{
  "content": {
    "icon": "bi-signpost-split",
    "id": "the-test-surfaces",
    "intro": "The test surfaces are what a system can be wrong about. Each is a dimension seen through a lens, listed with the invariant that must hold, the techniques that observe it, the predicate and what grounds it, the evidence it requires and the verdicts it can return. The architecture page reads the same grid in [what can drift, seen through how it drifts](/software-architecture/coverage#what-can-drift-seen-through-how-it-drifts).",
    "subsections": [
      {
        "blocks": [
          {
            "items": [
              "Dimension: [meaning](/records/reasoning/dimension-meaning)",
              "Lens: [semantic](/records/reasoning/lens-meaning)",
              "Invariant: [correct-outputs](/records/reasoning/invariant-correct-outputs)",
              "Predicate: [equivalence](/records/vocabulary/predicate-type-equivalence)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "An output is correct when it signifies what the input asked for, so the surface compares the meaning of the result with the meaning expected.",
                "term": "Fit"
              },
              {
                "description": "wrong value, incorrect algorithm, wrong computation",
                "term": "Failure modes"
              },
              {
                "description": "[unit-testing](/records/reasoning/technique-unit-testing), [property-based-testing](/records/reasoning/technique-property-based-testing), [differential-testing](/records/reasoning/technique-differential-testing), [assertion-checking](/records/reasoning/technique-assertion-checking)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[test-result](/records/vocabulary/evidence-source-test-result) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "output(input) = expected(input)",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-semantic-correctness",
        "title": "semantic-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [function](/records/reasoning/dimension-function)",
              "Lens: [behavioral](/records/reasoning/lens-behavior)",
              "Invariant: [correct-state-evolution](/records/reasoning/invariant-correct-state-evolution)",
              "Predicate: [invariant](/records/vocabulary/predicate-type-invariant)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "A workflow fulfils its role through the actions it takes, so the surface reads the role from the transitions the system actually performs.",
                "term": "Fit"
              },
              {
                "description": "invalid workflow, missing transition, incorrect business rule",
                "term": "Failure modes"
              },
              {
                "description": "[integration-testing](/records/reasoning/technique-integration-testing), [model-checking](/records/reasoning/technique-model-checking)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[test-result](/records/vocabulary/evidence-source-test-result) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "transition in allowedTransitions",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-functional-correctness",
        "title": "functional-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [state](/records/reasoning/dimension-state)",
              "Lens: [sequential](/records/reasoning/lens-sequential)",
              "Invariant: [valid-state-transitions](/records/reasoning/invariant-valid-state-transitions)",
              "Predicate: [temporal-order](/records/vocabulary/predicate-type-temporal-order)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "A state is valid only relative to the one before it, so the surface checks conditions in the order they occur.",
                "term": "Fit"
              },
              {
                "description": "invalid state, broken state transitions, violated lifecycle rules",
                "term": "Failure modes"
              },
              {
                "description": "[assertion-checking](/records/reasoning/technique-assertion-checking), [property-based-testing](/records/reasoning/technique-property-based-testing)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[test-result](/records/vocabulary/evidence-source-test-result) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "state[t+1] in next(state[t])",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-state-correctness",
        "title": "state-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [structure](/records/reasoning/dimension-structure)",
              "Lens: [structural](/records/reasoning/lens-structure)",
              "Invariant: [valid-interfaces-and-contracts](/records/reasoning/invariant-valid-interfaces-and-contracts)",
              "Predicate: [schema](/records/vocabulary/predicate-type-schema)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "A contract is an arrangement of fields and types, so the surface compares the shape of a payload with the shape the contract declares.",
                "term": "Fit"
              },
              {
                "description": "invalid input/output shape, schema mismatch, contract violation",
                "term": "Failure modes"
              },
              {
                "description": "[runtime-validation](/records/reasoning/technique-runtime-validation), [contract-testing](/records/reasoning/technique-contract-testing)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[test-result](/records/vocabulary/evidence-source-test-result) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "payload models declaredSchema",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-interface-correctness",
        "title": "interface-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [relation](/records/reasoning/dimension-relation)",
              "Lens: [relational](/records/reasoning/lens-relation)",
              "Invariant: [correct-interactions](/records/reasoning/invariant-correct-interactions)",
              "Predicate: [equivalence](/records/vocabulary/predicate-type-equivalence)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "An interaction is the connection between two components, so the surface checks each request against the response its counterpart owes.",
                "term": "Fit"
              },
              {
                "description": "wrong API response, incorrect UI behavior, invalid component communication",
                "term": "Failure modes"
              },
              {
                "description": "[end-to-end-testing](/records/reasoning/technique-end-to-end-testing), [contract-testing](/records/reasoning/technique-contract-testing), [integration-testing](/records/reasoning/technique-integration-testing)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[test-result](/records/vocabulary/evidence-source-test-result) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "response = contract(request)",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-interaction-correctness",
        "title": "interaction-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [time](/records/reasoning/dimension-time)",
              "Lens: [temporal](/records/reasoning/lens-time)",
