Skip to contentWolf-Rayet

Decision records

ADR-0005 Salience share threshold at level 3

Accepted2026-08-28Phase 3

#Context

Level 3 is Directed: the thing the screen is pointing at, short of demanding. Every other level has been decidable from the declaration alone. Directed is not, because it is a claim about rank — an element is Directed relative to what surrounds it, and a declaration cannot see its neighbours.

Leaving it undecided cost two things. The ESLint plugin's two-at-level-3 warning fires on a count with nothing behind it: it says a pair is suspicious without being able to say why this pair and not that one. And the level under-declaration exploit has been open since the Phase 0 spike, recorded in STATUS as closing by this ADR: a component declares Ambient and renders like a beacon, and every check stays green because every check reads the declaration. 07-under-declared.html is that exploit as a fixture — it is 02-one-demand.html with one character changed, data-wr-level="4" to "1". Both scenes rasterise identically and both measure 0.096764 on #scope-queue. Nothing that reads declarations can tell them apart.

The obvious fix is a threshold, and a threshold is exactly what this system refuses to carry unless it is derived. The ceiling took a phase and the ramps to earn its number (ADR-0011). A share threshold picked by taste would be the first unprincipled constant in the codebase, and it would sit at the centre of the system's own claim about hierarchy.

#Decision

Directed is a relative property, not an absolute share. A level-3 element must hold the largest emission share among the non-Demanded elements in its Scope, exceeding the runner-up by more than the engine's cross-platform drift tolerance — PLATFORM_TOLERANCE, in packages/budget/src/config.js. The dominance margin is therefore the measurement's own noise floor and carries no invented constant: a dominance this system asserts is one a second renderer would agree with, because that is precisely what the tolerance was measured to bound.

Two level-3 elements whose shares fall within tolerance of each other are measurably undecided. This ratifies the existing two-at-level-3 warning and gives it a criterion: not "there are two of them" but "neither of them wins by an amount the measurement can defend". It stays a warning. Playbook §5 calls the state permitted and flagged, and a suite that failed on it would teach people to manufacture a winner to quiet the tool.

Under-declaration is a failure, and under-declaration is an inversion of the ladder. An element fails when it satisfies dominance, is declared below Directed, and out-emits at least one element declared above it. The message names the element, its declared level, its measured share, the runner-up's share, the element it out-emits with that element's level and share, and the rule. This is the half no declaration-reading check could ever reach.

The inversion clause is not a softening; it is what makes the rule mean anything. An element that out-emits things declared *below* it is doing precisely what the ladder says it should — that is what the levels are for. Dominance alone would fail every Scope whose brightest element is resolvably brightest, which is most Scopes that render at all, and it would make the next sentence false.

Zero level-3 elements remains valid. A Scope with a flat hierarchy and no inversion passes. This is an ordinary and often correct thing for a Scope to be, and a rule that quietly required a Directed element in every Scope would be manufacturing the hierarchy it claims to measure.

The Scope's ground is excluded from the contest. Attribution credits an element with every governed pixel no declared child covers, so a full-Scope surface's share measures area rather than intensity. The ground is any member that encloses every other member: the Scope's own chrome, at 0.029 to 0.044 against a best member of 0.005, and an overlay's scrim, at 0.287 in 06-overlay-violation while the sheet above it reads 0.020 — which ADR-0016 already calls that Scope's ground.

#Rejected options

A fixed percentage share — half the Scope's emission, or similar. Merit: simple to state, simple to test, and immediately legible to anyone reading the rule. Lost because the number has no derivation. It is exactly the unprincipled constant this system refuses to carry, and it does not even hold still: half is trivial to reach among two elements and nearly impossible among twenty, so the same rule would mean something different in every Scope and would quietly punish dense screens for being dense.

Plurality alone, with no margin. Merit: no constant at all, which is the cleanest possible answer to the objection above. Lost because a lead of one part in a thousand flips with antialiasing between renderers — the same asymmetry that forced PLATFORM_TOLERANCE to be set by the light-substrate scene rather than the dark ones. A dominance the measurement cannot reproduce is noise ratified as hierarchy, and CI would disagree with itself across platforms.

Declaration-only, with no measured check. Merit: cheapest by far, already the status quo, and it needs no new machinery in the engine. Lost because it leaves the under-declaration exploit open by design. A component declares Ambient, renders like a beacon, and every receipt stays green while the screen lies — which is worse than having no check, because the receipt is evidence and this one would be false.

A separate tunable threshold token per theme. Merit: genuinely flexible, and the field themes do have different contrast economics, so a single number across four environments is a real simplification. Lost because it multiplies unprincipled constants by four and hands every team a knob to turn when a check is inconvenient. The drift tolerance already varies with what the measurement can actually resolve, which is the only thing the threshold should be sensitive to.

