Files
booth/persistent-memory.d/2026-09-22-seven-of-seven-falsifiers.md
T
vh 87e2c5364c feat(u3): a verbatim report declares the seam, the Booth mounts into it
A booth that ships its own index.html was served through ten regular
expressions applied to markup the Booth did not write: six in
wrap_verbatim_html hunting for somewhere to hang a favicon and a chip, four
in booth/inline.py substituting rendered ask markup into the author's own
tags. Both worked. Both were the most fragile thing in the service, on the
path the operator uses most.

The whole class is replaced by a declared seam. A report carries one line —
<script src="/_booth/embed.js" defer></script> — and the chrome mounts
through DOM APIs. What the server does to author HTML is now, in full:

    return html if declares_embed(html) else html + EMBED_SCRIPT_TAG

Two substring tests and a concatenation. Both of the old wrapper's hard
constraints stop existing rather than being satisfied more carefully:
nothing can displace a leading doctype into quirks mode and nothing can push
the charset meta out of its detection window, because nothing in front of
them ever moves. A page that declares the seam is served exactly as written.

Fragments are still rendered by the _ask_inline.html macros and handed over
GET /b/<name>/embed.json; embed.js places them and decides nothing. Openness
comes from open_marks, order from (created, id), questions in declaration
order. A single-question pick normalizes to key None, so the payload carries
questions as a list rather than an object — keying by name would serialize
that as the string "null".

Placement is an anchor fill, not a replacement: el.insertAdjacentHTML(
'beforeend'), so an author's wrapper and its contents survive. The regex it
replaces was eating the opening tag of dfa-concepts' styled .ask blocks and
orphaning their headings, live, unreported.

data-booth-mark is canonical; data-booth-ask stays a kept alias because two
live reports use it. The comment placeholders are dropped — no users.

Declared cost: the verbatim path now needs JavaScript. The never-invisible
guarantee holds through the index badge and /b/<name>/marks, both of which
render server-side.

Deleted: booth/inline.py entire, wrap_verbatim_html and its six patterns,
_BACK_CHIP, asks_chip, inject_asks, FAVICON_LINK, the styles() macro.

Tests 410 -> 434. tests/test_embed_browser.py drives a real Chromium: the
placement algorithm and the form= binding of a scattered multi-question form
cannot be observed any other way, and that binding was measured rather than
assumed (N=3 per condition, with a form-first positive control and a
points-at-nothing negative control).

Contract: docs/contracts/u3_declared_embed_seam.contract.md, with the
in-session seam review and the cold contract panel both recorded. Two of the
panel's findings were code fixes: a vacuous INV-3 falsifier that a renamed
regex walked straight through, and a bare-substring seam detection that read
a report merely quoting the path as declaring it and silently served it with
no chrome.
2026-09-22 10:43:41 -07:00

4.7 KiB

A vacuity pass that tries the contract's own mutation agrees with itself

2026-09-22 · booth

The contract-time vacuity pass — for each invariant, name a change that defeats it and check the named test goes red — was proposed independently by Regin and Kimi on U4's paraphrase round, and U4's own code-review panel then showed five of seven U4 falsifiers were vacuous: a green test cited by an INV rather than a test that would fail if the invariant broke. See 2026-09-22-vacuous-falsifiers.

U3 ran the pass as a real instrument rather than a promise. Script in the session scratchpad; for each invariant it applies the mutation the contract's Falsifiable: line names, runs the single named test, and asserts a non-zero exit, restoring the file in a finally either way.

INV mutation applied verdict
1 declaring page untouched append <!-- booth --> to the declaring branch FALSIFIED
2 appended, never inserted insert the tag before <title> instead FALSIFIED
3 no regex on author HTML re-declare _ICON_RE in app.py FALSIFIED
4 openness is the server's have embed.js derive open from bk-done FALSIFIED
5 embed.js read once read_text() per request in the route FALSIFIED
6 tail in payload order iterate the marks list backwards FALSIFIED
7 unplaced questions appended short-circuit the append branch to if (false) FALSIFIED

7/7, and — the part that makes it a measurement rather than a ritual — an unmutated control run confirming all seven named tests are green when nothing is broken. Without that control, a script whose mutation silently failed to apply (the text not found, the wrong file) reports the same clean-looking table. The script halts with MUTATION-MISS if its target string is absent, for exactly that reason.

Why it is worth the ten minutes

Three of the seven falsifiers are in embed.js, which the Python suite cannot see at all. INV-4, INV-6 and INV-7 are held only by browser tests, and "there is a browser test named after this invariant" is precisely the kind of claim that feels like coverage and can be empty. Two of those three mutations are one-token edits — marks.length - 1 and if (false) — so the cost of checking was minutes and the cost of being wrong was an invariant nobody was holding.

The general shape: an instrument that cannot fail loudly will fail quietly. Same family as the (gasp) tag-detection specimen in the global measurement rule, and as the zsh word-splitting bug that shipped an empty heid bundle — 2026-09-22-four-paths-to-one-fail-open-delete. A clean result and a broken method are indistinguishable from the output alone unless something in the method is designed to go red.

⚠ AND THEN THE COLD PANEL SHOWED ONE OF THE SEVEN WAS VACUOUS ANYWAY

The table above is real and it was not sufficient. The /heid-contract-review panel (01M351WKV666D681SSRNY7D7X6) — three of four arms, independently — showed INV-3's falsifier was vacuous, on this contract's central promise, and the pass above had passed it.

Why the pass missed it. INV-3 claims no regular expression is applied to author HTML. The test name-matched the six DELETED patterns. The mutation the pass applied was re-declaring _ICON_RE — the pattern the contract named — which the name-match caught. The mutation the invariant actually forbids is a regex under a new name (_TAIL_RE.sub(...) in the verbatim branch), and that sailed through green.

The mutation has to come from the INVARIANT'S CLAIM, not from the FALSIFIER'S EXAMPLE. A pass that applies the contract's own suggested mutation is testing the contract against itself, and it will agree.

Then the fix had a hole too, and only a re-run found it. The repaired test asserts booth/app.py performs exactly one regex operation. Re-running the pass against the fix showed an aliased import re as _r routes around the call check under a name it does not know — still VACUOUS. Closed with an import-shape assertion. Run the pass on the repair, not only on the draft.

Final state: 10/10 falsifiable, control green, the two extra rows being the panel's own findings turned into falsifiers.

What this is evidence for

U4 measured the problem (five of seven vacuous). U3 measured a pass working (7/7), then measured the pass's own blind spot, then measured the fix's blind spot. All three belong in the case if the vacuity-pass proposal is ever put to the operator as a /heid* skill amendment — and the second and third are the parts that stop it being adopted as a ritual that always passes.

Related: 2026-09-22-u3-declared-embed-seam-landed, 2026-09-22-the-browser-became-a-test-surface.