ADR-0004 Emission load formula
#Context
The emission budget is the load-bearing novelty of the system. Everything downstream is a bet on one number being stable enough to gate a merge and legible enough that a person can act on a failure. ADR-0001 committed to that bet; this decision resolves what the number is.
The playbook drafted the metric as total luminance above the substrate floor. The Phase 0 spike proved that definition wrong before any token existed. max(0, L − floor) is defined only for dark themes: in interior-light and field-day the chrome sits below the substrate, every term clamps to zero, and a Scope reads no emission at all. ADR-0003 commits every semantic token to all four themes from Phase 1, so a formula that silently passes two of them was unusable. The spike also demonstrated the failure as an exploit: a probe declaring a bright substrate with dark chrome scored 0.00000 and passed.
#Decision
Emission load for a Scope is the mean absolute perceptual deviation from its substrate, normalized by available headroom:
load(Scope) = Σ |L_block − L_substrate| · n_block
/ (governedPixels · max(L_substrate, 1 − L_substrate))L is OKLab lightness, not relative luminance. Lightness is the axis the token pipeline already authors in (ADR pipeline, playbook §7), and it is perceptually uniform, which relative luminance is not.
Four properties follow, and each was measured rather than assumed:
Direction is discarded. Attention does not care whether a mark is lighter or darker than its ground; a dark glyph on white and a bright badge on black both pull the eye. Absolute value gives one formula for all four themes with no per-theme branch.
The normalizer generalizes headroom. max(L_substrate, 1 − L_substrate) keeps output in 0 to 1 for dark, light, and mid-tone substrates. A full-white element on field-night scores exactly 1.0, as does full-black on interior-light. A mid-tone substrate has the least headroom, so identical chrome costs more there. That is intended: mid grey is the hardest ground to signal against in either direction, and a budget that charges more for it is reporting a real property of the design.
Content is masked before summing, per ADR-0009, via slot contracts. governedPixels counts chrome only.
Two tolerances, not one. Same-machine reproducibility asserts exact equality. Cross-platform drift is bounded at 1.0 × 10⁻³.
The ceiling is provisional at 0.200 and is not settled by this decision. It is derived in Phase 1 jointly with the OKLCH ramps, because a ceiling calibrated against fixtures whose brightness nothing has yet disciplined would encode the fixtures rather than the system.
#Rejected options
Relative luminance Y with a one-directional floor (max(0, L − floor)), the playbook's original draft. Physically intuitive and correct for dark themes. Rejected because it is undefined for light substrates: two of four committed themes read zero, and the substrate-inflation probe scored 0.00000 and passed. Under the accepted formula the same probe reads 0.41462 and fails on emission. One change closed a correctness hole and an exploit together.
Signed deviation. Preserves the physical reading and distinguishes brightening from darkening. Rejected because signs cancel: dark ink and a bright badge in one Scope subtract from each other, and a busy region can sum toward zero while shouting.
Per-theme direction, flipping the comparison for light themes. Superficially the smallest change. Rejected on its own terms before the maintenance cost: a white card on a light grey page in interior-light sits above the floor and would still read zero. It also has no defined behavior on a mid-tone substrate, which field-day may require.
APCA-based per-pixel contrast. Uses an algorithm already in the pipeline and is perceptually grounded. Rejected on two counts. APCA is a pair-based text-contrast metric, used off-label as a per-pixel field measure. More seriously, it welds the budget to the contrast check, and those must stay independent: contrast is a floor the budget may never suppress past (playbook §7). Coupling them means a threshold revision silently moves every emission number in the system.
Block downsampling before summing. Under the old formula it was a free optimization, identical to six decimals at block sizes 1, 4, and 8. Rejected, and the grounds strengthened under absolute deviation: a block containing pixels both lighter and darker than the substrate lets them cancel inside the block. Downsampling no longer buys nothing, it actively understates.
A single tolerance at 1.0 × 10⁻³. One number answering two questions, sized for the looser one. Rejected because same-machine reproducibility measures exactly zero on both platforms, so any nonzero value there is a defect rather than noise, and a 1.0 × 10⁻³ bound would hide a thirtyfold worsening of platform drift.
A platform bound at 1.0 × 10⁻⁴. Proposed against dark-theme data, where worst drift was 2.2 × 10⁻⁵. Rejected by measurement: the light-substrate fixture drifts 2.21 × 10⁻⁴, an order of magnitude higher, and the bound failed on its first four-scene run. This is the fixture earning its place. The bound is 1.0 × 10⁻³, with 4.5× margin on the worst measured case.
A second ceiling to close scope dilution. Proposed when dilution measured 2.5×, gating on both load-per-area and unnormalized total. Rejected because absolute deviation reduced dilution to 1.4× on its own: empty substrate is no longer free. The residual is inside the range of legitimate design variation, and a second gate would be machinery bought for a problem the direction term mostly solved. Recorded as a tolerated residual; revisit only if Phase 1 calibration widens it.
#Consequences
Measured properties, four scenes, both platforms:
| Property | Result |
|---|---|
| Same-machine reproducibility | 0 on all four scenes, both platforms |
| Worst cross-platform drift | 2.21 × 10⁻⁴ (04-calm-light, queue Scope) |
| Worst dark-scene drift | 2.20 × 10⁻⁵ |
| Font term | 0, via a generated face bundled in the fixtures |
| Mask integrity | Exact across three content payloads; 0 movement |
| Scope dilution residual | 1.4× |
Drift signs scatter either side of zero, which reads as last-digit rounding rather than the one-directional CoreText and FreeType ink bias visible under the old formula.
What remains open. Three exploits survive Phase 0 by design. Content laundering, wrapping bright chrome in a content slot, is the price ADR-0009 named; it closes in Phase 3 with typed slots and is narrowed in Phase 1 by a lint rule. Level under-declaration, a full-intensity block declared level 2, is routed to ADR-0005: the spike measured a 0.01790 share for an under-declared block against 0.01759 for a genuine level-4, which is the evidence that share alone cannot separate a swarm from a demand, so ADR-0005 needs a share term and an absolute term. Gradient smuggling now sits at 86% of the provisional ceiling, which is itself the argument for deriving the ceiling with the ramps rather than before them.
Touched checks. Emission load and both salience rows in the playbook §10 enforcement table. The playbook §8 sentence defining the metric as luminance above the floor is superseded by this decision; the term *emission load* is retained as a defined term of art meaning deviation from substrate, and the physical-light reading is retired.
A promotion. The substrate floor check moves from warning to error. A declared bright substrate zeroing the sum is the same hole as the direction term seen from the other side.