Skip to contentWolf-Rayet

Decision records

ADR-0033 The unthemed path comes under ADR-0032 before it comes due, and PLATFORM_TOLERANCE survives as a noise floor that gates nothing

Accepted2026-09-02Phase 4, reopened

#Context

ADR-0032 recorded per-platform baselines for the themed set and left the unthemed run() path alone, explicitly: "ADR-0004's bound keeps governing the unthemed run() path against baseline.json, which has not come due." config.js said the same thing in the same words — "Its worst is well inside the bound; it has not come due. When it does, the answer is ADR-0032's, applied there."

That was a decision to wait. This record is about what waiting would have been waiting *for*.

The finding is already in, and it is stronger here than it was there. Measured this pass between the two platforms the repository actually runs on, at the same commit:

themed setunthemed set
Scope values24672
differing across platforms24572
identical1, by coincidence0
worst \Δ\1.064e-32.990e-4
as a share of the 1.0e-3 bound106% — it failed29.9% — it has not

The themed set had one Scope that matched across platforms and it matched by accident. The unthemed set has none. Every single value the bound governs is a value the two platforms disagree about. What the bound asked was never "do these agree" — it was "does a disagreement present in all 72 happen to stay under 1.0e-3", and the answer being yes so far is not a property of the design system. It is a property of two font rasterisers.

The worst is 17-input-calm #scope-validation at 2.990e-4. The per-scene table has the same shape ADR-0004 measured at Phase 0 and for the same reason: dark-substrate scenes at 2.2e-5, light-substrate and light-heavy component scenes an order of magnitude above them, 04-calm-light at 2.210e-4 and the input scene's validation Scope above it. Nothing here is new physics. What is new is that the whole set is now known to differ, not just the scenes anyone had looked at.

Same-platform is exact, and both platforms were measured.

  • darwin-arm64, this machine against its own committed record, this pass: 72 of 72 identical, worst delta 0. Every regenerated receipt came back byte-identical to the committed one.
  • linux-x64, run 33534569376 at 57a64b4 against run 33533805708 at 1f2f12e — two independent runner VMs, eight minutes apart, on two commits whose difference is confined to .github/workflows/ and docs/STATUS.md and therefore touches no fixture, no engine and no token: 72 of 72 identical, worst delta exactly 0.

Waiting has a shape, and it is the shape this repository has already been burned by. The value that "comes due" is a value that has crossed a bound, and crossing that bound turns a job red for a quantity that has nothing to do with the design system — which is exactly the failure ADR-0032 was written to stop treating as a design finding. Holding the unthemed path back means holding open one path on which the next prose-heavy component scene produces a red build that says "regression" and means "FreeType".

#Decision

baseline.json holds one record per platform, keyed by ${process.platform}-${process.arch}, each carrying its own node, playwright, chromium and recordedBy alongside its scenes — the same shape themed-baseline.json has carried since ADR-0032. A run compares against the record for the platform doing the measuring and against nothing else, at REPRODUCIBILITY_TOLERANCE: exact equality. A platform with no entry fails and names itself rather than measuring itself and passing. --write-baseline rewrites only the running platform's entry and prints which other platforms it carried through untouched; --fill-baseline is additive within the running platform's entry and refuses to run at all if that platform has no entry yet.

Two records are committed with this decision. darwin-arm64 is carried through byte-identical from the single record that preceded it — no value re-measured, and the engine run this pass confirms all 72 unchanged. linux-x64 is the budget-receipts artifact of run 33534569376, recorded by CI on the platform it describes, at commit 57a64b4 — the commit this record is committed against, so unlike ADR-0032's linux record there is no "differs only in docs/" caveat to make: it measures these fixture bytes, at this commit, with nothing intervening.

chromium is null in both records, and the field is not filled in with a plausible number. Neither writing run named the browser build: the themed path has recorded browser.version() since ADR-0032, and run() only starts doing so with this decision. The next record written on either platform will carry it. A recorded field that was inferred rather than observed is the thing baselines exist to prevent.

#What did not transfer, and what it costs

ADR-0032's reasoning transfers whole. One of its *consequences* does not.

