# Failure shapes

> Each failure shape names a way a check goes wrong without failing, the invariant it breaks, its fix, the records it shows up in and the quality rules that…

Page: Ontology · Reasoning
Canonical: https://banes-lab.com/ontology/reasoning#the-failure-shapes

Listed in [Ontology · Reasoning](https://banes-lab.com/api/pages/ontology/reasoning.md), after [The invariants](https://banes-lab.com/ontology/reasoning/the-invariants.md) and before [The uncovered cells](https://banes-lab.com/ontology/reasoning/the-uncovered-cells.md).

Each failure shape names a way a check goes wrong without failing, the invariant it breaks, its fix, the records it shows up in and the quality rules that refuse it.

### No reachable check

Details

Shape
A representation that no check reaches.

Fix
Declare the representation into a check's jurisdiction, or state in writing that it lies outside it.

Breaks
[epi-reachable-check](https://banes-lab.com/records/reasoning/invariant-epi-reachable-check.md)

Seen in
[Manual-Only Governance](https://banes-lab.com/records/architecture/manual-only-governance.md), [Unobservable Failure](https://banes-lab.com/records/architecture/unobservable-failure.md), [Untested Implementation](https://banes-lab.com/records/lexicon/untested-implementation.md)

Refused by rules
None, because whether a representation is reachable is a property of the gate's jurisdiction, which no source rule sees

How it is checked

Checked by
the quality rules each shape names, which refuse its syntactic signature where one exists, the classification step of the verification substrate, which files every silent failure under a shape before a fix is chosen

Population
Every source file the named rules lint, and every failure a check or a review classifies

Freshness
A verdict stands until the linted source, a named rule or the shape's instances change

Refusal
A named rule fails the lint stage on the signature; the invariant each shape breaks is gated in every structured document that grounds it

Observation
The runtime observations that locate a failure, which are then filed under a shape

Evidence
Watched to fire and to accept: a suite plants a shape that names no invariant and no canon, and the bundled shapes validate clean

Authoritative side
The invariant the shape breaks, which the shape cites, while each named rule conforms to the shape's signature

Depends on
Not answered

Shape it refuses
Not answered

### Empty domain

Details

Shape
A check that ran over an empty domain and reported a pass.

Fix
Report the population beside every rate, and confirm at start-up that every name the check uses resolves.

Breaks
[epi-declared-domain](https://banes-lab.com/records/reasoning/invariant-epi-declared-domain.md)

Seen in
[Silent Failure](https://banes-lab.com/records/lexicon/silent-failure.md)

Refused by rules
empty-block, exception-handling

How it is checked

Checked by
the quality rules each shape names, which refuse its syntactic signature where one exists, the classification step of the verification substrate, which files every silent failure under a shape before a fix is chosen

Population
Every source file the named rules lint, and every failure a check or a review classifies

Freshness
A verdict stands until the linted source, a named rule or the shape's instances change

Refusal
A named rule fails the lint stage on the signature; the invariant each shape breaks is gated in every structured document that grounds it

Observation
The runtime observations that locate a failure, which are then filed under a shape

Evidence
Watched to fire and to accept: a suite plants a shape that names no invariant and no canon, and the bundled shapes validate clean

Authoritative side
The invariant the shape breaks, which the shape cites, while each named rule conforms to the shape's signature

Depends on
Not answered

Shape it refuses
Not answered

### Spent parent

Details

Shape
A parent counted as read while its children were never read.

Fix
Subtract the read set from the child set and report what remains.

Breaks
[epi-declared-domain](https://banes-lab.com/records/reasoning/invariant-epi-declared-domain.md)

Refused by rules
None, because a read set is known only while the run executes

How it is checked

Checked by
the quality rules each shape names, which refuse its syntactic signature where one exists, the classification step of the verification substrate, which files every silent failure under a shape before a fix is chosen

Population
Every source file the named rules lint, and every failure a check or a review classifies

Freshness
A verdict stands until the linted source, a named rule or the shape's instances change

Refusal
A named rule fails the lint stage on the signature; the invariant each shape breaks is gated in every structured document that grounds it

Observation
The runtime observations that locate a failure, which are then filed under a shape

Evidence
Watched to fire and to accept: a suite plants a shape that names no invariant and no canon, and the bundled shapes validate clean

Authoritative side
The invariant the shape breaks, which the shape cites, while each named rule conforms to the shape's signature

Depends on
Not answered

Shape it refuses
Not answered

### Edge from spelling

Details

Shape
A dependency created because two names share a word.