#Consequences

The check runs inside the existing per-Scope salience analysis and adds salience.share to every Scope in every receipt: leader, runner-up, margin, the tolerance it was judged by, and the two verdicts. No emission number moves — the check reads the attribution the engine already computes and adds no measurement.

The engine gains a warnings channel, which it did not have. Failures fail the build; warnings print, appear in the receipt, and leave pass alone. It exists because this decision needed it, not as a home for checks too weak to be failures.

Two fixtures join the un-themed suite. 07-under-declared.html must fail, on salience — share and nothing else — the scope-salience check cannot see it because there are no level-4 elements to count, and emission cannot because one bright block does not exceed the ceiling. 08-undecided.html must pass, carrying the undecided warning, and it is the fixture that makes the margin load-bearing: under plurality alone one of its two level-3 elements would be crowned on a lead of 1.0e-5.

Playbook §10 gains a row. The known-exploits table changes: level under-declaration is narrowed rather than closed — caught wherever it inverts the ladder, by measurement rather than by policy, with the residue named below rather than quietly absorbed.

#How the rule got its two clauses

Both clauses were added because the twenty-one themed scenes refuted the rule without them, which is the same way ADR-0015 was refuted and for the same reason: the fixtures are the experiment, and a rule that has not been run against them is a proposal.

Written as dominance alone against a ground exclusion covering only the Scope node, the check failed nine themed scenes that must pass. Two distinct causes, both real:

  • 05-overlay in all four themes and 06-overlay-violation failed on the scrim and the sheet — #confirm-scrim at 0.287 against a runner-up of 0.020. Both cover their Scope, so both were winning a contest they are not in. 06 failing on salience would also have destroyed ADR-0014's acceptance test, which requires that scene to fail on emission and nothing else.
  • 01-calm, 02-one-demand and 04-calm-light failed in interior-dark only, on #meter-throughput at 0.006091 against #tele-latency at 0.004628 — a margin of 1.5e-3 against a 1.0e-3 bound. A 72% throughput meter is legitimately the brightest thing in a calm telemetry panel, and it is declared level 2 above neighbours declared level 1. Nothing is inverted. Failing it would have made "zero level-3 elements is valid" false for any Scope that renders at all, and it would have failed the calm scene.

An intermediate ground rule — "encloses something smaller" — was tried and is too broad by a wide margin: a .row carrying a chip encloses the chip, so every row in every scene left the contest and a figcaption inherited the lead of 03-violations. Enclosing *every* other member is the rule that survives.

What this makes harder: the margin is generous. #scope-telemetry in the committed scenes runs a leader margin of 3.1e-4 against a 1.0e-3 bound, so a genuine but modest dominance can sit below the threshold and go unflagged. That is the intended direction of the error — the check refuses to call something Directed unless it can prove it — but it means the check is a floor on under-declaration, not a ceiling on it. Tightening it means a per-platform baseline and a same-platform bound, which ADR-004 already notes and does not build.

#What the anti-gaming probes say, including the one that still gets through

The eleven gameability probes were re-run against the check. One verdict changed, and one that should have changed did not. Both are worth stating plainly, because the probe suite exists to be believed.

p7-smuggle is now caught. It delivers light through a gradient and a 90px glow, both declared level 1, in a Scope whose chips are level 2. It passed every check in the system until this one; it now fails salience — share on the inversion. Smuggling light past the declaration through CSS rather than through a level is the same lie as under-declaring, and it is the same clause that catches it.

p5-underdeclare still passes, and it is the probe named for this exploit. It puts a full-intensity demand block in a Scope declared level 2, above level-1 rows and beside level-2 chips. Nothing in that Scope is declared above level 2, so nothing is inverted, and the check has nothing to compare against. The liar declared at the top of its Scope's declared range is invisible to a rule made only of ranks.

This is the honest boundary of the decision. Emission share is area-weighted, so a large level-2 block and a small level-2 chip differ by an order of magnitude for reasons that have nothing to do with intensity; separating "big" from "bright" needs emission per governed pixel, and comparing densities needs a margin in units of density, which PLATFORM_TOLERANCE is not. That margin would be a new constant with no derivation — the option this ADR rejected first and would be rejecting again under another name.

So: the exploit is narrowed, not retired. It is caught wherever the Scope carries a declaration above the liar's, which is every Scope with a real hierarchy, and missed where the liar sits at the top of a flat one. p5-underdeclare stays in the probe suite, passing, as the standing record of what is still open. Closing it is the successor decision, and it needs a density measurement rather than a threshold.

ADR-0010 is untouched: this decision is about rank within a Scope, and the View demand cap is about concurrency across them.