# A vacuity pass that tries the contract's own mutation agrees with itself _2026-09-22 · booth_ The contract-time **vacuity pass** — for each invariant, name a change that defeats it and check the named test goes red — was proposed independently by Regin and Kimi on U4's paraphrase round, and U4's own code-review panel then showed **five of seven** U4 falsifiers were vacuous: a green test *cited* by an `INV` rather than a test that would *fail* if the invariant broke. See [[2026-09-22-vacuous-falsifiers]]. U3 ran the pass as a real instrument rather than a promise. Script in the session scratchpad; for each invariant it applies the mutation the contract's *Falsifiable:* line names, runs the single named test, and asserts a **non-zero** exit, restoring the file in a `finally` either way. | INV | mutation applied | verdict | |---|---|---| | 1 declaring page untouched | append `` to the declaring branch | FALSIFIED | | 2 appended, never inserted | insert the tag before `` instead | FALSIFIED | | 3 no regex on author HTML | re-declare `_ICON_RE` in `app.py` | FALSIFIED | | 4 openness is the server's | have `embed.js` derive open from `bk-done` | FALSIFIED | | 5 embed.js read once | `read_text()` per request in the route | FALSIFIED | | 6 tail in payload order | iterate the marks list backwards | FALSIFIED | | 7 unplaced questions appended | short-circuit the append branch to `if (false)` | FALSIFIED | **7/7**, and — the part that makes it a measurement rather than a ritual — an **unmutated control run** confirming all seven named tests are green when nothing is broken. Without that control, a script whose mutation silently failed to apply (the text not found, the wrong file) reports the same clean-looking table. The script halts with `MUTATION-MISS` if its target string is absent, for exactly that reason. ## Why it is worth the ten minutes Three of the seven falsifiers are in `embed.js`, which the Python suite cannot see at all. INV-4, INV-6 and INV-7 are held **only** by browser tests, and "there is a browser test named after this invariant" is precisely the kind of claim that feels like coverage and can be empty. Two of those three mutations are one-token edits — `marks.length - 1` and `if (false)` — so the cost of checking was minutes and the cost of being wrong was an invariant nobody was holding. **The general shape:** an instrument that cannot fail loudly will fail quietly. Same family as the `(gasp)` tag-detection specimen in the global measurement rule, and as the zsh word-splitting bug that shipped an empty heid bundle — [[2026-09-22-four-paths-to-one-fail-open-delete]]. A clean result and a broken method are indistinguishable from the output alone unless something in the method is designed to go red. ## ⚠ AND THEN THE COLD PANEL SHOWED ONE OF THE SEVEN WAS VACUOUS ANYWAY The table above is real and it was **not sufficient**. The `/heid-contract-review` panel (`01M351WKV666D681SSRNY7D7X6`) — three of four arms, independently — showed **INV-3's falsifier was vacuous**, on this contract's central promise, and the pass above had passed it. **Why the pass missed it.** INV-3 claims *no regular expression is applied to author HTML*. The test name-matched the six DELETED patterns. The mutation the pass applied was re-declaring `_ICON_RE` — **the pattern the contract named** — which the name-match caught. The mutation the invariant actually forbids is a regex under a *new* name (`_TAIL_RE.sub(...)` in the verbatim branch), and that sailed through green. > **The mutation has to come from the INVARIANT'S CLAIM, not from the > FALSIFIER'S EXAMPLE.** A pass that applies the contract's own suggested > mutation is testing the contract against itself, and it will agree. **Then the fix had a hole too, and only a re-run found it.** The repaired test asserts `booth/app.py` performs exactly one regex operation. Re-running the pass *against the fix* showed an aliased `import re as _r` routes around the call check under a name it does not know — still VACUOUS. Closed with an import-shape assertion. **Run the pass on the repair, not only on the draft.** Final state: **10/10 falsifiable**, control green, the two extra rows being the panel's own findings turned into falsifiers. ## What this is evidence for U4 measured the problem (five of seven vacuous). U3 measured a pass working (7/7), then measured **the pass's own blind spot**, then measured the fix's blind spot. All three belong in the case if the vacuity-pass proposal is ever put to the operator as a `/heid*` skill amendment — and the second and third are the parts that stop it being adopted as a ritual that always passes. Related: [[2026-09-22-u3-declared-embed-seam-landed]], [[2026-09-22-the-browser-became-a-test-surface]].