Skip to contentWolf-Rayet

Decision records

ADR-0031 The ceiling's independence is of its inputs, not of its selection

Accepted2026-09-01Phase 1, reopened

#Context

ADR-0030 took the emission ceiling off the scenes it judges. It replaced ADR-0011's calibration against four Phase 0 fixture loads with a derivation from each theme's own ramps and role floors, raised all four ceilings between 18.9% and 39.3%, and closed STATUS open item 11. That decision is right, and this record does not reopen it: the formula, its inputs and all four numbers are carried forward unchanged.

What ADR-0030 got wrong is the account it gave of itself. It made two different claims of independence from scenes, one exact and one too broad, and set them beside each other in one voice as though they were the same claim.

The exact one is the rule it adopted, in *Decision*:

Each theme's emission ceiling is derived from that theme's own ramps and role floors, and reads no scene.

That is true of the mechanism as adopted, and it is verifiable on disk rather than on assertion: packages/budget/receipts/ceiling-derivation.json records "rendersRead": 0, and names its inputs as packages/tokens/receipts/ramps-<theme>.json and packages/tokens/semantic.config.json, both committed generator output. tools/derive-ceiling.js launches no browser.

The broad one is in *Context*, and it is the overstatement:

The question this record answers is the first one, and it is answerable without measuring a single component: a ceiling may not be a function of the loads of the scenes it judges.

The rule stated after the colon can be settled without measuring anything, and it was. But the sentence claims the *question* was answered without measuring a component, and the record's own *Rejected options* say otherwise: two of them give a reason that cites a rendered scene. Both are quoted whole here, so the overstatement is visible in this record rather than described by it.

One rung with no ground term. Simpler, one input instead of two, and it gives field-night 0.09393. Rejected because a Scope does not choose its own ground: under ADR-0016 emission is measured from the theme substrate, so a Scope that renders its declared raised surface has already spent ground before it draws anything. A ceiling that excluded it would charge every Scope for existing. Measured, it leaves 02-one-demand--field-night — one legitimate demand, the thing the ceiling is sized to admit — at 99.1% of its budget.
Leave the calibration reading the Phase 0 scenes and treat the two failures as scene defects, with no calibration change. Defensible on the evidence available: the two scenes are within 2.4% of the ceiling, field-day is the theme with the least headroom by design, and a component that overruns its budget is exactly what the budget is for. Rejected because it cannot be tested. With the calibration reading four scenes and the judgement covering 83, "the components are too loud" and "the ceiling is calibrated on the wrong population" predict the same observation, and no measurement of the components can separate them while the ceiling still depends on four of them. Fixing the derivation first is what makes the component question answerable — and, as it happens, answers it: under a ceiling derived from the theme, both scenes pass with 13.9% and 14.9% of their budget unspent.

The first is the load-bearing case. 02-one-demand--field-night at 0.093052 against that candidate's ceiling of 0.09393 is 99.065% of budget, and that measurement is stated as part of why the candidate lost. A check that can reject a candidate is a check the outcome depended on, whichever way it came out. The second is the weaker case: its stated reason for losing is that it cannot be tested, but the paragraph closes on two scene measurements — 13.9% and 14.9% of budget unspent — offered as the answer the change makes available.

The previous pass corrected this by appending a dated Amendment to ADR-0030 and by writing an exception into the register preamble to permit it. The register's rule is that closed decisions are never edited; they are superseded. That rule is unconditional. Both the amendment and the exception are reverted, and the correction is this record.

#Decision

A ceiling's independence is a property of its inputs, not of the process that selected it. ADR-0030's adopted formula reads each theme's own ramps and role floors and reads no scene; that stands, and all four ceilings stand at interior-light 0.151339, interior-dark 0.152920, field-day 0.143198, field-night 0.128641, the values packages/budget/src/config.js carries. Candidate formulas were sanity checked against rendered scenes before one was adopted, and that check was capable of rejecting a candidate — it rejected one. A sanity check that can reject a candidate is part of the selection and is not independence. The two are recorded apart from here on: a scene may not be an *input* to a ceiling, and none is; a scene may be evidence against a *proposal*, and one was. No ceiling moves, no formula changes, no fixture is edited, and no load is re-measured by this record.

