# The CLASS half of a SUBSTRATE read through a tool: where the line between data and document falls, and what each side owes. # Raised from `templates/model.template.md`. The measured half lives in a finding surface and never here. # Nothing here names a project, a party, a tool, a file or a count. ═══════════════════ LIFETIME (declared, read rather than inferred) ═══════════════════ **THE VALUES ARE DRAWN FROM THE CLOSED SETS THE PARAMETER SURFACE DECLARES AND ARE NOT RESTATED HERE.** A mechanism RESOLVES the members there; this surface class states what each axis SEPARATES, which is the half no parameter surface should carry — one member set with two consumers rather than one set stated twice. **The file default:** retention `current-truth` — a class statement is corrected in place and states what is true now. Mutability `owner-rewritable` — any party may write it, announced before the edit lands, because a model is an OUTCOME surface authored jointly rather than a set of per-party claims. Removal authority `author` — each author cuts its own words on a collision. | section | axis | value | why | | ------------------------------------------ | ---------- | -------- | ------------------------------------------------------------------------------------------------- | | this LIFETIME block and the CONTRACT block | mutability | `frozen` | written from the template and never edited in a live surface — a correction lands in the template | **ONE WRITER PER RECORD HAS NO OPERAND HERE, AND THAT IS DECLARED RATHER THAN ASSUMED.** A coordination surface carries per-party CLAIMS, so a record is the unit and a fence implements the invariant. A model carries ONE PRODUCT, authored jointly, with no per-party unit for the invariant to range over — so the invariant does not hold weakly or partially, it has **no operand**, which is a third state distinct from held and violated. An invariant silently assumed to cover a surface it has no operand on reads as held, and every derivation above it inherits a guarantee that was never available. **RECORD STRUCTURE IS REFUSED HERE RATHER THAN MERELY UNNECESSARY.** Partitioning a class statement into per-party spans makes it read as several parties' opinions where its whole value is that it reads as one statement — and it would not buy what a fence buys anyway, because the collision on this surface is between MEANINGS. **The instrument that reaches it is the announcement plus each author cutting its OWN duplicate**, which is a different mechanism, and naming it here is what stops a later reader proposing the fence. ═══════════════════ CONTRACT (permanent) ═══════════════════ ## What may enter, and what may not **A MODEL SHIPS CLASSES AND NEVER INSTANCES.** Its catalog carries SHAPES — a mechanism with no effect, a green reading over a set that excluded its own subject, a hand-kept index drifting, a search used as a proxy for a graph, a finding with no destination. It never carries which file, which party, or how many, or the next adopter inherits another project's incidents as laws. **THE THREE CONSTRUCTS SEPARATE, AND CONFLATING THEM IS WHAT MAKES A ROW LOOK HOMELESS:** | construct | is | is not | | ------------- | ------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | | an invariant | a property the topology RELIES ON, whose loss invalidates derivations above it | a measurement, since nothing records it firing | | a class | the shape of a defect, transferable to a tree with nothing else in common | a property of one topology, which is what an invariant is | | a measurement | a reading taken at one coordinate, with its evidence, range and consumer | a law, and one copied into a template makes the next adopter inherit another project's incidents | **So an invariant lands in neither surface unaltered and in both once split.** Its CLASS belongs here; its ROW — this topology's own instance, with what watches it, over which members, for which consumer — belongs in the finding surface. **The invariant itself is neither.** ## Stating an invariant **AN INVARIANT A TOPOLOGY RELIES ON WITHOUT STATING IS INDISTINGUISHABLE FROM A PROPERTY A READER HAPPENED TO INFER**, so every guarantee derived from it is only as sound as an assumption nobody wrote down. **THE TEST IS NOT WHETHER THE INVARIANT IS TRUE — IT IS WHETHER ANYTHING WOULD DISAGREE IF IT STOPPED BEING.** A property holding today with no dissenting mechanism is held by circumstance: nothing observes its loss, the first violation is silent, and the guarantee above it keeps reading as sound. **So an invariant is stated with the thing that would object, or it is stated as unheld and the derivations resting on it are marked with it.** **AND IT IS STATED IN A SURFACE THE PARTIES BOUND BY IT RECEIVE.** An invariant delivered to nobody is a capability nothing consumes — and **a mechanism that must honor one is the hardest consumer to remember, because it is the only one that cannot ask.