              "Invariant: [acceptable-execution-time](/records/reasoning/invariant-acceptable-execution-time)",
              "Predicate: [bound](/records/vocabulary/predicate-type-bound)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "Execution time is a duration measured across a run, so the surface compares elapsed time with the deadline.",
                "term": "Fit"
              },
              {
                "description": "timeout, deadline miss, stale data, starvation",
                "term": "Failure modes"
              },
              {
                "description": "[load-testing](/records/reasoning/technique-load-testing), [monitoring](/records/reasoning/technique-monitoring), [tracing](/records/reasoning/technique-tracing)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[measurement](/records/vocabulary/evidence-source-measurement) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "elapsed <= deadline",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-temporal-correctness",
        "title": "temporal-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [behavior](/records/reasoning/dimension-behavior)",
              "Lens: [temporal](/records/reasoning/lens-time)",
              "Invariant: [safe-concurrent-behavior](/records/reasoning/invariant-safe-concurrent-behavior)",
              "Predicate: [invariant](/records/vocabulary/predicate-type-invariant)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "Concurrent code misbehaves only in particular interleavings, so the surface examines what the system does across the orderings time allows.",
                "term": "Fit"
              },
              {
                "description": "race conditions, deadlocks, livelocks, ordering failures",
                "term": "Failure modes"
              },
              {
                "description": "[stress-testing](/records/reasoning/technique-stress-testing), [deterministic-replay](/records/reasoning/technique-deterministic-replay)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[runtime-observation](/records/vocabulary/evidence-source-runtime-observation) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "for-all interleavings: linearizable(history)",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-concurrency-correctness",
        "title": "concurrency-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [composition](/records/reasoning/dimension-composition)",
              "Lens: [evolutionary](/records/reasoning/lens-change)",
              "Invariant: [controlled-memory-usage](/records/reasoning/invariant-controlled-memory-usage)",
              "Predicate: [bound](/records/vocabulary/predicate-type-bound)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "A leak shows as the live set growing in content over a long run, so the surface tracks what memory holds as the run develops.",
                "term": "Fit"
              },
              {
                "description": "memory leaks, excessive allocation, fragmentation, retention bugs",
                "term": "Failure modes"
              },
              {
                "description": "[heap-analysis](/records/reasoning/technique-heap-analysis), [profiling](/records/reasoning/technique-profiling)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[measurement](/records/vocabulary/evidence-source-measurement) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "liveSet bounded as t grows and retained delta approaches 0",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-memory-correctness",
        "title": "memory-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [composition](/records/reasoning/dimension-composition)",
              "Lens: [behavioral](/records/reasoning/lens-behavior)",
              "Invariant: [acceptable-resource-consumption](/records/reasoning/invariant-acceptable-resource-consumption)",
              "Predicate: [absence](/records/vocabulary/predicate-type-absence)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "A handle leak is a resource the system acquires and never gives back, so the surface pairs each acquisition with its release.",
                "term": "Fit"
              },
              {
                "description": "file/socket/connection/handle leaks",
                "term": "Failure modes"
              },
              {
                "description": "[monitoring](/records/reasoning/technique-monitoring), [assertion-checking](/records/reasoning/technique-assertion-checking)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[runtime-observation](/records/vocabulary/evidence-source-runtime-observation) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "acquired = released (no leaked handles)",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-resource-correctness",
        "title": "resource-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [scale](/records/reasoning/dimension-scale)",
              "Lens: [statistical](/records/reasoning/lens-statistical)",
              "Invariant: [acceptable-execution-time](/records/reasoning/invariant-acceptable-execution-time)",
              "Predicate: [bound](/records/vocabulary/predicate-type-bound)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "Performance depends on load, and one request says little about it, so the surface reads latency and throughput as distributions over many requests.",
                "term": "Fit"
              },
              {
                "description": "slow algorithms, excessive CPU, high latency, throughput degradation",
                "term": "Failure modes"
              },
              {
                "description": "[profiling](/records/reasoning/technique-profiling), [load-testing](/records/reasoning/technique-load-testing)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[measurement](/records/vocabulary/evidence-source-measurement) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "latency_p99 <= budget and throughput >= floor",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-performance-correctness",
        "title": "performance-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [probability](/records/reasoning/dimension-probability)",
              "Lens: [anomaly](/records/reasoning/lens-anomaly)",
              "Invariant: [reliability-under-faults](/records/reasoning/invariant-reliability-under-faults)",
              "Predicate: [absence](/records/vocabulary/predicate-type-absence)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "A crash is a rare departure from normal running, so the surface looks for the inputs and faults that make it likely.",
                "term": "Fit"
              },
              {
                "description": "crashes, unhandled exceptions, process termination",
                "term": "Failure modes"
              },
              {
                "description": "[chaos-testing](/records/reasoning/technique-chaos-testing), [fault-injection](/records/reasoning/technique-fault-injection), [monitoring](/records/reasoning/technique-monitoring)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[runtime-observation](/records/vocabulary/evidence-source-runtime-observation) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "no input leads to an unhandled fault",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-reliability-correctness",
