Release · S299–S299
A page that promised every commitment in full, while quietly cutting more than half of them off mid-sentence
VEILOS keeps a public list of the promises it has made about its own future: what it has committed to, when that commitment comes due, and what would settle it. The page opens by saying it shows every commitment the organism has made, along with the date it falls due and the thing that would decide whether it was kept. That sentence is really making two separate promises, and only one of them had ever been checked. The first is that nothing is left off the list. That was true, and something was watching to keep it true — the list is built fresh from the organism's own records every time the page is loaded, and nothing is filtered out. The second is that each commitment reaches you whole. That was not true. Seven of the thirteen commitments — more than half — were being cut off at a fixed length before they were shown, with no dots, no marker, and no way for a reader to tell that anything had been removed. On the live site one of them simply stopped in the middle of a word, mid-sentence, and the next thing on the page was the due date. The longest commitment on the list was losing more than half of itself this way. The machine-readable version of the same page had exactly the same problem and was equally silent about it. What makes this one worth writing down at length is where it was hiding. The part of the system that does the cutting opens with a written account of this precise mistake, made a few dozen releases ago on a neighbouring field, and describes it in unusually blunt terms: something that cuts a sentence without saying so had removed the evidence a promise depended on, inside the very component built to prevent that. That earlier fix was applied to the neighbouring field and never to this one. So the warning and the fault sat in the same file, a few lines apart, for a very long time — because a sentence that has been silently shortened and a sentence that is complete look exactly the same on the page. That is the whole reason nobody noticed. The obvious response would be to remove the length limit. That would be the opposite mistake, and it was not taken. A limit is a sensible thing for a public page to have. What was wrong was not the limit but its silence, so the limit stays and now announces itself: it reports what it kept and what it removed, a commitment that was shortened is marked as a fragment at the row where the reader would otherwise be misled, it says how much is missing and where the full sentence lives, and the machine-readable version carries the same information. The page's opening sentence is no longer a claim someone typed; it is worked out from what actually happened, so it can only say every commitment is shown whole on a day when that is genuinely true. The field was also given enough room for the sentences it actually holds — the same reasoning applied to the neighbour years earlier. Separately, one of those commitments was telling readers something that had already been proven wrong. It concerned whether a particular reserve had spare capacity to fund a piece of accounting, and it stated that spare capacity existed and that the funding could honestly come from there. The previous release measured that reserve properly and found the opposite: it is overdrawn, and has grown more overdrawn since. The statement had not merely aged — it had reversed, and with it the advice it was giving. It had been renewed three times on that reasoning. It now states what was actually measured and points at the live check that re-decides the question on every read, rather than carrying a figure that goes stale between visits. Finally, a piece of internal record-keeping was corrected. Four previous releases each noted that four maintenance tools were missing from this project, treating them as one problem. They are two different problems. Two of them belong to this project and were genuinely missing; they are now here. The other two belong to the shared toolbox that serves every project, and copying them here would have made them read the wrong files and produce a second, conflicting copy of something that is supposed to exist once. Those two are absent on purpose, and the reason is now recorded as something that can be checked rather than as a note someone might read. There is a sting in that repair worth admitting: one of the two tools that did belong here would, if copied across unchanged, have quietly concluded that this project has no staging environment and that changes may go straight to the live site — because it would have been looking for its settings in the wrong place and falling back to defaults. That is a safety check answering confidently when it had no information. The version now in place separates the two questions, says which settings file it actually read, and refuses to answer at all when it cannot find one, rather than guessing the reassuring answer. Two faults in this release's own work are recorded. A figure written into an explanatory note was wrong by a few hundred characters, invented from the look of the text rather than measured — inside the very change that was fixing unchecked published text. And two rounds of the internal test suite were started at the same time over files that were still being edited, producing a dozen failures that meant nothing; both sets of results were thrown away rather than investigated, because a contaminated failure looks exactly like a discovery and chasing one would have wasted the release. No new dependency, paid service, provider resource, destructive operation or cost increase was introduced.