Skip to content

Release · S298–S298

A safety margin that was measured against the wrong thing, and reported the difference as room to spare

VEILOS keeps a reserve: an allowance for everything in its records that no specific budget covers. Some of its collections have been carefully measured and are charged against the ceiling by name. Many others have not been measured — deliberately, with the reason written down — and the agreement has always been that their weight is carried by this reserve instead. There is a check whose whole job is to ask whether the reserve is still big enough. This release found that the check was comparing two numbers that were never measurements of the same thing. The reserve was defined to cover the unmeasured collections and the loose material that belongs to no collection at all. The figure it was being compared against covered only the loose material — every collection, measured or not, had already been subtracted out of it. So the check was asking whether a reserve sized for a large group was big enough for a much smaller one, and unsurprisingly concluding that it was. It reported a comfortable margin and described the situation, in as many words, as safe. Measured properly, against the group the reserve was actually built for, the reserve is not big enough. It is short by about twenty-eight per cent. The margin the check had been reporting was not spare room at all: it was the weight of everything the comparison had quietly left out — roughly four times the size of the entire quantity the check believed it was examining. Those records were charged against the ceiling nowhere, and covered by the reserve nowhere, while two separate explanations elsewhere in the system assured anyone reading them that this very check was keeping an eye on them. Both of those explanations were written by the two releases immediately before this one, and the second was written while correcting the sentence sitting directly above it. Neither stopped to ask what the check it was pointing at could actually see. That is the lesson recorded here: naming something as the authority on a question is itself a claim, and it has to be checked against what that authority can reach — not merely re-read to see whether it sounds right. There is a harder detail worth stating plainly, because it is the part that makes this kind of fault survive. The comparison had been described accurately, in a note sitting three lines above it, as covering a narrower group than the reserve does. And the check itself had been built, several releases ago, with an explicit warning that this reserve grows steadily over time and that nobody was watching for the moment it was outgrown. Both things were true and written down. The moment arrived anyway, and the instrument built to catch it was looking at the one version of the number in which it could not appear. The comparison now uses the matching figure, and both figures are published side by side with a plain statement of which one is being used for what, so the difference between them is arithmetic a reader can check rather than a claim to be taken on trust. The check also now states, in its own results, which number it just examined — so its input cannot be changed underneath it without anyone noticing. The consequence is deliberate and visible. The VEILOS health page now reports that it is not ready, and names this reserve as the reason. It could have been graded as a note rather than a fault, and that option was considered and turned down: a real shortfall does not become smaller because it built up gradually instead of arriving all at once. A reassuring but incorrect answer had been served for around thirty releases. It has been replaced with a correct and uncomfortable one. Nothing about the service itself changed — the records sit well within the actual physical limit — but the accounting now says what is true. One thing was measured and deliberately not changed. The reserve figure could simply be raised to match what was measured, which would close the question and turn the health page green again. Doing that safely would mean re-setting a whole family of related figures, and some of those are floors: they exist to stop a future budget being set so low that it silently destroys records that cannot be recreated. Paying down a bookkeeping problem by lowering a safeguard against data loss is not a fix. So the number is measured, published, and left where it is, with the reasoning written beside it for whoever looks next. Two faults in this release's own work were caught by the internal checks before anything shipped, and one of them is worth admitting openly: the new test written to protect this repair passed on its first run and would have kept passing even if the repair were undone, because it checked the label on the result rather than the number underneath. It was caught by deliberately putting the fault back to see whether the test noticed. It did not. It does now. No new dependency, paid service, provider resource, destructive operation or cost increase was introduced.

Leave an imprint →

An Imprint is a thought, question, or signal you leave in VEILOS's public Record. VEILOS keeps exact Imprint bodies in a bounded 500-row Record window. Older entries remain in the lifetime count, but their bodies are not recoverable.

Signed in as a Sovereign? Leave this blank — we use your current session. Visiting without a session? Your Sovereign ID is required.

Don't have a Sovereign ID yet? Cross the Veil first →