        "title": "reliability-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [probability](/records/reasoning/dimension-probability)",
              "Lens: [temporal](/records/reasoning/lens-time)",
              "Invariant: [availability-under-stress](/records/reasoning/invariant-availability-under-stress)",
              "Predicate: [bound](/records/vocabulary/predicate-type-bound)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "Availability is the share of time the service answers, so the surface measures uptime over a period under a declared fault set.",
                "term": "Fit"
              },
              {
                "description": "service outage, cascading failure, degraded service",
                "term": "Failure modes"
              },
              {
                "description": "[chaos-testing](/records/reasoning/technique-chaos-testing), [fault-injection](/records/reasoning/technique-fault-injection)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[runtime-observation](/records/vocabulary/evidence-source-runtime-observation) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "uptime >= SLO under the declared fault set",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-availability-correctness",
        "title": "availability-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [relation](/records/reasoning/dimension-relation)",
              "Lens: [statistical](/records/reasoning/lens-statistical)",
              "Invariant: [consistency-across-components](/records/reasoning/invariant-consistency-across-components)",
              "Predicate: [invariant](/records/vocabulary/predicate-type-invariant)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "Replicas agree or drift as a population, so the surface compares the state of every copy with the others.",
                "term": "Fit"
              },
              {
                "description": "stale cache, divergent replicas, invalid synchronization",
                "term": "Failure modes"
              },
              {
                "description": "[differential-testing](/records/reasoning/technique-differential-testing), [assertion-checking](/records/reasoning/technique-assertion-checking)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[test-result](/records/vocabulary/evidence-source-test-result) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "for-all replicas: converge(state)",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-consistency-correctness",
        "title": "consistency-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [identity](/records/reasoning/dimension-identity)",
              "Lens: [structural](/records/reasoning/lens-structure)",
              "Invariant: [correct-outputs](/records/reasoning/invariant-correct-outputs)",
              "Predicate: [invariant](/records/vocabulary/predicate-type-invariant)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "Persisted data is correct when each record is still the same record in the same shape, so the surface checks identity and layout across writes and migrations.",
                "term": "Fit"
              },
              {
                "description": "corrupted persistence, invalid migrations, duplicate records",
                "term": "Failure modes"
              },
              {
                "description": "[assertion-checking](/records/reasoning/technique-assertion-checking), [integration-testing](/records/reasoning/technique-integration-testing)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[test-result](/records/vocabulary/evidence-source-test-result) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "persisted = written and migrate then inverse = identity",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-data-correctness",
        "title": "data-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [scale](/records/reasoning/dimension-scale)",
              "Lens: [anomaly](/records/reasoning/lens-anomaly)",
              "Invariant: [numerical-validity](/records/reasoning/invariant-numerical-validity)",
              "Predicate: [invariant](/records/vocabulary/predicate-type-invariant)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "Numbers fail at the edges of their range, so the surface looks for the magnitudes where a result overflows, loses precision or turns into NaN.",
                "term": "Fit"
              },
              {
                "description": "overflow, precision loss, NaN propagation",
                "term": "Failure modes"
              },
              {
                "description": "[property-based-testing](/records/reasoning/technique-property-based-testing), [static-analysis](/records/reasoning/technique-static-analysis)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[analysis-report](/records/vocabulary/evidence-source-analysis-report) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "result is finite and not overflow and not NaN",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-numerical-correctness",
        "title": "numerical-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [cause](/records/reasoning/dimension-cause)",
              "Lens: [causal](/records/reasoning/lens-cause)",
              "Invariant: [security-boundaries](/records/reasoning/invariant-security-boundaries)",
              "Predicate: [absence](/records/vocabulary/predicate-type-absence)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "An exploit is a chain from an input to an effect the boundary should prevent, so the surface traces what each input can cause.",
                "term": "Fit"
              },
              {
                "description": "injection, privilege escalation, unsafe deserialization",
                "term": "Failure modes"
              },
              {
                "description": "[static-analysis](/records/reasoning/technique-static-analysis), [fuzz-testing](/records/reasoning/technique-fuzz-testing)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[analysis-report](/records/vocabulary/evidence-source-analysis-report) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "no input yields privilege escalation or injection",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-security-correctness",
        "title": "security-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [novelty](/records/reasoning/dimension-novelty)",
              "Lens: [anomaly](/records/reasoning/lens-anomaly)",
              "Invariant: [deterministic-behavior-where-required](/records/reasoning/invariant-deterministic-behavior-where-required)",
              "Predicate: [equivalence](/records/vocabulary/predicate-type-equivalence)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "Nondeterminism appears as an output that differs from the one expected for the same input, so the surface repeats runs and looks for the deviation.",
                "term": "Fit"
              },
              {
                "description": "the same input producing different outputs",
                "term": "Failure modes"
              },
              {