** **THE THREE SLOTS, AND OMITTING ANY ONE LEAVES IT UNSTATED:** the PROPERTY in a form that could be false, since a statement nothing could contradict states nothing; the SET it quantifies over, since a property established at one node and asserted for the whole structure is a verdict beyond its range; and the PARTIES it binds, because an invariant constrains actors rather than describing a shape, and the parties decide where it must be delivered. **WHAT A READER MAY NOT DERIVE FROM A STATED ONE:** that it is ENFORCED. A statement is a claim about the topology; a check is a mechanism over artifacts. **Half-held is the common case and the one a bare statement cannot express** — a property observed on one axis and assumed on another reads as whole, and the axis nobody watches is where the first violation lands. ## The contradicted invariant, which no check can see **WHERE THE TOPOLOGY STATES THE OPPOSITE SOMEWHERE ELSE, EVERY MECHANISM STAYS GREEN WHILE THE INVARIANT IS VIOLATED.** A mechanism implementing the contradictory statement faithfully satisfies every ordering its own path checks, so nothing reports a defect: the contradiction is between two STATEMENTS, and no query ranges over both. **So a statement is not the unit of the check — the SET of statements is**, and adding a statement adds an obligation to re-derive that set whenever the invariant changes, ordered by how often each copy is delivered rather than by which file is easiest to reason about. ## The four elements every model declares **SCHEMA ALONE TRANSFERS THE SHAPE AND NOT THE GUARANTEE** — a stated rule with no gate reads as governance while each party privately concludes the backlog is their own indiscipline. | element | states | | ------------ | -------------------------------------------------------------------- | | SCHEMA | the fields and their types | | LIFETIME | when each field is written, and what deletes it | | FAILURE MODE | what goes wrong when it is not obeyed, and how that failure presents | | GATE | the check that observes it, or `none` as declared debt | ## The form of a statement **A CLAUSE STATES THE SHAPE AND THE PARAMETER SURFACE HOLDS THE MEMBERS.** A vocabulary restated here is a second copy with nothing keeping the two equal, and the copy nobody re-reads is the one a reader takes. Where a set is closed, this surface states what its values SEPARATE and the declaration states what they ARE. **A MANDATED FIELD ACQUIRES A MECHANISM ONLY IN A FORM A MECHANISM CAN JOIN ON.** A value drawn from a closed set or an identifier can acquire a consumer at any time; free prose cannot, ever, without changing form. Both read as governed, so the distinction is invisible from the schema and decisive for everything downstream — **a field is therefore mandated in a resolvable form, or it is declared to be for readers.** **A COUNT IS NEVER WRITTEN.** A model that states how many rules, parties, surfaces or members exist has copied a fact something else derives, and it is wrong from the first change nobody propagated while reading as current. ## Gate - A statement naming a project, a party, a tool, a file or a count fails: those are instance content. - An invariant stated without its property, its set and its parties is unstated and fails as such. - An invariant stated with no objector fails unless it declares itself unheld and marks what rests on it. - Every declared element — SCHEMA, LIFETIME, FAILURE MODE, GATE — is present; `none` is a real GATE value stating declared debt, while an absent one makes an oversight indistinguishable from an assessed decision. ═══════════════════ MODEL ═══════════════════ ## The split is the answer rather than either side of it **A SURFACE READ THROUGH A TOOL IS BOTH DATA AND DOCUMENT IN ONE FILE, AND THE LINE BETWEEN THEM IS DECIDABLE.** It carries a CARRIER — fields whose consumers are mechanisms and whose values are drawn from closed sets or are identifiers — and a PAYLOAD, whose only consumer is a reader and which no parser reaches without a heuristic. So the substrate question resolves as a SPLIT rather than a choice between two whole-file answers: **type the carrier, leave the payload prose.** **AND THE LINE IS PER-FIELD RATHER THAN PER-SURFACE OR PER-FORMAT.** A structured file may hold a field whose value is prose, and a prose file may hold a field a parser resolves — so a verdict taken at the file reads as coverage over slots it never examined. **The discriminator is whether a MECHANISM JOINS on the value**, never where the value lives or what the file's extension says. **A KEY AND ITS VALUE MAY FALL ON OPPOSITE SIDES, AND THAT IS THE CORRECT FORM RATHER THAN A DEFECT.** Where presence under a key is the machine-readable claim and the value is the reason a reader needs, the mechanism consumes the key and never parses the sentence. **AND A SECOND FAILURE MODE SITS BESIDE THE NAMED ONE, WHICH IS WHERE A SPLIT SURFACE ACTUALLY BREAKS.** The named one is a mechanism that must INTERPRET the payload to compute the carrier — the case the split exists to forbid. The other is a carrier and a payload that ANSWER THE SAME QUESTION DIFFERENTLY, and it is invisible to every mechanism precisely because nothing needs to interpret anything: the consumer resolves the carrier and is correct, while the reader takes the payload, because prose is what a reader consumes. **The checkable field is the one that was right, so no check can reach the false one.