# Module 12 — defend a local evaluation system

This is a classroom capstone, **not a production deployment** or a certificate.
Use invented data only. The native Module 12 lessons are not published merely
because this folder exists. No paid service, real key or customer data is needed.

## What is yours and what is assistance

Author SPEC.md, your integration in capstone_practice.py, your own changed-input
tests, DEFENSE.md and CASE_STUDY.md. Reuse the tested Module 10 service and Module
11 acquisition/inspection/path helpers explicitly. capstone.py supplies reviewed
loopback-only HTTP transport, exclusive output and a reference orchestration.
Copying the reference is guided work, not independent implementation.

The API uses **supplied** dimensions/frame counts, not measured pixels. The
acquisition separately measures actual retained bytes and container duration.
Findings contain invented classroom observations; neither approvals nor fixture
actors establish real human identity, creative judgment, rights or privacy.
Accepted media stays quarantined. Do not expose this system on the public Internet.

## Prerequisites and environments

Finish Modules 9–11, keep their extracted folders, and follow their own setup.
Use the separately installed Module 10 environment (FastAPI/Pydantic/Starlette/
Uvicorn/HTTPX/pytest); expose Module 11's folder through explicit PYTHONPATH.
**Do not install Module 11 into Module 10**: both kits own practice.py.
Module 12 adds no Python application dependency and needs no new installation.
The commands below run from this module-12 folder, using your actual absolute
paths, not the placeholders. CPython >=3.11 is declared; Windows 3.12.10 with
trusted FFprobe 9.0 is the executed development environment, not all platforms.

Initial trusted Module 10 test-tool installation needs Internet or a prepared
cache. The fixture workflow afterward uses only your owned loopback service.
No OpenSSL is required for learner practice. Install and trust FFprobe yourself;
never substitute an unreviewed binary or disable TLS to make an exercise pass.

### Windows PowerShell — first terminal

```powershell
$module10Python='C:/YOUR/EXTRACTED/module-10/.venv/Scripts/python.exe'
$module11Folder='C:/YOUR/EXTRACTED/module-11'
$env:DVP_FFPROBE='C:/YOUR/TRUSTED/ffprobe.exe'
$previousModulePath=$env:PYTHONPATH
$env:PYTHONPATH=$module11Folder
& $module10Python -X utf8 -B -m pytest -q test_capstone.py
& $module10Python -X utf8 -B -m evaluation_service init --db "$PWD/NEW-owned.db"
try {
  & $module10Python -X utf8 -B capstone_service.py --db "$PWD/NEW-owned.db" --ffprobe $env:DVP_FFPROBE --fixture-auth --port 8765
} finally {
  $env:PYTHONPATH=$previousModulePath
}
```

The supplied transport/orchestration has 17 public cases. --target practice
fails with NotImplementedError until you own the integration; passing reviewed
transport cases alone is not your work. The server stays running on 127.0.0.1.
Use a second terminal, then Ctrl+C only your own server. If the port is used,
choose another and use it consistently; never stop someone else's process.
For restart evidence rerun capstone_service.py on the same database, **not** NEW initialization.

### Windows PowerShell — second terminal, also in module-12

```powershell
$module10Python='C:/YOUR/EXTRACTED/module-10/.venv/Scripts/python.exe'
$module11Folder='C:/YOUR/EXTRACTED/module-11'
$env:DVP_FFPROBE='C:/YOUR/TRUSTED/ffprobe.exe'
$previousModulePath=$env:PYTHONPATH
$env:PYTHONPATH=$module11Folder
try {
  & $module10Python -X utf8 -B capstone.py --port 8765 --asset Museum_changed --media "$module11Folder/fixtures/one-second.wav" --mime audio/wav --ffprobe $env:DVP_FFPROBE --output "$PWD/NEW-reference-run"
} finally {
  $env:PYTHONPATH=$previousModulePath
}
```

Choose NEW database/output names for a new exercise; existing or partial output
is never overwritten or automatically deleted. A later failure may leave a new
folder or successful server-side writes **without** a completed export; this is
not a transaction across HTTP, SQLite and files. Diagnose retained work and use
a fresh owned run, not a blind repeat presented as rollback. The service's own
record/audit transaction remains its separate database boundary.