                "description": "[property-based-testing](/records/reasoning/technique-property-based-testing), [deterministic-replay](/records/reasoning/technique-deterministic-replay)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[test-result](/records/vocabulary/evidence-source-test-result) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "f(x) = f(x) across runs",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-determinism-correctness",
        "title": "determinism-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [relation](/records/reasoning/dimension-relation)",
              "Lens: [sequential](/records/reasoning/lens-sequential)",
              "Invariant: [protocol-compliance](/records/reasoning/invariant-protocol-compliance)",
              "Predicate: [temporal-order](/records/vocabulary/predicate-type-temporal-order)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "A protocol is a relation between parties that holds only in a given order of messages, so the surface checks the sequence against the protocol's grammar.",
                "term": "Fit"
              },
              {
                "description": "invalid message ordering, malformed communication sequence",
                "term": "Failure modes"
              },
              {
                "description": "[contract-testing](/records/reasoning/technique-contract-testing), [model-checking](/records/reasoning/technique-model-checking)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[test-result](/records/vocabulary/evidence-source-test-result) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "messageSeq in protocolGrammar",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-protocol-correctness",
        "title": "protocol-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [state](/records/reasoning/dimension-state)",
              "Lens: [structural](/records/reasoning/lens-structure)",
              "Invariant: [configuration-validity](/records/reasoning/invariant-configuration-validity)",
              "Predicate: [schema](/records/vocabulary/predicate-type-schema)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "Configuration is the condition a deployment starts in, and it is valid when its keys and values take the declared shape, so the surface checks it against its schema.",
                "term": "Fit"
              },
              {
                "description": "invalid environment variables, feature flag errors, deployment mismatch",
                "term": "Failure modes"
              },
              {
                "description": "[runtime-validation](/records/reasoning/technique-runtime-validation), [static-analysis](/records/reasoning/technique-static-analysis)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[analysis-report](/records/vocabulary/evidence-source-analysis-report) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "config models configSchema",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-configuration-correctness",
        "title": "configuration-correctness"
      },
      {
        "blocks": [
          {
            "items": [
              "Dimension: [meaning](/records/reasoning/dimension-meaning)",
              "Lens: [frequency](/records/reasoning/lens-frequency)",
              "Invariant: [accurate-observability](/records/reasoning/invariant-accurate-observability)",
              "Predicate: [invariant](/records/vocabulary/predicate-type-invariant)"
            ],
            "kind": "list"
          },
          {
            "entries": [
              {
                "description": "A signal is accurate when every event it stands for is emitted each time the event occurs, so the surface compares how often events happen with how often they are reported.",
                "term": "Fit"
              },
              {
                "description": "missing logs, incorrect metrics, broken traces",
                "term": "Failure modes"
              },
              {
                "description": "[monitoring](/records/reasoning/technique-monitoring), [tracing](/records/reasoning/technique-tracing)",
                "term": "Techniques"
              },
              {
                "description": "[ver-ground-truth](/records/reasoning/node-ver-ground-truth)",
                "term": "Predicate grounds"
              },
              {
                "description": "[runtime-observation](/records/vocabulary/evidence-source-runtime-observation) · required",
                "term": "Evidence"
              },
              {
                "description": "[ver-evidence](/records/reasoning/node-ver-evidence)",
                "term": "Evidence grounds"
              },
              {
                "description": "[pass](/records/vocabulary/verdict-pass), [fail](/records/vocabulary/verdict-fail), [unknown](/records/vocabulary/verdict-unknown)",
                "term": "Verdicts"
              }
            ],
            "kind": "glossary"
          },
          {
            "code": "for-all event: emitted and measurable",
            "kind": "code",
            "language": "text",
            "title": "Predicate"
          },
          {
            "kind": "text",
            "text": "How it is checked"
          },
          {
            "entries": [
              {
                "description": "the techniques each surface lists, whose results the surface's predicate and evidence decide, the covered-surfaces check, which validates every surface a module declares covered",
                "term": "Checked by"
              },
              {
                "description": "Every module that declares the surface covered, and the code under that module",
                "term": "Population"
              },
              {
                "description": "A verdict stands until the module's code, its declaration or the surface changes",
                "term": "Freshness"
              },
              {
                "description": "The covered-surfaces check fails a module that declares an unknown surface; a surface whose evidence is empty stays unknown, never pass",
                "term": "Refusal"
              },
              {
                "description": "The runtime techniques among the surface's list, which locate failures without certifying their absence",
                "term": "Observation"
              },
              {
                "description": "Watched to fire and to accept: a suite plants a surface with no techniques, an empty verdict domain, a blank predicate and a colliding cell, and the bundled surfaces validate clean",
                "term": "Evidence"
              },
              {
                "description": "The evidence the surface's techniques produce, which the verdict is decided from, so an empty evidence set leaves it unknown",
                "term": "Authoritative side"
              },
              {
                "description": "Not answered",
                "term": "Depends on"
              },
              {
                "description": "Not answered",
                "term": "Shape it refuses"
              }
            ],
            "kind": "glossary"
          }
        ],
        "id": "reasoning-test-surface-observability-correctness",
        "title": "observability-correctness"
      }
    ],
    "title": "The test surfaces"
  },
  "graph": {
    "narrative": true,