** **IT IS A CLASS RATHER THAN AN INVARIANT, BECAUSE NOTHING WOULD OBJECT IF IT STOPPED HOLDING.** Deciding which token in a payload makes a claim about the question its carrier already answers needs a phrase list or an inference, and a gate whose population is defined by a phrase list is refused — so the property is stated as UNHELD, and every derivation resting on a split surface's halves agreeing rests on an assumption. **The available repair is authoring rather than enforcement: a payload restating what a carrier declares is removed rather than reconciled**, since a field answering a question another field already answers is the duplication the split exists to end. ## The obligations a typed fact carries, in order **TYPING A FACT DISCHARGES THE FIRST OBLIGATION AND CREATES THE ONES AFTER IT.** Each is a distinct failure with a distinct repair, and a surface satisfying one while omitting another reads as governed from the side that was satisfied. | obligation | discharged by | failure when omitted | | ---------------- | ------------------------------------------------------------ | --------------------------------------------------------------------------- | | TYPE the carrier | a declaration with a closed vocabulary and a refusing reader | a fact nothing can resolve, carried in a form no mechanism reaches | | GATE the join | a consumer checkable against the record's declared field set | a declaration read wrongly, reporting confidently, invisible from both ends | | DELIVER the fact | a channel that arrives at the moment a party acts | a correct derived fact computable throughout and reaching nobody | **TYPING RELOCATES A DEFECT RATHER THAN REMOVING IT, AND THAT IS THE ARGUMENT FOR IT.** In prose a fact and its consumer are one object, so a misreading IS the defect and lives where no mechanism can reach. Typed, they are two objects, and every misreading becomes a MIS-JOIN — which is not a smaller class, but one that lives in code, and code is the substrate a gate can range over. **AND THE THIRD OBLIGATION IS THE ONE NEITHER SIDE OF THE ORIGINAL QUESTION CARRIED.** A declaration nothing reads is inert; a join reading the wrong fields is worse than inert; and a correct derived fact nobody is handed is a third failure, distinct from both, whose repair is neither a type nor a check but a channel. ## The invariants this topology relies on ### A declared lifetime is READ, never inferred from a path **PROPERTY** — every decision a mechanism takes about what it may do to a surface resolves from that surface's DECLARED lifetime, and never from the shape of its path or the spelling of its name. **SET** — every mechanism that scans, rewrites, skips, removes or anchors a finding on any governed surface. **PARTIES** — every author of such a mechanism, at the moment the operand is chosen. **OBJECTOR** — a check comparing each mechanism's resolved operand against the declaration, which fails a mechanism deciding from a path. **RETENTION, MUTABILITY AND REMOVAL AUTHORITY ARE INDEPENDENT AXES AND NONE IS DERIVABLE FROM THE OTHERS.** A predicate answering a question about one axis from the values of the others is performing a derivation the vocabulary declares unavailable — and where the proxies happen to agree it is correct by luck, so its population of wrong answers is exactly the set where they diverge. **A one-word summary of a lifetime collapses to the weakest axis and drops the rest silently**, which is how a never-remove ruling loses its operand. **Path shape may DISCOVER which surfaces are of a kind; it may never DECIDE what their contents are.** ### A finding's locus is consumed as its repair target **PROPERTY** — the locus a finding reports is a location a party can act on. **SET** — every finding emitted against any governed surface. **PARTIES** — every mechanism that emits a finding, and every party that acts on one. **OBJECTOR** — a walk resolving each emitted locus against the surface's declared lifetime, which fails a line-locus on a surface that only grows. **THE DECLARED LIFETIME DECIDES WHETHER THE PROPERTY HOLDS, AND EACH LIFETIME BREAKS IT DIFFERENTLY.** On an APPEND-ONLY surface a line decays as the surface grows, so the locus is exact when written and wrong when read — repaired by anchoring to the enclosing addressable span. On a GENERATED surface the locus is exact and UNREPAIRABLE, which is worse than a refusal because an edit there lands and the next regeneration discards it. On an IMMUTABLE surface the repair belongs to nobody, and a finding that cannot be drained trains every reader to discount the color, with the cost landing on the findings beside it. **AND ONE FORM IS INVISIBLE TO ANY PREDICATE READING THE SURFACE: A PERMANENT SPAN INSIDE A MUTABLE ONE.