Fix
Join on the id the referent declares.

Breaks
[epi-declared-dependency](https://banes-lab.com/records/reasoning/invariant-epi-declared-dependency.md)

Seen in
[Hidden Dependencies](https://banes-lab.com/records/lexicon/hidden-dependencies.md)

Refused by rules
None, because a join on spelling reads like any other string comparison in source

How it is checked

Checked by
the quality rules each shape names, which refuse its syntactic signature where one exists, the classification step of the verification substrate, which files every silent failure under a shape before a fix is chosen

Population
Every source file the named rules lint, and every failure a check or a review classifies

Freshness
A verdict stands until the linted source, a named rule or the shape's instances change

Refusal
A named rule fails the lint stage on the signature; the invariant each shape breaks is gated in every structured document that grounds it

Observation
The runtime observations that locate a failure, which are then filed under a shape

Evidence
Watched to fire and to accept: a suite plants a shape that names no invariant and no canon, and the bundled shapes validate clean

Authoritative side
The invariant the shape breaks, which the shape cites, while each named rule conforms to the shape's signature

Depends on
Not answered

Shape it refuses
Not answered

### Trusted leaf

Details

Shape
A node inside the graph that is trusted without a check, such as an exit code or a modification time.

Fix
Route the node through a check that can fail, and disclose what no check can reach.

Breaks
[epi-verdict-is-representation](https://banes-lab.com/records/reasoning/invariant-epi-verdict-is-representation.md)

Seen in
[Flaky Test Normalization](https://banes-lab.com/records/architecture/flaky-test-normalization.md), [Mock Mirage](https://banes-lab.com/records/architecture/mock-mirage.md), [Security Theater](https://banes-lab.com/records/architecture/security-theater.md)

Refused by rules
error-handling

How it is checked

Checked by
the quality rules each shape names, which refuse its syntactic signature where one exists, the classification step of the verification substrate, which files every silent failure under a shape before a fix is chosen

Population
Every source file the named rules lint, and every failure a check or a review classifies

Freshness
A verdict stands until the linted source, a named rule or the shape's instances change

Refusal
A named rule fails the lint stage on the signature; the invariant each shape breaks is gated in every structured document that grounds it

Observation
The runtime observations that locate a failure, which are then filed under a shape

Evidence
Watched to fire and to accept: a suite plants a shape that names no invariant and no canon, and the bundled shapes validate clean

Authoritative side
The invariant the shape breaks, which the shape cites, while each named rule conforms to the shape's signature

Depends on
Not answered

Shape it refuses
Not answered

### Lossy lowering

Details

Shape
A reshaped representation that dropped a distinction a later check needs.

Fix
Keep the distinction, and refuse at the writer anything the layout cannot express.

Breaks
[epi-preserved-distinction](https://banes-lab.com/records/reasoning/invariant-epi-preserved-distinction.md)

Seen in
[Null Semantics Drift](https://banes-lab.com/records/architecture/null-semantics-drift.md), [Schema Drift](https://banes-lab.com/records/architecture/schema-drift.md), [Silent Data Corruption](https://banes-lab.com/records/architecture/silent-data-corruption.md)

Refused by rules
type-safety

How it is checked

Checked by
the quality rules each shape names, which refuse its syntactic signature where one exists, the classification step of the verification substrate, which files every silent failure under a shape before a fix is chosen

Population
Every source file the named rules lint, and every failure a check or a review classifies

Freshness
A verdict stands until the linted source, a named rule or the shape's instances change

Refusal
A named rule fails the lint stage on the signature; the invariant each shape breaks is gated in every structured document that grounds it

Observation
The runtime observations that locate a failure, which are then filed under a shape

Evidence
Watched to fire and to accept: a suite plants a shape that names no invariant and no canon, and the bundled shapes validate clean

Authoritative side
The invariant the shape breaks, which the shape cites, while each named rule conforms to the shape's signature

Depends on
Not answered

Shape it refuses
Not answered

### Stale read

Details

Shape
A check that reads a representation the run already changed.