    "requires": [],
    "teaches": [],
    "traces": []
  },
  "href": "https://banes-lab.com/ontology/reasoning#the-test-surfaces",
  "number": "209",
  "page": "ontology",
  "ref": "chapter:/ontology/reasoning#the-test-surfaces",
  "relations": [
    {
      "links": [
        {
          "href": "https://banes-lab.com/software-architecture/coverage#what-can-drift-seen-through-how-it-drifts",
          "json": "https://banes-lab.com/json/software-architecture/coverage/what-can-drift-seen-through-how-it-drifts",
          "label": "What can drift, seen through how it drifts",
          "markdown": "https://banes-lab.com/software-architecture/coverage/what-can-drift-seen-through-how-it-drifts.md",
          "ref": "chapter:/software-architecture/coverage#what-can-drift-seen-through-how-it-drifts"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-dimension-meaning",
          "json": "https://banes-lab.com/json/records/reasoning/dimension-meaning",
          "label": "Meaning",
          "markdown": "https://banes-lab.com/records/reasoning/dimension-meaning.md",
          "ref": "reasoning:dimension-meaning"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-lens-meaning",
          "json": "https://banes-lab.com/json/records/reasoning/lens-meaning",
          "label": "Meaning",
          "markdown": "https://banes-lab.com/records/reasoning/lens-meaning.md",
          "ref": "reasoning:lens-meaning"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-correct-outputs",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-correct-outputs",
          "label": "Correct Outputs",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-correct-outputs.md",
          "ref": "reasoning:invariant-correct-outputs"
        },
        {
          "href": "https://banes-lab.com/ontology/schema#vocabulary-predicate-type-equivalence",
          "json": "https://banes-lab.com/json/records/vocabulary/predicate-type-equivalence",
          "label": "equivalence",
          "markdown": "https://banes-lab.com/records/vocabulary/predicate-type-equivalence.md",
          "ref": "vocabulary:predicate-type-equivalence"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-unit-testing",
          "json": "https://banes-lab.com/json/records/reasoning/technique-unit-testing",
          "label": "Unit Testing",
          "markdown": "https://banes-lab.com/records/reasoning/technique-unit-testing.md",
          "ref": "reasoning:technique-unit-testing"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-property-based-testing",
          "json": "https://banes-lab.com/json/records/reasoning/technique-property-based-testing",
          "label": "Property Based Testing",
          "markdown": "https://banes-lab.com/records/reasoning/technique-property-based-testing.md",
          "ref": "reasoning:technique-property-based-testing"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-differential-testing",
          "json": "https://banes-lab.com/json/records/reasoning/technique-differential-testing",
          "label": "Differential Testing",
          "markdown": "https://banes-lab.com/records/reasoning/technique-differential-testing.md",
          "ref": "reasoning:technique-differential-testing"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-assertion-checking",
          "json": "https://banes-lab.com/json/records/reasoning/technique-assertion-checking",
          "label": "Assertion Checking",
          "markdown": "https://banes-lab.com/records/reasoning/technique-assertion-checking.md",
          "ref": "reasoning:technique-assertion-checking"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-node-ver-ground-truth",
          "json": "https://banes-lab.com/json/records/reasoning/node-ver-ground-truth",
          "label": "Ground Truth",
          "markdown": "https://banes-lab.com/records/reasoning/node-ver-ground-truth.md",
          "ref": "reasoning:node-ver-ground-truth"
        },
        {
          "href": "https://banes-lab.com/ontology/schema#vocabulary-evidence-source-test-result",
          "json": "https://banes-lab.com/json/records/vocabulary/evidence-source-test-result",
          "label": "test-result",
          "markdown": "https://banes-lab.com/records/vocabulary/evidence-source-test-result.md",
          "ref": "vocabulary:evidence-source-test-result"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-node-ver-evidence",
          "json": "https://banes-lab.com/json/records/reasoning/node-ver-evidence",
          "label": "Evidence",
          "markdown": "https://banes-lab.com/records/reasoning/node-ver-evidence.md",
          "ref": "reasoning:node-ver-evidence"
        },
        {
          "href": "https://banes-lab.com/ontology/schema#vocabulary-verdict-pass",
          "json": "https://banes-lab.com/json/records/vocabulary/verdict-pass",
          "label": "pass",
          "markdown": "https://banes-lab.com/records/vocabulary/verdict-pass.md",
          "ref": "vocabulary:verdict-pass"
        },
        {
          "href": "https://banes-lab.com/ontology/schema#vocabulary-verdict-fail",
          "json": "https://banes-lab.com/json/records/vocabulary/verdict-fail",
          "label": "fail",
          "markdown": "https://banes-lab.com/records/vocabulary/verdict-fail.md",
          "ref": "vocabulary:verdict-fail"
        },
        {
          "href": "https://banes-lab.com/ontology/schema#vocabulary-verdict-unknown",
          "json": "https://banes-lab.com/json/records/vocabulary/verdict-unknown",
          "label": "unknown",
          "markdown": "https://banes-lab.com/records/vocabulary/verdict-unknown.md",
          "ref": "vocabulary:verdict-unknown"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-dimension-function",
          "json": "https://banes-lab.com/json/records/reasoning/dimension-function",
          "label": "Function",
          "markdown": "https://banes-lab.com/records/reasoning/dimension-function.md",
          "ref": "reasoning:dimension-function"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-lens-behavior",
          "json": "https://banes-lab.com/json/records/reasoning/lens-behavior",
          "label": "Behavior",
          "markdown": "https://banes-lab.com/records/reasoning/lens-behavior.md",
          "ref": "reasoning:lens-behavior"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-correct-state-evolution",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-correct-state-evolution",
          "label": "Correct State Evolution",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-correct-state-evolution.md",
          "ref": "reasoning:invariant-correct-state-evolution"
        },
        {
          "href": "https://banes-lab.com/ontology/schema#vocabulary-predicate-type-invariant",
          "json": "https://banes-lab.com/json/records/vocabulary/predicate-type-invariant",
          "label": "invariant",
          "markdown": "https://banes-lab.com/records/vocabulary/predicate-type-invariant.md",
          "ref": "vocabulary:predicate-type-invariant"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-integration-testing",
          "json": "https://banes-lab.com/json/records/reasoning/technique-integration-testing",
          "label": "Integration Testing",
          "markdown": "https://banes-lab.com/records/reasoning/technique-integration-testing.md",
