
Real GPU inference, paid-provider compatibility, and a clean-machine packaged desktop journey remain unverified. Any follow-up implementation should target dev under the repository's contribution/branching rules.
Summary
After generating a disposable asset and deleting its file, the identical request returned
success=true,is_cached=true, and the old asset URL; the runner was called only once. creative_runner.py:211 trusts cache.py:120 without checking output availability.Environment and evidence
devat c1c5dbe. The remotedevmatched this commit when filing.Reproduction or validation
Observed: success=True, is_cached=True, old asset URL, and only one engine call although the file is absent.
User impact
Users see a successful result that cannot be displayed or exported; R09 and R16 require valid output reuse.
Proposed approach
Validate cache output references and files, invalidate broken entries, and recompute or report an actionable missing-output state. Add startup reconciliation and tests for deleted/corrupt assets.
Acceptance criteria
Verification scope
Real GPU inference, paid-provider compatibility, and a clean-machine packaged desktop journey remain unverified. Any follow-up implementation should target
devunder the repository's contribution/branching rules.