Fix
Derive after the last mutator, and decide freshness by the fingerprint of the inputs and the code.

Breaks
[epi-fresh-read](https://banes-lab.com/records/reasoning/invariant-epi-fresh-read.md)

Seen in
[Cache Poisoning by Design](https://banes-lab.com/records/architecture/cache-poisoning-by-design.md)

Refused by rules
None, because no catalogued rule refuses a cache keyed by time or by lifetime alone

How it is checked

Checked by
the quality rules each shape names, which refuse its syntactic signature where one exists, the classification step of the verification substrate, which files every silent failure under a shape before a fix is chosen

Population
Every source file the named rules lint, and every failure a check or a review classifies

Freshness
A verdict stands until the linted source, a named rule or the shape's instances change

Refusal
A named rule fails the lint stage on the signature; the invariant each shape breaks is gated in every structured document that grounds it

Observation
The runtime observations that locate a failure, which are then filed under a shape

Evidence
Watched to fire and to accept: a suite plants a shape that names no invariant and no canon, and the bundled shapes validate clean

Authoritative side
The invariant the shape breaks, which the shape cites, while each named rule conforms to the shape's signature

Depends on
Not answered

Shape it refuses
Not answered

### Two derivations

Details

Shape
One question answered by two derivations that can drift apart.

Fix
Collapse them to one derivation, computed by the producer of the answer.

Breaks
[epi-one-derivation](https://banes-lab.com/records/reasoning/invariant-epi-one-derivation.md)

Seen in
[Duplicated Authority](https://banes-lab.com/records/lexicon/duplicated-authority.md)

Refused by rules
duplicate-code

How it is checked

Checked by
the quality rules each shape names, which refuse its syntactic signature where one exists, the classification step of the verification substrate, which files every silent failure under a shape before a fix is chosen

Population
Every source file the named rules lint, and every failure a check or a review classifies

Freshness
A verdict stands until the linted source, a named rule or the shape's instances change

Refusal
A named rule fails the lint stage on the signature; the invariant each shape breaks is gated in every structured document that grounds it

Observation
The runtime observations that locate a failure, which are then filed under a shape

Evidence
Watched to fire and to accept: a suite plants a shape that names no invariant and no canon, and the bundled shapes validate clean

Authoritative side
The invariant the shape breaks, which the shape cites, while each named rule conforms to the shape's signature

Depends on
Not answered

Shape it refuses
Not answered

### Weak link kept

Details

Shape
A link below the certainty floor kept in a chain with a flag on it.

Fix
Remove the link from the chain.

Breaks
[epi-weakest-link](https://banes-lab.com/records/reasoning/invariant-epi-weakest-link.md)

Refused by rules
None, because the certainty of a link is a property of the chain, which no source rule sees

How it is checked

Checked by
the quality rules each shape names, which refuse its syntactic signature where one exists, the classification step of the verification substrate, which files every silent failure under a shape before a fix is chosen

Population
Every source file the named rules lint, and every failure a check or a review classifies

Freshness
A verdict stands until the linted source, a named rule or the shape's instances change

Refusal
A named rule fails the lint stage on the signature; the invariant each shape breaks is gated in every structured document that grounds it

Observation
The runtime observations that locate a failure, which are then filed under a shape

Evidence
Watched to fire and to accept: a suite plants a shape that names no invariant and no canon, and the bundled shapes validate clean

Authoritative side
The invariant the shape breaks, which the shape cites, while each named rule conforms to the shape's signature

Depends on
Not answered

Shape it refuses
Not answered

### Absence certified by observation

Details

Shape
No observed failure read as proof that no failure exists.

Fix
Use the observation to locate failures, and leave the verdict on absence to a check.