          "ref": "reasoning:technique-integration-testing"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-model-checking",
          "json": "https://banes-lab.com/json/records/reasoning/technique-model-checking",
          "label": "Model Checking",
          "markdown": "https://banes-lab.com/records/reasoning/technique-model-checking.md",
          "ref": "reasoning:technique-model-checking"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-dimension-state",
          "json": "https://banes-lab.com/json/records/reasoning/dimension-state",
          "label": "State",
          "markdown": "https://banes-lab.com/records/reasoning/dimension-state.md",
          "ref": "reasoning:dimension-state"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-lens-sequential",
          "json": "https://banes-lab.com/json/records/reasoning/lens-sequential",
          "label": "Sequential",
          "markdown": "https://banes-lab.com/records/reasoning/lens-sequential.md",
          "ref": "reasoning:lens-sequential"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-valid-state-transitions",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-valid-state-transitions",
          "label": "Valid State Transitions",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-valid-state-transitions.md",
          "ref": "reasoning:invariant-valid-state-transitions"
        },
        {
          "href": "https://banes-lab.com/ontology/schema#vocabulary-predicate-type-temporal-order",
          "json": "https://banes-lab.com/json/records/vocabulary/predicate-type-temporal-order",
          "label": "temporal-order",
          "markdown": "https://banes-lab.com/records/vocabulary/predicate-type-temporal-order.md",
          "ref": "vocabulary:predicate-type-temporal-order"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-dimension-structure",
          "json": "https://banes-lab.com/json/records/reasoning/dimension-structure",
          "label": "Structure",
          "markdown": "https://banes-lab.com/records/reasoning/dimension-structure.md",
          "ref": "reasoning:dimension-structure"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-lens-structure",
          "json": "https://banes-lab.com/json/records/reasoning/lens-structure",
          "label": "Structure",
          "markdown": "https://banes-lab.com/records/reasoning/lens-structure.md",
          "ref": "reasoning:lens-structure"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-valid-interfaces-and-contracts",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-valid-interfaces-and-contracts",
          "label": "Valid Interfaces and Contracts",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-valid-interfaces-and-contracts.md",
          "ref": "reasoning:invariant-valid-interfaces-and-contracts"
        },
        {
          "href": "https://banes-lab.com/ontology/schema#vocabulary-predicate-type-schema",
          "json": "https://banes-lab.com/json/records/vocabulary/predicate-type-schema",
          "label": "schema",
          "markdown": "https://banes-lab.com/records/vocabulary/predicate-type-schema.md",
          "ref": "vocabulary:predicate-type-schema"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-runtime-validation",
          "json": "https://banes-lab.com/json/records/reasoning/technique-runtime-validation",
          "label": "Runtime Validation",
          "markdown": "https://banes-lab.com/records/reasoning/technique-runtime-validation.md",
          "ref": "reasoning:technique-runtime-validation"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-contract-testing",
          "json": "https://banes-lab.com/json/records/reasoning/technique-contract-testing",
          "label": "Contract Testing",
          "markdown": "https://banes-lab.com/records/reasoning/technique-contract-testing.md",
          "ref": "reasoning:technique-contract-testing"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-dimension-relation",
          "json": "https://banes-lab.com/json/records/reasoning/dimension-relation",
          "label": "Relation",
          "markdown": "https://banes-lab.com/records/reasoning/dimension-relation.md",
          "ref": "reasoning:dimension-relation"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-lens-relation",
          "json": "https://banes-lab.com/json/records/reasoning/lens-relation",
          "label": "Relation",
          "markdown": "https://banes-lab.com/records/reasoning/lens-relation.md",
          "ref": "reasoning:lens-relation"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-correct-interactions",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-correct-interactions",
          "label": "Correct Interactions",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-correct-interactions.md",
          "ref": "reasoning:invariant-correct-interactions"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-end-to-end-testing",
          "json": "https://banes-lab.com/json/records/reasoning/technique-end-to-end-testing",
          "label": "End To End Testing",
          "markdown": "https://banes-lab.com/records/reasoning/technique-end-to-end-testing.md",
          "ref": "reasoning:technique-end-to-end-testing"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-dimension-time",
          "json": "https://banes-lab.com/json/records/reasoning/dimension-time",
          "label": "Time",
          "markdown": "https://banes-lab.com/records/reasoning/dimension-time.md",
          "ref": "reasoning:dimension-time"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-lens-time",
          "json": "https://banes-lab.com/json/records/reasoning/lens-time",
          "label": "Time",
          "markdown": "https://banes-lab.com/records/reasoning/lens-time.md",
          "ref": "reasoning:lens-time"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-acceptable-execution-time",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-acceptable-execution-time",
          "label": "Acceptable Execution Time",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-acceptable-execution-time.md",
          "ref": "reasoning:invariant-acceptable-execution-time"
        },
        {
          "href": "https://banes-lab.com/ontology/schema#vocabulary-predicate-type-bound",
          "json": "https://banes-lab.com/json/records/vocabulary/predicate-type-bound",
          "label": "bound",
          "markdown": "https://banes-lab.com/records/vocabulary/predicate-type-bound.md",
          "ref": "vocabulary:predicate-type-bound"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-load-testing",
          "json": "https://banes-lab.com/json/records/reasoning/technique-load-testing",
          "label": "Load Testing",
          "markdown": "https://banes-lab.com/records/reasoning/technique-load-testing.md",
          "ref": "reasoning:technique-load-testing"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-monitoring",
          "json": "https://banes-lab.com/json/records/reasoning/technique-monitoring",
          "label": "Monitoring",
          "markdown": "https://banes-lab.com/records/reasoning/technique-monitoring.md",
          "ref": "reasoning:technique-monitoring"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-tracing",