** Where a surface ACCUMULATES it accepts a write, so the repair is reachable by appending — and the span the locus names is permanent by that same lifetime, so the finding still stands whatever anybody appends. The repair being reachable and the finding being clearable are different properties, and only the SPAN's mutability separates them: the surface's own answer is the wrong operand, and a check asking it reports a repairable target over an unclearable finding. The objector reads the anchored span rather than the file — the same anchor the first form repairs to — and fails a finding whose locus resolves to an item key on a surface whose declared retention accumulates. ### One aggregate, overwritten, or no aggregate at all **PROPERTY** — after any run, the single aggregate is the truth, and no second document describing the same subject exists under a name derived from how a run was invoked. **SET** — every run of every shared measurement. **PARTIES** — every party that invokes one. **OBJECTOR** — a check failing a write of a scope-keyed, caller-keyed or invocation-keyed report beside the aggregate. **A RUN THAT CANNOT HONESTLY REPLACE THE AGGREGATE STREAMS RATHER THAN WRITING ANYWHERE.** Not over it, because a label describes a document and does not preserve the one it replaced, so the state guarantee is not weakened but unavailable. Not beside it, because a keyed name produces a set of documents each true of a moment and none of them the state, which nobody prunes and no reader can reconstruct. **Streaming costs the caller nothing it does not already have**, since the verdict is in front of the party that asked for it. ### A narrowed measurement divides into classes rather than behaving uniformly **PROPERTY** — every scoped mechanism declares which of the three it is, and a narrowed run acts on that declaration rather than running every mechanism against a reduced scope. **SET** — every mechanism a scoped run may invoke. **PARTIES** — the author of each mechanism, and every party invoking one narrowly. **OBJECTOR** — a check failing a mechanism that declares no class while drawing subjects and evidence from different sources. **THE CLASSES SEPARATE ON WHERE SUBJECTS AND EVIDENCE COME FROM, WHICH IS A PROPERTY OF THE MECHANISM'S OWN INPUTS.** A mechanism whose SUBJECTS arrive through a declared read and whose EVIDENCE arrives through the scanned set is NOT NARROWABLE: narrowing preserves every subject and destroys the evidence that would clear each one, so its narrowed verdict is FALSE while reading as a measurement. A mechanism declaring BOTH halves is SCOPE-INVARIANT: its findings are true and out of jurisdiction. A mechanism that MUTATES from a root-derived set is skipped on a third ground — skipping protects artifacts the scope never bounded, and honest findings do not make a removal in-scope. **AND THE FEATURE THAT MAKES A MECHANISM SCOPE-PROOF IS THE FEATURE THAT MAKES THE FIRST CLASS POSSIBLE.** Restoring a mechanism's declared operands under any scope is correct and is why such a mechanism runs at all; applied to its SUBJECTS alone it guarantees a full population judged against an emptied evidence set. ### A guard about who can still act resolves an OBSERVATION, never a declaration of membership **PROPERTY** — a mechanism deciding whether a party can still respond resolves that from an observation of that party's own recent activity, and resolves a declaration only where its question is about MEMBERSHIP. **SET** — every guard whose trigger or threshold is drawn from a roster of declared parties. **PARTIES** — the author of each such guard, at the moment the operand is chosen. **OBJECTOR** — a check failing a mutation guard whose operand resolves to a membership reader, and a roster derived from parties that are either held or recently observed. **MEMBERSHIP AND LIVENESS ARE DIFFERENT QUESTIONS AND A ROSTER ANSWERS ONLY THE FIRST.** A party is recorded and rowed whether or not it is running, so a guard reading that record sets its bound from a fact that cannot answer it — and the guard then FIRES CORRECTLY AND FIRES ONE PARTY TOO LATE, which is why testing whether it ever fires cannot detect it. **The operand is the subject of the test, never the comparison.** **AND THE TWO SIGNALS ARE UNIONED RATHER THAN RANKED**, because a party that is held stops producing activity precisely while it is held: recency alone shrinks the set underneath the parties being counted, so the bound moves against a denominator falling for the wrong reason. ### A derived subject set is safe only where its empty case means NO CONSTRAINT **PROPERTY** — a set derived rather than declared is substituted only into a consumer that reads an empty set as no constraint, and never into one that reads it as every constraint satisfied. **SET** — every consumer of a derived party set. **PARTIES** — the author of the derivation, and the author of every consumer it is substituted into. **OBJECTOR** — a refusal at any edge computed as a filter over that set, which fails an empty subject set rather than holding over it. **ONE OPERAND MAY FEED TWO CONSUMERS WITH OPPOSITE READINGS OF EMPTINESS, AND THAT IS INVISIBLE FROM THE OPERAND.