{
  "schemaVersion": "protocol-case-1.0",
  "name": "Duplicate withdrawal deliveries against one account",
  "assumptions": [
    "serializable-atomic-transactions",
    "rollback-on-abort-and-retry-exhaustion",
    "commit-unknown-may-commit",
    "stable-time-within-attempt",
    "no-unmodeled-writers",
    "preauthenticated-principals"
  ],
  "initialRows": {
    "accounts": {
      "alice": { "id": "alice", "owner": "alice", "balance": 50000 }
    },
    "withdrawal_receipts": {}
  },
  "initialize": [],
  "requests": [
    {
      "instance": "engine-a",
      "delivery": "engine-a",
      "call": {
        "binding": "Ledger/Withdrawal::withdraw",
        "arguments": {
          "principal": { "user_id": "alice", "roles": [] },
          "input": { "idempotency_key": "w-1", "amount": 2500 }
        }
      }
    },
    {
      "instance": "engine-b",
      "delivery": "engine-b",
      "call": {
        "binding": "Ledger/Withdrawal::withdraw",
        "arguments": {
          "principal": { "user_id": "alice", "roles": [] },
          "input": { "idempotency_key": "w-1", "amount": 2500 }
        }
      }
    }
  ],
  "times": [1000],
  "externalResults": {},
  "invariants": [],
  "traceInvariants": [
    {
      "name": "exact-durable-receipt",
      "kind": "return-receipt",
      "table": "withdrawal_receipts",
      "keyBinding": "Ledger/Withdrawal::receipt_key",
      "keyArguments": {
        "principal": "request.principal",
        "input": "request.input"
      },
      "resultPath": [
        { "constructor": "Committed" },
        { "field": "value" },
        { "field": "balance_after" }
      ],
      "rowPath": [{ "field": "balance_after" }]
    },
    {
      "name": "receipts-never-rewritten",
      "kind": "immutable-rows",
      "table": "withdrawal_receipts"
    }
  ],
  "witnesses": [
    {
      "name": "receipt-reachable",
      "kind": "table-nonempty",
      "table": "withdrawal_receipts"
    },
    { "name": "returned", "kind": "event", "event": "returned" }
  ],
  "bounds": {
    "maxStates": 100000,
    "maxDepth": 20,
    "maxFaults": 1,
    "maxCrashes": 1,
    "maxOperations": 1000
  }
}