          "json": "https://banes-lab.com/json/records/reasoning/technique-tracing",
          "label": "Tracing",
          "markdown": "https://banes-lab.com/records/reasoning/technique-tracing.md",
          "ref": "reasoning:technique-tracing"
        },
        {
          "href": "https://banes-lab.com/ontology/schema#vocabulary-evidence-source-measurement",
          "json": "https://banes-lab.com/json/records/vocabulary/evidence-source-measurement",
          "label": "measurement",
          "markdown": "https://banes-lab.com/records/vocabulary/evidence-source-measurement.md",
          "ref": "vocabulary:evidence-source-measurement"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-dimension-behavior",
          "json": "https://banes-lab.com/json/records/reasoning/dimension-behavior",
          "label": "Behavior",
          "markdown": "https://banes-lab.com/records/reasoning/dimension-behavior.md",
          "ref": "reasoning:dimension-behavior"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-safe-concurrent-behavior",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-safe-concurrent-behavior",
          "label": "Safe Concurrent Behavior",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-safe-concurrent-behavior.md",
          "ref": "reasoning:invariant-safe-concurrent-behavior"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-stress-testing",
          "json": "https://banes-lab.com/json/records/reasoning/technique-stress-testing",
          "label": "Stress Testing",
          "markdown": "https://banes-lab.com/records/reasoning/technique-stress-testing.md",
          "ref": "reasoning:technique-stress-testing"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-deterministic-replay",
          "json": "https://banes-lab.com/json/records/reasoning/technique-deterministic-replay",
          "label": "Deterministic Replay",
          "markdown": "https://banes-lab.com/records/reasoning/technique-deterministic-replay.md",
          "ref": "reasoning:technique-deterministic-replay"
        },
        {
          "href": "https://banes-lab.com/ontology/schema#vocabulary-evidence-source-runtime-observation",
          "json": "https://banes-lab.com/json/records/vocabulary/evidence-source-runtime-observation",
          "label": "runtime-observation",
          "markdown": "https://banes-lab.com/records/vocabulary/evidence-source-runtime-observation.md",
          "ref": "vocabulary:evidence-source-runtime-observation"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-dimension-composition",
          "json": "https://banes-lab.com/json/records/reasoning/dimension-composition",
          "label": "Composition",
          "markdown": "https://banes-lab.com/records/reasoning/dimension-composition.md",
          "ref": "reasoning:dimension-composition"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-lens-change",
          "json": "https://banes-lab.com/json/records/reasoning/lens-change",
          "label": "Change",
          "markdown": "https://banes-lab.com/records/reasoning/lens-change.md",
          "ref": "reasoning:lens-change"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-controlled-memory-usage",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-controlled-memory-usage",
          "label": "Controlled Memory Usage",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-controlled-memory-usage.md",
          "ref": "reasoning:invariant-controlled-memory-usage"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-heap-analysis",
          "json": "https://banes-lab.com/json/records/reasoning/technique-heap-analysis",
          "label": "Heap Analysis",
          "markdown": "https://banes-lab.com/records/reasoning/technique-heap-analysis.md",
          "ref": "reasoning:technique-heap-analysis"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-profiling",
          "json": "https://banes-lab.com/json/records/reasoning/technique-profiling",
          "label": "Profiling",
          "markdown": "https://banes-lab.com/records/reasoning/technique-profiling.md",
          "ref": "reasoning:technique-profiling"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-acceptable-resource-consumption",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-acceptable-resource-consumption",
          "label": "Acceptable Resource Consumption",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-acceptable-resource-consumption.md",
          "ref": "reasoning:invariant-acceptable-resource-consumption"
        },
        {
          "href": "https://banes-lab.com/ontology/schema#vocabulary-predicate-type-absence",
          "json": "https://banes-lab.com/json/records/vocabulary/predicate-type-absence",
          "label": "absence",
          "markdown": "https://banes-lab.com/records/vocabulary/predicate-type-absence.md",
          "ref": "vocabulary:predicate-type-absence"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-dimension-scale",
          "json": "https://banes-lab.com/json/records/reasoning/dimension-scale",
          "label": "Scale",
          "markdown": "https://banes-lab.com/records/reasoning/dimension-scale.md",
          "ref": "reasoning:dimension-scale"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-lens-statistical",
          "json": "https://banes-lab.com/json/records/reasoning/lens-statistical",
          "label": "Statistical",
          "markdown": "https://banes-lab.com/records/reasoning/lens-statistical.md",
          "ref": "reasoning:lens-statistical"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-dimension-probability",
          "json": "https://banes-lab.com/json/records/reasoning/dimension-probability",
          "label": "Probability",
          "markdown": "https://banes-lab.com/records/reasoning/dimension-probability.md",
          "ref": "reasoning:dimension-probability"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-lens-anomaly",
          "json": "https://banes-lab.com/json/records/reasoning/lens-anomaly",
          "label": "Anomaly",
          "markdown": "https://banes-lab.com/records/reasoning/lens-anomaly.md",
          "ref": "reasoning:lens-anomaly"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-reliability-under-faults",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-reliability-under-faults",
          "label": "Reliability Under Faults",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-reliability-under-faults.md",
          "ref": "reasoning:invariant-reliability-under-faults"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-chaos-testing",
          "json": "https://banes-lab.com/json/records/reasoning/technique-chaos-testing",
          "label": "Chaos Testing",
          "markdown": "https://banes-lab.com/records/reasoning/technique-chaos-testing.md",
          "ref": "reasoning:technique-chaos-testing"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-fault-injection",
          "json": "https://banes-lab.com/json/records/reasoning/technique-fault-injection",
          "label": "Fault Injection",
          "markdown": "https://banes-lab.com/records/reasoning/technique-fault-injection.md",
          "ref": "reasoning:technique-fault-injection"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-availability-under-stress",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-availability-under-stress",