Breaks
[epi-observation-locates](https://banes-lab.com/records/reasoning/invariant-epi-observation-locates.md)

Refused by rules
None, because the shape lies in how a report is read, not in source

How it is checked

Checked by
the quality rules each shape names, which refuse its syntactic signature where one exists, the classification step of the verification substrate, which files every silent failure under a shape before a fix is chosen

Population
Every source file the named rules lint, and every failure a check or a review classifies

Freshness
A verdict stands until the linted source, a named rule or the shape's instances change

Refusal
A named rule fails the lint stage on the signature; the invariant each shape breaks is gated in every structured document that grounds it

Observation
The runtime observations that locate a failure, which are then filed under a shape

Evidence
Watched to fire and to accept: a suite plants a shape that names no invariant and no canon, and the bundled shapes validate clean

Authoritative side
The invariant the shape breaks, which the shape cites, while each named rule conforms to the shape's signature

Depends on
Not answered

Shape it refuses
Not answered

### Stop on confidence

Details

Shape
A run that stops because the model is confident, before completion, saturation and verification hold.

Fix
Stop only when the three conditions hold, or when the run is blocked on something outside it.

Breaks
[epi-terminate-on-three](https://banes-lab.com/records/reasoning/invariant-epi-terminate-on-three.md)

Refused by rules
None, because the shape lies in how a run decides to stop, not in source

How it is checked

Checked by
the quality rules each shape names, which refuse its syntactic signature where one exists, the classification step of the verification substrate, which files every silent failure under a shape before a fix is chosen

Population
Every source file the named rules lint, and every failure a check or a review classifies

Freshness
A verdict stands until the linted source, a named rule or the shape's instances change

Refusal
A named rule fails the lint stage on the signature; the invariant each shape breaks is gated in every structured document that grounds it

Observation
The runtime observations that locate a failure, which are then filed under a shape

Evidence
Watched to fire and to accept: a suite plants a shape that names no invariant and no canon, and the bundled shapes validate clean

Authoritative side
The invariant the shape breaks, which the shape cites, while each named rule conforms to the shape's signature

Depends on
Not answered

Shape it refuses
Not answered

### Unfailable floor

Details

Shape
A threshold set below what its population already meets, so the check it guards cannot fail until most of the population is gone.

Fix
Set the floor from the population as it stands, and plant a case below it to watch the check fail.

Breaks
[epi-verdict-is-representation](https://banes-lab.com/records/reasoning/invariant-epi-verdict-is-representation.md)

Refused by rules
None, because whether a floor can be reached is a property of the population, which no source rule sees

How it is checked

Checked by
the quality rules each shape names, which refuse its syntactic signature where one exists, the classification step of the verification substrate, which files every silent failure under a shape before a fix is chosen

Population
Every source file the named rules lint, and every failure a check or a review classifies

Freshness
A verdict stands until the linted source, a named rule or the shape's instances change

Refusal
A named rule fails the lint stage on the signature; the invariant each shape breaks is gated in every structured document that grounds it

Observation
The runtime observations that locate a failure, which are then filed under a shape

Evidence
Watched to fire and to accept: a suite plants a shape that names no invariant and no canon, and the bundled shapes validate clean

Authoritative side
The invariant the shape breaks, which the shape cites, while each named rule conforms to the shape's signature

Depends on
Not answered

Shape it refuses
Not answered

### Verdictless verifier

Details

Shape
A tool named as a verifier that reports no pass, no fail and no exit code, so what it examines has no check at all.

Fix
Give the tool a verdict and an exit code, or rename it to the probe it is.