### macOS/Linux — equivalent explicit paths

```sh
module10_python=/absolute/module-10/.venv/bin/python
module11_folder=/absolute/module-11
export DVP_FFPROBE=/absolute/trusted/ffprobe
PYTHONPATH="$module11_folder" "$module10_python" -X utf8 -B -m pytest -q test_capstone.py
PYTHONPATH="$module11_folder" "$module10_python" -X utf8 -B -m evaluation_service init --db "$PWD/NEW-owned.db"
PYTHONPATH="$module11_folder" "$module10_python" -X utf8 -B capstone_service.py --db "$PWD/NEW-owned.db" --ffprobe "$DVP_FFPROBE" --fixture-auth --port 8765
```

In another terminal, set the same variables and run:

```sh
PYTHONPATH="$module11_folder" "$module10_python" -X utf8 -B capstone.py --port 8765 --asset Museum_changed --media "$module11_folder/fixtures/one-second.wav" --mime audio/wav --ffprobe "$DVP_FFPROBE" --output "$PWD/NEW-reference-run"
```

## Read actual evidence, then change it

The default server selects the reviewed Module 10 functions. For your own system,
initialize an owned database with your completed Module 10 implementation from
the Module 10 folder, following its setup with no Module 11 PYTHONPATH set.
Then start capstone_service.py with both `--module10-practice` followed by the
absolute path to YOUR completed Module 10 practice.py and `--operation-target practice`.
The launcher loads that explicitly selected trusted local Python code under a
separate module name, and selects Module 11's practice observer from PYTHONPATH.
It reuses only the three reviewed observation routes; auth/error middleware and
your actual transformation/repository/review remain in the selected base app.
Missing or unfinished code fails visibly at the relevant boundary, not via a
reference fallback. A responding process/dependency does not prove your code is complete.
No database is initialized, migrated or repaired by the capstone launcher.

`capstone_alternative.py` shows a different explicit-step integration that passes
the same public checks; it uses disclosed transport, not the completed reference
workflow. Studying or copying it is still guided assistance, not your authorship.

Successful CLI exit 0 prints:

```text
Actual fixture workflow retained; independent portfolio defense is still separate.
```

The NEW folder contains workflow.json plus quarantine/payload.bin and
quarantine/receipt.json. Inspect the actual files locally: measured accepted WAV,
16078 received bytes, container duration 1.0; generated evaluation/finding IDs;
current approved finding revision 3; creation snapshot still unreviewed; four
ordered persisted audit events. Generated IDs vary, not hardcoded answers.

Request/read-back parity and container observations do not prove semantic media
analysis or independent authorship. The key fields metadata_basis and
judgment_basis retain that distinction. Changing the public fixture observation
does not establish that someone watched a real clip.

1. Implement capstone_practice.run_workflow without delegating to the reference.
   Use capstone.request as disclosed transport; validate returned route IDs with
   the supplied identifier helper, use returned revisions and read real saved
   evaluation/finding/audit before exporting. Preserve the explicit evidence bases.
2. Run the public checks with --target practice; then append --target practice to
   the actual CLI command with a different NEW output folder. Keep your own code.
3. Use the second included MP4 with video/mp4 and changed asset/criterion/evidence.
   Author tests and a driver with fresh metadata and a different permitted review
   outcome. Do not claim supplied width/frames were measured by FFprobe.
4. Demonstrate actual 422 strict-schema refusal, 403 actor refusal, 409 stale/state
   conflict, accepted-but-quarantined media, dependency not-ready and safe fault.
   Use the Module 10 CONTRACT and Module 11 operator checklist for precise requests.
5. Stop/restart your own server on the same DB, then GET your stored finding and
   audit with the public fixture author token. Retain matching actual reads.

HTTP transport is narrowly 127.0.0.1, declared routes, five-second per-I/O timeout,
64 KiB request/response ceiling, public fixture actors only, no proxy/redirect.
It is not a hard whole-workflow deadline, public client or secure real identity.
Quarantine assumes an owned tree with no hostile concurrent writer; it is not
race-proof OS isolation. Process-local readiness metrics reset on restart.

Public credentials fixture-author-a and fixture-reviewer-a are not Academy login.
Nothing automatically sends logs/code/notes to the optional site tutor.

## Documents and defense

SPEC.md is a blank measurable contract with one clearly labeled example.
DEFENSE.md is an evidence/reviewer rubric, not an automated approval.
CASE_STUDY.md is a narrative template; keep private originals/credentials local.
Record guided versus independent versus self-reported versus observed evidence.
Unknown or missing evidence remains NOT READY, even with a perfect quiz score.
