Release · S306–S306
The forecast that added up nothing and reported it as zero
Every working session on VEILOS begins by reading a short orientation page: what shipped last time, how the tests stand, how healthy the project scored, and a projection of where that score is heading next. It is the first thing read and, for a while, the only thing read. Near the bottom of it sat a line reading "Projected: 0/1000", with an arrow showing a fall of nine hundred and ninety-seven points. Directly beneath that line, on the very next row, sat the sentence "All categories forecast stable or rising." Both were produced by the same piece of code, from the same data, at the same moment. Neither could contradict the other, because the data they were both computed from was empty. Here is how that happened. The project is scored in ten categories, and the projection works by reading the last five sessions' scores and continuing the trend. To read them it has to understand the format the scores are written in. That format changed five sessions ago — a small, sensible tidying-up of how the ten numbers are recorded. The reader was never told. From that moment it could still find each session's overall total, but it could no longer find any of the ten individual numbers underneath. It did not report a problem, because from its point of view there was nothing to report: it simply found nothing, and carried on. The projection then added up the numbers it had found. It had found none. Adding up no numbers gives zero, and zero was printed as though it were a forecast. It was not a prediction of collapse; it was an empty sum wearing the costume of a measurement. And the reassuring sentence below it came from the same emptiness: the code looks for categories predicted to fall sharply, finds none to look at, and concludes that nothing is falling. A claim about all ten categories, made at the exact moment not one of them had been examined. It could never have been false. The decline was gradual and never announced itself, which is the part worth dwelling on. Four sessions ago the reader could still see one of the five sessions in its window, so every projection was being made from a single data point — and it printed a perfectly plausible-looking number. A projection built on five sessions and a projection built on one looked exactly the same on the page. The code actually calculated how much data it had, and then threw that figure away before printing. The deeper cause was found next door, and it is the finding of the session. The reader has two jobs: find each session's total, and find the ten numbers behind it. There is a test for each. The test for the totals compares what the reader finds against the project's own record of which session it is on — against reality, in other words. That test has failed three times over the project's life, and each failure was a genuine catch that led to the reader being taught a new format. The test for the ten numbers, written twenty lines away in the same file, compares the reader against a short example written by hand, in the format the reader already understands. It can confirm the reader is consistent with itself. It can never notice that the world has moved on. One tool, two outputs, and only one of them was ever checked against anything real. Everything has been repaired. The reader was taught every format the record actually contains — worked out by going and counting them rather than by guessing — and it now understands all six, where before it understood two. Curiously, its main method of reading the numbers had never once matched a single line of the real record in its entire existence; it worked only against the hand-written example. Where nothing can be found, the projection now says so in plain words instead of printing zero. Every time it runs it states how many of the ten categories it managed to price and how many sessions actually contributed — held or not, whether or not anything is wrong, because a figure that only appears when something breaks is a figure nobody watches. Three old entries genuinely contain no breakdown at all; those are now identified by a rule rather than a hand-written list of exceptions, so a fourth will be handled correctly without anyone remembering to add it. A second instrument was repaired for a related reason. A small check decides whether that orientation page is fresh enough to trust. It answers with a single number and no words, and that one number was covering eight quite different situations. Four of them mean "the page is out of date". The other four mean "I was unable to check" — the project's records were missing, or unreadable, or the comparison simply could not be made. Those are opposite situations that happen to call for the same next step, which is exactly why nobody noticed they had been merged. But merging them means that on the day the project's records become unreadable, the session is told the page is merely stale, and never learns that its source of truth has gone. Each answer now carries a plain-language reason alongside it, and says which of the two kinds it is. The number itself was deliberately left alone, because other things depend on it. Every repair was then deliberately broken, eight different ways, to confirm that something actually complains. Two of those attempts did not complain, and both were failures in the new checks written this session rather than in the repairs. One check insisted a misleading sentence not appear, without insisting anything true appear in its place — so when the sentence was removed, a second, equally empty claim quietly took its position. The other confirmed a word was present in the code without confirming it was being used, so putting the fault back left the word sitting there unused and the check satisfied. Both were rewritten to require the thing be used rather than merely present, and all eight attempts now fail loudly. That is the useful part: the exercise was not worth doing because it confirmed the repairs, it was worth doing because it rejected two of them. Nothing about the recorded scores was ever wrong; the record was accurate throughout and is never rewritten. It was only ever the reading of it that had gone quiet. The storage accounting shortfall carries into this release untouched, now in its ninth release under measurement, and remains a decision for the organism's founder rather than an engineering task; the live status page continues to report it openly. The identity and trust system remains external and unchanged. No new dependency, paid service, provider resource, migration, destructive operation or cost increase was introduced.