Breaks
[epi-reachable-check](https://banes-lab.com/records/reasoning/invariant-epi-reachable-check.md)

Refused by rules
None, because whether a tool issues a verdict is a property of its output contract, which no source rule sees

How it is checked

Checked by
the quality rules each shape names, which refuse its syntactic signature where one exists, the classification step of the verification substrate, which files every silent failure under a shape before a fix is chosen

Population
Every source file the named rules lint, and every failure a check or a review classifies

Freshness
A verdict stands until the linted source, a named rule or the shape's instances change

Refusal
A named rule fails the lint stage on the signature; the invariant each shape breaks is gated in every structured document that grounds it

Observation
The runtime observations that locate a failure, which are then filed under a shape

Evidence
Watched to fire and to accept: a suite plants a shape that names no invariant and no canon, and the bundled shapes validate clean

Authoritative side
The invariant the shape breaks, which the shape cites, while each named rule conforms to the shape's signature

Depends on
Not answered

Shape it refuses
Not answered

### Unindexed construct kind

Details

Shape
A kind of construct the index a family of checks reads never records, so every check over that index misses every construct of the kind.

Fix
Record the kind in the index, and confirm that a planted construct of the kind is reported.

Breaks
[epi-preserved-distinction](https://banes-lab.com/records/reasoning/invariant-epi-preserved-distinction.md)

Refused by rules
None, because an index's coverage of construct kinds is a property of its builder, which no source rule sees

How it is checked

Checked by
the quality rules each shape names, which refuse its syntactic signature where one exists, the classification step of the verification substrate, which files every silent failure under a shape before a fix is chosen

Population
Every source file the named rules lint, and every failure a check or a review classifies

Freshness
A verdict stands until the linted source, a named rule or the shape's instances change

Refusal
A named rule fails the lint stage on the signature; the invariant each shape breaks is gated in every structured document that grounds it

Observation
The runtime observations that locate a failure, which are then filed under a shape

Evidence
Watched to fire and to accept: a suite plants a shape that names no invariant and no canon, and the bundled shapes validate clean

Authoritative side
The invariant the shape breaks, which the shape cites, while each named rule conforms to the shape's signature

Depends on
Not answered

Shape it refuses
Not answered

## Links to

- [Reachable Check](https://banes-lab.com/records/reasoning/invariant-epi-reachable-check.md)
- [Manual-Only Governance](https://banes-lab.com/records/architecture/manual-only-governance.md)
- [Unobservable Failure](https://banes-lab.com/records/architecture/unobservable-failure.md)
- [Untested Implementation](https://banes-lab.com/records/lexicon/untested-implementation.md)
- [Declared Domain](https://banes-lab.com/records/reasoning/invariant-epi-declared-domain.md)
- [Silent Failure](https://banes-lab.com/records/lexicon/silent-failure.md)
- [Declared Dependency](https://banes-lab.com/records/reasoning/invariant-epi-declared-dependency.md)
- [Hidden Dependencies](https://banes-lab.com/records/lexicon/hidden-dependencies.md)
- [Checked Verdict](https://banes-lab.com/records/reasoning/invariant-epi-verdict-is-representation.md)
- [Flaky Test Normalization](https://banes-lab.com/records/architecture/flaky-test-normalization.md)
- [Mock Mirage](https://banes-lab.com/records/architecture/mock-mirage.md)
- [Security Theater](https://banes-lab.com/records/architecture/security-theater.md)
- [Preserved Distinction](https://banes-lab.com/records/reasoning/invariant-epi-preserved-distinction.md)
- [Null Semantics Drift](https://banes-lab.com/records/architecture/null-semantics-drift.md)
- [Schema Drift](https://banes-lab.com/records/architecture/schema-drift.md)
- [Silent Data Corruption](https://banes-lab.com/records/architecture/silent-data-corruption.md)
- [Fresh Read](https://banes-lab.com/records/reasoning/invariant-epi-fresh-read.md)
- [Cache Poisoning by Design](https://banes-lab.com/records/architecture/cache-poisoning-by-design.md)
- [One Derivation](https://banes-lab.com/records/reasoning/invariant-epi-one-derivation.md)
- [Duplicated Authority](https://banes-lab.com/records/lexicon/duplicated-authority.md)
- [Weakest Link](https://banes-lab.com/records/reasoning/invariant-epi-weakest-link.md)
- [Observation Scope](https://banes-lab.com/records/reasoning/invariant-epi-observation-locates.md)
- [Three-Condition Stop](https://banes-lab.com/records/reasoning/invariant-epi-terminate-on-three.md)
