Skip to contentWolf-Rayet

Decision records

ADR-0036 The dominance margin comes from the ladder, and PLATFORM_TOLERANCE keeps only the use that is about rasterisers

Accepted2026-09-02Phase 4, reopened

#Context

ADR-0032 took the themed baseline off PLATFORM_TOLERANCE and ADR-0033 took the unthemed path off it too. Both recorded that the constant survived anyway, because other decisions were denominated in it. What survived was four spenders across three decisions: ADR-0005's salience dominance margin and the undecided warning's spread, ADR-0016's substrate-floor check, and ADR-0030's bound on config.js agreeing with derive-ceiling.js.

ADR-0033 also left an open item, and it is the thing that forces this decision. The constant is 1.0e-3. The worst measured cross-platform drift in the system is 1.064e-3 — 11-alert-calm--field-day.html #scope-notices, the only Scope in the set carrying three full alert bodies. Recomputed from the two committed themed records at this ADR's HEAD: 246 Scope values compared between darwin-arm64 and linux-x64, 245 of them differing, worst 1.064e-3. On the unthemed set, 72 of 72 differ, worst 2.990e-4.

So ADR-0005's sentence — the margin "is precisely what the tolerance was measured to bound" — is false at the edge. The measurement escaped the bound.

The tempting reading is that a number needs fixing. It does not. A constant that four different checks spend is a constant nobody has asked a question of, and the drift finding is only the first place the overloading became visible. The right move is to ask each spender what question it is actually asking, and to notice that they do not all ask the same one. Two of them are about the design language. One of them is about arithmetic precision. Exactly one of them is about what two rasterisers do.

The obstacle in ADR-0005 was real at the time. It rejected a density margin because "comparing densities needs a margin in units of density, which PLATFORM_TOLERANCE is not. That margin would be a new constant with no derivation." That was true in Phase 3. It stopped being true in ADR-0030, which derived step — the mean adjacent |ΔL| of a theme's neutral ramp over its headroom — as half of the emission ceiling. A margin in units of density, derived from the ramps, already exists in this system. It has simply never been spent on this question.

#Decision

The salience dominance margin is one rung of the theme's own lightness ladder, spread over the area the claim is made about. A share is a normalised lightness excess summed over the pixels an element owns and divided by the Scope's governed count, so the ladder's rung — a lightness — becomes commensurable with a share only once it is given an area. The area is the leader's own, because the assertion is that the leader stands a level above the runner-up and one level is one rung across the leader's pixels:

required = ladderStep(theme) × (governedPixels(leader) / governed(scope))
dominant = margin > required

ladderStep is ADR-0030's step, committed to config.js as LADDER_STEPS and recomputed from the generated ramps by derive-ceiling.js, which fails if the literals have drifted. It is not a new constant; it is a number the system already derives, now spent twice. The themeless Phase 0 fixtures take LEGACY_LADDER_STEP, the smallest rung the generated set contains, and go when those fixtures go.

The undecided warning is that same test negated. Two Directed elements are measurably undecided when neither leads the other by a rung. "One wins" and "neither wins" are one question, and answering them with two different margins would let a Scope be both at once.

The bound on a committed derived value agreeing with its own derivation is one unit in the last place of the precision it is committed at — DERIVATION_BOUND = 1e-6, three orders tighter than what it replaces. derive-ceiling.js reads committed hex and does arithmetic. No pixel is rasterised anywhere in it, so a rasterisation floor was standing over a computation it had never met. What is left to disagree about across machines is libm's cube root inside oklabL8, which quantisation to six decimals already hides except where a value lands on a rounding boundary — one ULP, which is exactly what this admits. Measured at this HEAD, all four ceilings and all four rungs agree with their derivations at Δ 0.00e+0.

The substrate-floor check keeps PLATFORM_TOLERANCE, on the merits. It compares a ground the renderer composited against a ground the declaration predicts, and both sides come out of the rasteriser. "How far apart may two composited lightnesses be before the declaration is a lie" is precisely a question about what two renderers do, which is the only question this constant was ever measured to answer. The ladder has nothing to say about it: a ground is not a rung, and no amount of derivation from the ramps would tell you how much two composites may disagree. This use is kept because it is right, not because it was there.

#What survives of ADR-0005

ADR-0005 is reopened on one clause and stands on the rest. It is not superseded.

