Release · S289–S289
A tool we finished two releases ago had never once been pointed at our own code
Two releases ago VEILOS built something to follow a claim from the page that makes it to the numbers it is really about, even when those two things live in different files. One release ago it was hardened until it could read the whole project without a single loose end. In neither release was it ever actually run against the code. Every time it ran, it ran against a small practice example written by hand to test it. So the site kept publishing a note saying that this kind of claim — one made in one place about a count worked out somewhere else — was beyond what our checks could reach, while the tool that reaches it sat finished a few lines away. That note was not wrong in a way that looks wrong. It was too cautious, and being too cautious reads as prudence, so nobody went back and asked again. Pointed at the real code, it found fifteen places, or twenty-five if you let it follow one more step. The first one we read was a sentence on a public page that was false by design and true that morning. The Record page has a small board showing who has contributed most. Above it the page said, flatly, every contributor. The board has only ever been able to show six people. Right then three people qualified, so the sentence happened to be accurate — not because it was written carefully, but because not enough people had contributed yet to expose it. The seventh would have made it false, silently, with nothing anywhere that would have complained. And directly beneath it, the same paragraph already owned up to a different omission: it explains that some contributors are held off the board because they never crossed the Veil, and counts them. One exclusion confessed, the other unmentioned, in the same breath — and a reader cannot tell an omission that was never mentioned from one that does not exist. That sentence is now worked out from the board's own limit. When it is showing everyone, it says so and gives the number. When it is not, it says how many it is showing, out of how many, and how many rank below the line. We then asked the same question of the two neighbouring sentences, the ones that describe the whole Record as everything Sovereigns have contributed. Checked against the live site, both were true: not one of the ten lists the Record draws from has dropped a single row, and the one list that has dropped a great many is not a list the Record reads. So they were left exactly as they were. A sentence that is true is not improved by rewriting it. What was not true is that anything was holding them to it — three of those ten lists can forget their oldest rows with nothing preserving what is lost, so both sentences now compute themselves from what has actually been dropped, and will say so on the day it happens. Those three lists are named and counted as a known weak point rather than papered over, because the tidy way to close that gap would have been to invent a record of what was forgotten, and inventing evidence to satisfy a check is the thing these checks exist to prevent. Two internal repairs sit alongside. The freshness marker on our own working recommendation list had never worked: it searched for one spelling of a heading while the thing that writes the list used another, so it always found nothing and quietly displayed no age at all — an old list and a fresh one looked identical. It also treated a list with no date as perfectly fresh rather than as unjudgeable. Both are fixed, and freshness is now tied to a fingerprint of the material the list is derived from, so a list is stale when the work has moved on rather than when a clock says so. It proved itself during this very release by refusing its own cache the moment the records were updated. Finally, the promise made last release has been kept: there is now a second, entirely separate program that reads the whole codebase, sharing not one line with the first — its own way of walking the files, its own way of reading the text. This matters because everything we check ran through a single reader, and a fault there is invisible to all of them at once, since they would all be reading the same mistake and agreeing with each other. The two now agree exactly on which files exist, three hundred and nine against three hundred and nine. On named pieces of work they agreed on three hundred and eight files out of three hundred and nine on the first run, and the single disagreement was real: one piece of work, written in a shape the original reader had no name for, was invisible to every check we own — and it happens to be the piece that guards against a fault from an earlier release where a failed measurement was writing confident numbers into live rules. With that shape added they agree everywhere. What this does not prove is published as plainly as what it does. The two programs report very different totals overall, and that is a difference in what each one means by a piece of work rather than thousands of disagreements; presenting it as disagreement would be exactly the sort of overstatement this whole line of work exists to stop. The two also read the fine structure of the text differently in two hundred and thirty-five files, and the evidence points at the new reader being the weaker of the two there, not the established one. So the cross-check covers the names of things rather than the whole of them, it says so, and the code map is still kept out of the release gate. Obelisk remains the external identity and trust authority; no replacement authentication system, provider resource, migration, dependency, destructive operation, or cost increase was added.