ADR-0032 wrote that PLATFORM_TOLERANCE "no longer governs the themed path," which left the unthemed path as the thing keeping the constant alive. Take that away and the expectation is that the constant dies with it. It does not, and it must not. Two other decisions are denominated in it:

  • ADR-0005 sets the salience share dominance margin at PLATFORM_TOLERANCE in engine.js: a level-3 element is "clearly dominant" only if it leads the runner-up by more than this. That was a deliberate refusal to invent a constant — the margin is the measurement's own noise floor, so "a dominance this system asserts is one a second renderer would agree with." The same number sets the undecided warning's spread and the substrate-mismatch check.
  • ADR-0030 bounds config.js's agreement with derive-ceiling.js at it, where the bound costs nothing and the fault it catches is orders of magnitude larger.

So the constant now gates no baseline comparison anywhere in the system while remaining load-bearing in two places that have nothing to do with baselines. Its name describes a comparison that no longer happens. It is documented in place rather than renamed, because the identifier is quoted in ADR-0005's text and serialised into every receipt as tolerance, and renaming it would move committed receipt bytes to make a comment read better.

And one thing it is now known not to bound. ADR-0005 chose this number because it bounded the cross-platform drift. The worst cross-platform drift now measured in the system is 1.064e-3 — the themed 11-alert-calm #scope-notices value that forced ADR-0032 — which is *above* it. ADR-0005's margin therefore no longer strictly bounds the quantity it was chosen to bound, on the themed set. This is recorded rather than absorbed: raising the constant to fit would be widening a bound to admit a measurement, which ADR-0011, ADR-0030 and ADR-0032 each refuse in turn, and it would move salience verdicts on scenes nobody has looked at. It is a standing open item for whoever reopens ADR-0005, not a defect to patch under this one.

#Rejected options

Leave it. It has not come due. The option ADR-0032 chose, and it has real merit: nothing is failing, no evidence is spent, and a decision taken in response to a failure is better grounded than one taken in anticipation of it. It lost because the anticipation is not speculative — 72 of 72 values differ *today*, measured, and the only thing not yet known is which scene crosses first. Waiting buys nothing and costs a future red build that misnames its own cause. It also lost on a smaller point: leaving one path on a retired comparison means the repository holds two different answers to the same question, and the next reader has to work out which one is the current thinking.

Widen PLATFORM_TOLERANCE so the unthemed path never comes due. Rejected for the reason ADR-0032 rejected it for the themed path, and here it is worse: there is no failing value to widen *for*, so the widening would be pure anticipation of a number nobody has measured yet. A bound set to clear a value that does not exist is not a bound.

Take the record from a fresh CI run rather than from run 33534569376's artifact. The cleaner-feeling option: dispatch a run, take its artifact, commit it. It lost because it buys nothing. 33534569376 ran at 57a64b4, which is this commit's parent and the tree this record is committed against; its fixture and engine bytes are the ones being recorded. A fresh run would produce the same 72 numbers — which is precisely what the comparison against 33533805708 already demonstrates, on two independent VMs, at delta 0. Spending a run to re-derive a number two runs already agree on is ceremony.

Write the linux-x64 record from this machine. The one option that is available in one command and produces a file with the right shape. It is rejected absolutely and it is the rule this ADR carries over: a record written by a platform that did not do the measuring is a fabrication with a platform name on it. darwin-arm64 cannot measure what FreeType draws.

Normalise the rasteriser instead. Left where ADR-0032 left it: the only option that attacks the cause, still open as the thing to build if a portable per-Scope number is ever wanted for its own sake, still not worth shipping and pinning a font stack to buy a claim that is narrower than it looks.

#Consequences

What the unthemed suite now claims. *This platform measures what this platform recorded, exactly.* Stronger than what it replaced — 0 rather than 1.0e-3 — and it is the claim that catches regressions, because a change to a scene, a token, a component or the engine moves a number on the machine measuring it.

What is lost, plainly. There is no longer a committed number that is *the* emission load of an unthemed Scope. There are two, and all 72 differ. baseline.json was the file ADR-0004's cross-platform evidence lived in, and reading a value out of it is now a claim about a platform. ADR-0004's Measured-properties table keeps its figures as the historical measurement they were.

Both baselines are now a maintenance obligation. Adding a scene to SCENES means recording it on every platform that has an entry; a scene added on darwin alone fails on linux naming itself. That was already true of the themed set and is now true of both.

The exact gate is deliberate on this path too. A runner image that changes its font stack under an unchanged platform name turns the fixtures job red. That is the correct outcome, it is the class of change a baseline exists to make visible, and the remedy is a deliberate re-record reviewed in the diff.