#Rejected options

Amend the accepted record in place with a dated Amendment section. It puts the correction where a reader of ADR-0030 will find it, which is its real merit: a superseding record can be missed by someone who arrives at 0030 directly, and the correction is descriptive, so nothing about the decision moves. It is also what the previous pass did. Rejected because it can only be done by relaxing the register's own rule, and that is what happened — the preamble grew an exception for descriptive corrections, written in the same pass as the first correction that needed it, by the author who needed it. "The decision did not move" is precisely the judgement the closed-record rule exists to keep out of the editing author's hands, because every in-place edit is descriptive in the eyes of the person making it. Discoverability is the one thing this option buys, and the status transition on 0030 buys it for the cost of one line, using the mechanism the register already had.

Leave the overstatement uncorrected, on the grounds that the numbers are right. Cheapest by far, and defensible on impact: no ceiling, no formula and no verdict depends on that sentence, the four numbers are derived and re-derivable from committed token output, and no reader is misled about what the engine computes. Rejected because the rejected options are the register's evidence of judgment — this register's own preamble holds that a decision without a recorded alternative was not a decision — and a record whose *Context* claims no component was measured, while its own *Rejected options* rejects a candidate on a rendered measurement, is evidence against itself. The claim that is wrong is the one about method, and method is the whole of what a reader takes from a record whose numbers they cannot re-run by eye.

Re-derive the formula so that no scene was consulted at any stage, making the original sentence true as written. The only option that delivers independence in the broad sense the sentence asserted, leaving ADR-0030's strongest claim intact rather than narrowed. Rejected because it would discard a check for the sake of a sentence. The sanity check against rendered scenes is why One rung with no ground term was caught leaving a legitimate one-demand scene at 99.065% of its budget; a derivation that was never checked against anything rendered is not more independent, only less examined. It would also be work that changes nothing — the adopted formula is the one such a re-derivation arrives at, and the ceilings it produces are the four already committed.

#Consequences

Nothing the engine computes changes. No ceiling, no load, no verdict and no receipt moves. The only files this record touches are itself, ADR-0030's status line, the two registers and STATUS.

ADR-0030 takes the one edit a closed record takes. Its status line becomes Superseded by ADR-0031, which is the transition the register's lifecycle already defines — the same edit ADR-0011, ADR-0015, ADR-0018 and ADR-0022 carry. Its body is untouched, including both sentences quoted above: the overstatement stays on the page where it was made, and this record is what a reader is sent to. The register preamble is back to its unconditional wording, and there is no amendment mechanism in this repository.

What the must-fail set cost — nothing. The previous pass audited it, and that result survives the change of vehicle. A ceiling that rises can only turn a failing scene green, so the set that must stay red was re-measured rather than assumed: 21 must-fail themed renders across seven scenes, every one re-rendered that pass, and not one verdict moved in either direction. Sixteen of the twenty-one fail on salience checks that count declared levels and read no ceiling, so they could not have moved at all; the remaining five are the two scenes that fail on emission load — 03-violations in all four themes at 0.173637 / 0.150548 / 0.183581 / 0.154922 against 0.143198 / 0.128641 / 0.152920 / 0.151339, and 06-overlay-violation--interior-light at 0.313171 against 0.151339 — and both still fail on emission under the widened ceilings. 06-overlay-violation is not outside the sweep: it is one of the 83, carries its own themed-baseline row, and was rendered with the rest. The thinnest margin is 03-violations--interior-light, over by 2.37% where it was 42.6% under ADR-0011, as ADR-0030 already named. The only two emission verdicts that changed anywhere in the 83 are the two calm field-day scenes ADR-0030 names in its *Consequences*, and the smallest remaining margin in the system is 27-checkbox-calm--field-day at 0.019886, 86.1% spent.

What this makes easier. The distinction is now available by name for the next derivation that has to defend itself: the question to ask of a proposed ceiling is what its expression reads, not what its author looked at while choosing it. ceiling-derivation.json's rendersRead field is the check that answers the first question, and it is already in the receipt.

What this makes harder. A correction now costs a record. That is the intended price, and it is why the closed-record rule is worth keeping unconditional: the cost is paid in one file and one status line, and what it buys is that no accepted record can be edited by whoever finds it inconvenient.

Which checks it touches. None. No entry in the enforcement table changes, and the full battery is re-run against this tree to establish that.