A booth that ships its own index.html was served through ten regular
expressions applied to markup the Booth did not write: six in
wrap_verbatim_html hunting for somewhere to hang a favicon and a chip, four
in booth/inline.py substituting rendered ask markup into the author's own
tags. Both worked. Both were the most fragile thing in the service, on the
path the operator uses most.
The whole class is replaced by a declared seam. A report carries one line —
<script src="/_booth/embed.js" defer></script> — and the chrome mounts
through DOM APIs. What the server does to author HTML is now, in full:
return html if declares_embed(html) else html + EMBED_SCRIPT_TAG
Two substring tests and a concatenation. Both of the old wrapper's hard
constraints stop existing rather than being satisfied more carefully:
nothing can displace a leading doctype into quirks mode and nothing can push
the charset meta out of its detection window, because nothing in front of
them ever moves. A page that declares the seam is served exactly as written.
Fragments are still rendered by the _ask_inline.html macros and handed over
GET /b/<name>/embed.json; embed.js places them and decides nothing. Openness
comes from open_marks, order from (created, id), questions in declaration
order. A single-question pick normalizes to key None, so the payload carries
questions as a list rather than an object — keying by name would serialize
that as the string "null".
Placement is an anchor fill, not a replacement: el.insertAdjacentHTML(
'beforeend'), so an author's wrapper and its contents survive. The regex it
replaces was eating the opening tag of dfa-concepts' styled .ask blocks and
orphaning their headings, live, unreported.
data-booth-mark is canonical; data-booth-ask stays a kept alias because two
live reports use it. The comment placeholders are dropped — no users.
Declared cost: the verbatim path now needs JavaScript. The never-invisible
guarantee holds through the index badge and /b/<name>/marks, both of which
render server-side.
Deleted: booth/inline.py entire, wrap_verbatim_html and its six patterns,
_BACK_CHIP, asks_chip, inject_asks, FAVICON_LINK, the styles() macro.
Tests 410 -> 434. tests/test_embed_browser.py drives a real Chromium: the
placement algorithm and the form= binding of a scattered multi-question form
cannot be observed any other way, and that binding was measured rather than
assumed (N=3 per condition, with a form-first positive control and a
points-at-nothing negative control).
Contract: docs/contracts/u3_declared_embed_seam.contract.md, with the
in-session seam review and the cold contract panel both recorded. Two of the
panel's findings were code fixes: a vacuous INV-3 falsifier that a renamed
regex walked straight through, and a bare-substring seam detection that read
a report merely quoting the path as declaring it and silently served it with
no chrome.
4.7 KiB
A vacuity pass that tries the contract's own mutation agrees with itself
2026-09-22 · booth
The contract-time vacuity pass — for each invariant, name a change that
defeats it and check the named test goes red — was proposed independently by
Regin and Kimi on U4's paraphrase round, and U4's own code-review panel then
showed five of seven U4 falsifiers were vacuous: a green test cited by an
INV rather than a test that would fail if the invariant broke. See
2026-09-22-vacuous-falsifiers.
U3 ran the pass as a real instrument rather than a promise. Script in the
session scratchpad; for each invariant it applies the mutation the contract's
Falsifiable: line names, runs the single named test, and asserts a non-zero
exit, restoring the file in a finally either way.
| INV | mutation applied | verdict |
|---|---|---|
| 1 declaring page untouched | append <!-- booth --> to the declaring branch |
FALSIFIED |
| 2 appended, never inserted | insert the tag before <title> instead |
FALSIFIED |
| 3 no regex on author HTML | re-declare _ICON_RE in app.py |
FALSIFIED |
| 4 openness is the server's | have embed.js derive open from bk-done |
FALSIFIED |
| 5 embed.js read once | read_text() per request in the route |
FALSIFIED |
| 6 tail in payload order | iterate the marks list backwards | FALSIFIED |
| 7 unplaced questions appended | short-circuit the append branch to if (false) |
FALSIFIED |
7/7, and — the part that makes it a measurement rather than a ritual — an
unmutated control run confirming all seven named tests are green when
nothing is broken. Without that control, a script whose mutation silently failed
to apply (the text not found, the wrong file) reports the same clean-looking
table. The script halts with MUTATION-MISS if its target string is absent,
for exactly that reason.
Why it is worth the ten minutes
Three of the seven falsifiers are in embed.js, which the Python suite cannot
see at all. INV-4, INV-6 and INV-7 are held only by browser tests, and
"there is a browser test named after this invariant" is precisely the kind of
claim that feels like coverage and can be empty. Two of those three mutations
are one-token edits — marks.length - 1 and if (false) — so the cost of
checking was minutes and the cost of being wrong was an invariant nobody was
holding.
The general shape: an instrument that cannot fail loudly will fail quietly.
Same family as the (gasp) tag-detection specimen in the global measurement
rule, and as the zsh word-splitting bug that shipped an empty heid bundle —
2026-09-22-four-paths-to-one-fail-open-delete. A clean result and a broken
method are indistinguishable from the output alone unless something in the
method is designed to go red.
⚠ AND THEN THE COLD PANEL SHOWED ONE OF THE SEVEN WAS VACUOUS ANYWAY
The table above is real and it was not sufficient. The /heid-contract-review
panel (01M351WKV666D681SSRNY7D7X6) — three of four arms, independently —
showed INV-3's falsifier was vacuous, on this contract's central promise, and
the pass above had passed it.
Why the pass missed it. INV-3 claims no regular expression is applied to
author HTML. The test name-matched the six DELETED patterns. The mutation the
pass applied was re-declaring _ICON_RE — the pattern the contract named —
which the name-match caught. The mutation the invariant actually forbids is a
regex under a new name (_TAIL_RE.sub(...) in the verbatim branch), and that
sailed through green.
The mutation has to come from the INVARIANT'S CLAIM, not from the FALSIFIER'S EXAMPLE. A pass that applies the contract's own suggested mutation is testing the contract against itself, and it will agree.
Then the fix had a hole too, and only a re-run found it. The repaired test
asserts booth/app.py performs exactly one regex operation. Re-running the pass
against the fix showed an aliased import re as _r routes around the call
check under a name it does not know — still VACUOUS. Closed with an import-shape
assertion. Run the pass on the repair, not only on the draft.
Final state: 10/10 falsifiable, control green, the two extra rows being the panel's own findings turned into falsifiers.
What this is evidence for
U4 measured the problem (five of seven vacuous). U3 measured a pass working
(7/7), then measured the pass's own blind spot, then measured the fix's
blind spot. All three belong in the case if the vacuity-pass proposal is ever
put to the operator as a /heid* skill amendment — and the second and third
are the parts that stop it being adopted as a ritual that always passes.
Related: 2026-09-22-u3-declared-embed-seam-landed, 2026-09-22-the-browser-became-a-test-surface.