Survives, untouched:

  • Directed is a relative property, not an absolute share. The whole shape of the rule — plurality among non-Demanded elements, plus a margin — is unchanged.
  • The inversion clause. Under-declaration is dominance and declared below Directed and out-emitting something declared above. This is still what makes the rule mean anything, and this ADR does not touch it.
  • Zero level-3 elements remains valid.
  • The ground exclusion, and the rule that ground means encloses *every* other member.
  • Undecided stays a warning, not a failure, for the reason Playbook §5 gives.
  • The refusal that generated the original decision: no threshold this system carries may be picked by taste. This ADR is that refusal applied to ADR-0005's own answer.

Reopened: the identity of the margin, and one sentence of reasoning. ADR-0005 said the margin "is the measurement's own noise floor and carries no invented constant," and that a dominance the system asserts "is one a second renderer would agree with." The first half was a good instinct pointed at the wrong quantity — reproducibility is not significance. Two elements one part in a thousand apart are on the same rung of every theme in this system, and crowning one of them ratified a difference the design language cannot name. The second half is now delivered by ADR-0032 and ADR-0033 in the place it belongs, the baseline gate, at exact equality.

Also reopened: ADR-0005's closing claim that a density margin "would be a new constant with no derivation." ADR-0030 supplies the derivation, so the claim no longer holds. This ADR does not close p5-underdeclare — that still needs the contest itself moved into density terms, which is a larger change than replacing a margin, and it stays the successor decision.

#Rejected options

Leave the constant shared. Merit: one number in one place, no receipt churn, and the sharing was deliberate rather than accidental — ADR-0005 chose it precisely so the margin would carry no invented constant, which was a real principle honestly applied. It also has the merit of being the option that requires believing nothing new. It lost to its own arithmetic. The 1.064e-3 finding means the shared justification is already false at the edge, so "leave it shared" is not a stable position, only a deferred one. And the deeper objection stands even where the number holds: four checks spending one constant is not economy if they are asking different questions, because then the constant is right for at most one of them and right for the others only by coincidence. That is not a shared constant. It is an overloaded one, and the coincidence is what broke.

Raise it to exceed measured drift. Merit: genuinely the smallest possible change — one line — and it restores ADR-0005's sentence literally rather than reinterpreting it, which is an honest thing to want. Everything goes green immediately. It lost for the reason ADR-0011, ADR-0030 and ADR-0032 each give in turn: a bound raised to admit the value that broke it is not a bound, it is a transcript of the worst thing measured so far. It also lost on a point specific to this case. Raising the constant would itself move salience verdicts, so it is not the conservative option it appears to be — it pays a behavioural cost and buys only a number. And it would leave the category error untouched: the dominance margin would still be answering a question about rasterisers when the question asked is about hierarchy.

Split it into three unrelated constants with no derivation behind any of them. Merit: it is honest about the thing this ADR is also claiming — that the uses differ and should not share a number — and it delivers that immediately, with no theory required and each use sized to its own evidence. It is the cheapest way to stop the overloading. It lost because it is the option ADR-0005 already rejected twice, once as "a fixed percentage share" and once as "a separate tunable threshold token per theme," and it loses to the same objection both times: it multiplies unprincipled constants, and it hands every team a knob to turn when a check is inconvenient. Three knobs instead of one is worse, not better. The specific reason it lost here is that the premise is wrong about two of the three: a derivation was available for the dominance margin and for the derivation bound, and taking numbers instead of those derivations would pay the entire cost of the split — three constants to defend, three to keep honest — for none of its benefit. Splitting is right. Splitting *without* derivation was never the only way to split.

#Consequences

No emission number moves. The change reads the attribution the engine already computes and adds a per-owner governed-pixel tally beside the per-owner excess it already keeps. Both baselines match at REPRODUCIBILITY_TOLERANCE — exact — on darwin-arm64 after the change, which is the check that proves it.

Sixty-four Scope-level salience verdicts move. All of them are the dominant flag; none of them changes a scene's pass/fail, and none changes an underDeclared finding. They are named below rather than counted, and no scene was adjusted to keep an old verdict.

