Experiment objects live in workspace object storage, which a script can write
directly, and results are read on the unrestricted pool — so a forged experiment
naming another flow job returned output the jobs API would have refused. Only
jobs this server stamped with that experiment's id are read now.
Also from round 9:
- recording an experiment requires write on the dataset, not read: it persists
into the dataset's namespace and its shared list
- clear the results table when the selection changes and surface a failed load,
instead of labelling the previous experiment's numbers as the new one's
- a storage fault is no longer reported as a deleted dataset
- the lock-timeout message at the recording site no longer says to retry, which
would run the whole dataset again on top of the jobs already queued
- ExperimentRow.status documents canceled and skipped
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>