          "label": "Availability Under Stress",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-availability-under-stress.md",
          "ref": "reasoning:invariant-availability-under-stress"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-consistency-across-components",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-consistency-across-components",
          "label": "Consistency Across Components",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-consistency-across-components.md",
          "ref": "reasoning:invariant-consistency-across-components"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-dimension-identity",
          "json": "https://banes-lab.com/json/records/reasoning/dimension-identity",
          "label": "Identity",
          "markdown": "https://banes-lab.com/records/reasoning/dimension-identity.md",
          "ref": "reasoning:dimension-identity"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-numerical-validity",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-numerical-validity",
          "label": "Numerical Validity",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-numerical-validity.md",
          "ref": "reasoning:invariant-numerical-validity"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-static-analysis",
          "json": "https://banes-lab.com/json/records/reasoning/technique-static-analysis",
          "label": "Static Analysis",
          "markdown": "https://banes-lab.com/records/reasoning/technique-static-analysis.md",
          "ref": "reasoning:technique-static-analysis"
        },
        {
          "href": "https://banes-lab.com/ontology/schema#vocabulary-evidence-source-analysis-report",
          "json": "https://banes-lab.com/json/records/vocabulary/evidence-source-analysis-report",
          "label": "analysis-report",
          "markdown": "https://banes-lab.com/records/vocabulary/evidence-source-analysis-report.md",
          "ref": "vocabulary:evidence-source-analysis-report"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-dimension-cause",
          "json": "https://banes-lab.com/json/records/reasoning/dimension-cause",
          "label": "Cause",
          "markdown": "https://banes-lab.com/records/reasoning/dimension-cause.md",
          "ref": "reasoning:dimension-cause"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-lens-cause",
          "json": "https://banes-lab.com/json/records/reasoning/lens-cause",
          "label": "Cause",
          "markdown": "https://banes-lab.com/records/reasoning/lens-cause.md",
          "ref": "reasoning:lens-cause"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-security-boundaries",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-security-boundaries",
          "label": "Security Boundaries",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-security-boundaries.md",
          "ref": "reasoning:invariant-security-boundaries"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-technique-fuzz-testing",
          "json": "https://banes-lab.com/json/records/reasoning/technique-fuzz-testing",
          "label": "Fuzz Testing",
          "markdown": "https://banes-lab.com/records/reasoning/technique-fuzz-testing.md",
          "ref": "reasoning:technique-fuzz-testing"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-dimension-novelty",
          "json": "https://banes-lab.com/json/records/reasoning/dimension-novelty",
          "label": "Novelty",
          "markdown": "https://banes-lab.com/records/reasoning/dimension-novelty.md",
          "ref": "reasoning:dimension-novelty"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-deterministic-behavior-where-required",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-deterministic-behavior-where-required",
          "label": "Required Determinism",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-deterministic-behavior-where-required.md",
          "ref": "reasoning:invariant-deterministic-behavior-where-required"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-protocol-compliance",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-protocol-compliance",
          "label": "Protocol Compliance",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-protocol-compliance.md",
          "ref": "reasoning:invariant-protocol-compliance"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-configuration-validity",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-configuration-validity",
          "label": "Configuration Validity",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-configuration-validity.md",
          "ref": "reasoning:invariant-configuration-validity"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-lens-frequency",
          "json": "https://banes-lab.com/json/records/reasoning/lens-frequency",
          "label": "Frequency",
          "markdown": "https://banes-lab.com/records/reasoning/lens-frequency.md",
          "ref": "reasoning:lens-frequency"
        },
        {
          "href": "https://banes-lab.com/ontology/reasoning#reasoning-invariant-accurate-observability",
          "json": "https://banes-lab.com/json/records/reasoning/invariant-accurate-observability",
          "label": "Accurate Observability",
          "markdown": "https://banes-lab.com/records/reasoning/invariant-accurate-observability.md",
          "ref": "reasoning:invariant-accurate-observability"
        }
      ],
      "relation": "links-to"
    },
    {
      "links": [
        {
          "href": "https://banes-lab.com/software-architecture/coverage#what-can-drift-seen-through-how-it-drifts",
          "json": "https://banes-lab.com/json/software-architecture/coverage/what-can-drift-seen-through-how-it-drifts",
          "label": "What can drift, seen through how it drifts",
          "markdown": "https://banes-lab.com/software-architecture/coverage/what-can-drift-seen-through-how-it-drifts.md",
          "ref": "chapter:/software-architecture/coverage#what-can-drift-seen-through-how-it-drifts"
        }
      ],
      "relation": "linked-from"
    }
  ],
  "route": null,
  "section": "the-test-surfaces",
  "summary": "The test surfaces are what a system can be wrong about.",
  "tab": "reasoning",
  "title": "The test surfaces",
  "siblings": {
    "next": {
      "href": "https://banes-lab.com/ontology/reasoning#the-techniques",
      "json": "https://banes-lab.com/json/ontology/reasoning/the-techniques",
      "label": "The techniques",
      "markdown": "https://banes-lab.com/ontology/reasoning/the-techniques.md",
      "ref": "chapter:/ontology/reasoning#the-techniques"
    },
    "previous": {
      "href": "https://banes-lab.com/ontology/reasoning#the-universal-axes",
      "json": "https://banes-lab.com/json/ontology/reasoning/the-universal-axes",
      "label": "The universal axes",
      "markdown": "https://banes-lab.com/ontology/reasoning/the-universal-axes.md",
      "ref": "chapter:/ontology/reasoning#the-universal-axes"
    }
  },
  "up": {
    "href": "https://banes-lab.com/ontology/reasoning",
    "json": "https://banes-lab.com/json/api/pages/ontology/reasoning",
    "label": "Ontology · Reasoning",
    "markdown": "https://banes-lab.com/api/pages/ontology/reasoning.md",
    "ref": "api:/ontology/reasoning"
  }
}