Unthemed set — thirteen, twelve losing dominance and one gaining it:

  • 09-indicator-calm #scope-queue, 12-mixed-two-demands #scope-notices, 13-meter-calm #scope-telemetry, 17-input-calm #scope-account, 17-input-calm #scope-validation, 22-tag-calm #scope-telemetry, 23-inline-loading-calm #scope-telemetry, 24-loading-calm #scope-route, 25-tooltip-calm #scope-telemetry, 26-button-calm #scope-telemetry, 27-checkbox-calm #scope-telemetry, 28-radio-button-calm #scope-telemetry — dominant true → false.
  • 21-proof-supervisor-queue #scope-queue — dominant false → true, on a margin of 2.17e-4 against a new requirement of 1.75e-4.

That last one is the finding worth reading twice. The new rule is not uniformly looser. #scope-queue in the proof fixture has a leader small enough that one rung across its pixels is worth less than 1.0e-3, so a lead the old bound dismissed as noise is a lead the ladder can name. The margin is scale-free now: it tightens for small elements and loosens for large ones, which is exactly the area-weighting ADR-0005 identified as its own honest boundary and could not then act on.

Themed set — forty-nine, all losing dominance:

  • 05-overlay #scope-confirm in all four themes, and 06-overlay-violation #scope-confirm in interior-light.
  • 09-indicator-calm #scope-queue in interior-dark and interior-light.
  • 11-alert-calm #scope-notices in interior-light.
  • 12-mixed-two-demands #scope-notices in field-day, interior-dark, interior-light.
  • 13-meter-calm, 22-tag-calm, 23-inline-loading-calm, 25-tooltip-calm, 26-button-calm, 27-checkbox-calm, 28-radio-button-calm, each #scope-telemetry, each in field-day, interior-dark and interior-light — twenty-one in all.
  • 14-queue-calm #scope-instruments in field-day, interior-dark, interior-light, and 14-queue-calm #scope-work in interior-light.
  • 17-input-calm #scope-account and #scope-validation, each in field-day, interior-dark, interior-light — six.
  • 18-navigation-calm and 19-navigation-two-demands, each #scope-instruments, each in field-day and interior-dark — four.
  • 24-loading-calm #scope-route in field-day, interior-dark, interior-light.

Gameability probes — two: p2a-dilution-tight and p2b-dilution-padded, both #scope-dilution, dominant true → false.

One new warning, and it is a finding rather than a regression. 17-input-calm #scope-validation now reports two measurably undecided Directed elements — #field-seats and #field-org — in the unthemed scene and in field-day, interior-dark and interior-light. Under the old bound their shares differed by more than 1.0e-3 and one was crowned. Under the ladder they are on the same rung, which is what the scene actually looks like: two form fields of equal weight, neither pointed at. The scene is named here rather than edited to restore the old verdict.

The acceptance tests hold. 07-under-declared still fails on salience — share and nothing else, in the unthemed scene and in all four themes, on #queue-03. 08-undecided still passes carrying its warning, in the unthemed scene and all four themes. p7-smuggle is still caught on the inversion. p5-underdeclare still passes, still the standing record of what this rule cannot see.

The two salience messages in report.js are rewritten, and only in prose. They told the reader the margin was "the engine's cross-platform drift tolerance, so a dominance claimed here is one another renderer would agree with." Both halves are now false, and a receipt is evidence — a message that explains a verdict by the wrong rule is worse than one that explains nothing. They now name the rung and print it beside the required margin. No verdict is computed in that file.

Receipts gain three fields and one changes meaning. salience.share.tolerance is now the per-Scope required margin rather than a global constant, and ladderStep, ladderSource and leaderGovernedPixels are added beside it, because a receipt reporting a verdict against a margin that varies per Scope without reporting the margin would be unreadable. The Scope emission values the baselines gate on are untouched.

derive-ceiling.js closes a second loop. It already recomputed the four ceilings against config.js; it now recomputes the four ladder rungs against LADDER_STEPS the same way and at the same bound. LADDER_STEPS is therefore defended rather than asserted — an undefended literal there would have been precisely the unprincipled constant ADR-0005 refused.

PLATFORM_TOLERANCE keeps one spender and its name becomes accurate. It was named for a comparison the system stopped performing; it now names the only comparison still asking its question. The open item from ADR-0033 narrows rather than closes: 1.064e-3 exceeds 1.0e-3, but that is drift in area-weighted emission load, which is not the quantity the substrate check compares, and nobody has measured cross-platform drift in a composited ground. The measurement that would settle it has not been taken. It stays open, now scoped to one check instead of four.