** A guard stands down when its set is empty, which is safe. A set of edges computed as filters all HOLD when the filtered result is empty, which is a universal pass over a population that was never examined. **So a single repair at the derivation moves a deadlock out of one consumer and puts a silent unanimous agreement into the other** — and the direction is a property of each consumer's own code rather than a judgement about which cost is worse. **WHICH MAKES THE JOIN A DIAGNOSIS AND NOT A REPAIR.** Recognizing that two consumers share an operand is correct and says nothing about whether they may share its derivation; the empty case is the question that decides, and it is answered by reading each consumer rather than by reasoning about the operand. ### A verdict carries a STANDING beside its value, and a measurement's own writes are not contention **PROPERTY** — a verdict whose read set moved beneath it loses its standing to be quoted and keeps its value, and the moves a measurement made ITSELF are reported apart from the moves anybody else made. **SET** — every shared measurement over a surface other parties may write. **PARTIES** — every party that takes one, and every party that quotes one. **OBJECTOR** — the measurement naming its moved read set and separating its own written paths from it, which fails to withdraw a standing no concurrent write damaged. **WITHDRAWING THE VALUE IS THE WRONG REPAIR AND WITHDRAWING NOTHING IS THE OTHER ONE.** Declaring a moved verdict a failure asserts a defect nothing observed; leaving it unmarked hands a reader a description of an interleaving in the shape of a description of a state. What a concurrent write actually damages is the claim to describe ONE MOMENT, so that is the property withdrawn, and the value stands untouched. **AND A MEASUREMENT THAT REPAIRS WHILE IT READS MOVES ITS OWN OPERANDS, WHICH THE SAME COMPARISON CANNOT TELL FROM A PEER'S WRITE.** Counting them together inverts the mechanism: the more a measurement repairs, the less its verdict may be believed, so the parties doing the most work publish the least usable result. The two sets are named APART rather than one being subtracted, because a surface a measurement repaired AND a peer also wrote is indistinguishable from one only the measurement repaired — after the write the stamp is the measurement's either way, and stating that residue is what keeps the separation honest. **THE EXCLUSIVE BARRIER IS DECLINED HERE RATHER THAN OVERLOOKED.** A barrier exists for exclusive WRITES; holding one across a READ serializes every measurement against every write, makes measuring a contention point, and blocks live parties to settle a question about the past. The standing is a distinction the result already carries, which is the same move as replaying a commuting write instead of queueing every one of them. ## The elements, as this topology instantiates them | element | states | | ------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | SCHEMA | a governed surface declares, per field, whether its value is CARRIER — closed vocabulary or identifier — or PAYLOAD; and every mechanism declares the surfaces it reads and the narrowing class it belongs to | | LIFETIME | a carrier field is written when its fact changes and removed when its subject leaves; a payload field is written by its author and retired by that author; a declared lifetime is authored once per surface and read on every mechanism's every decision | | FAILURE MODE | a fact nothing resolves reads as governed; a join over the wrong fields reports confidently and is invisible from both ends; a derived fact nobody is handed reaches nobody while being computable throughout; a locus a party cannot act on trains readers to discount every finding beside it; a keyed second report accumulates documents no reader can reconstruct | | GATE | `none` for the carrier/payload declaration and for the delivery obligation, as declared debt — the first because whether a value is genuinely resolvable is a property of every future consumer rather than of the field, and the second because whether a party RECEIVED a fact is an act no artifact records; the narrowing class, the lifetime operand and the locus anchor each carry an objector named above | ## What this model does not settle **WHETHER A GIVEN VALUE IS RESOLVABLE IS A JUDGEMENT AT THE MOMENT OF AUTHORING**, and no mechanism decides it: a closed vocabulary and an identifier are recognisable, and the boundary case — a value that could be made resolvable by changing its form — is exactly where an author is choosing rather than reporting. **The model states which side each form falls on and refuses to state which side a particular value belongs to.** **AND THE DELIVERY OBLIGATION HAS NO ARTIFACT.** Whether a party received a fact is an act inside a turn, so the gate value is `none` and the property is stated as unheld: every derivation resting on a party having been told is resting on an assumption, and the repair available is to make the channel ARRIVE rather than to check that it did.