Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Projection contracts

Closed August 2026. The scanner could establish that a reference reached a repository object, but it could not hold visible documentation equal to the exact source or producer-owned value it claimed to show. This phase added one policy-owned relation instead of a family of code-, table-, and language-specific checkers. The live contract is in Controls and policy and Trusted semantic evidence; this page records why the relation is narrow.

The first step closed the completed-site fragment rules against raw and percent-decoded anchors, legacy names, redirects, invalid escapes, and duplicate targets in #570. A projection then received one stable (document, name) identity, one typed source, one adjacent visible sink, and one projection kind in #571. The scanner evaluates that closed relation in #576, while #577 makes removing it a policy weakening rather than letting deletion erase the obligation.

Exact source selection, not a formatter language

A source is already meaningful before it reaches a sink. Exact blob lines and the named regions from #572 select repository bytes. The shared typed projection primitives from #573 let a complete tree-path selection become sorted rows in #579 or a canonical decimal count in #574. Selection reuses the snapshot discovery the scan already paid for; named regions use one exact ordered marker pair and never run a regex or repository process.

Comparison normalizes line endings and removes exactly one terminal newline, but preserves every other byte. Sorted rows retain duplicate multiplicity and ordering defects. The two-pointer difference in #580 reports exact totals and bounded missing and extra previews instead of copying an unbounded mismatch into the report. The grammar is closed: there is no template language, arbitrary table schema, or source parser hidden in a sink.

Completeness controls what absence can prove

The same evaluator consumes producer-owned records. A present row can project one exact value after #583, but an absent row means absent only when the producer declared that exact set complete. Complete sets can project all display values or their count after #584; partial sets cannot prove equality, extra rows, counts, or absence. Keys remain identity even when two rows display the same value.

Projection work has its own ceilings rather than borrowing the scanner’s aggregate memory bound. #582 meters assertion count, selected and projected bytes, compared records, and copied previews independently. The retained measurements cover equal, first-different, last-different, all-different, large-row, and shared-source inputs; the limits came from integrated release runs rather than an estimate.

Local authoring does not create authority

The public scanner can bind one candidate-free semantic template to the exact invocation candidate after #585. The offline authoring command added by #586 bounds and canonicalizes specialist key/value rows into that template. Neither path executes a producer, authenticates its claims, or changes the report from self-asserted; provider authority still requires an independently planned acquisition.

Two tempting extensions deliberately did not close. A fixed two-column table has no retained user, so code blocks and exact row projections remain the visible forms. Automatic projection rewrites have no retained real findings that prove stable replacement identities; until they do, Amiss reports the exact drift and does not rewrite the sink.

Last change: , commit: a3e8a428