Skip to contentWolf-Rayet

Decision records

ADR-0069 A countdown reports a prediction, and its level is the only one this system computes

Accepted2026-09-05Phase 4, reopened

#Context

ADR-0021's section F is this system's own set — the components that exist because Carbon is built for applications and this is built for supervision. sla-countdown is the row that section describes most sharply, and it describes a problem rather than a component:

the only component in the system whose level rises with no input changing. Everything else declares a level about a state; a countdown declares one about elapsed time, and it escalates on its own. That makes it the first component that can breach the View's demand cap without anyone rendering anything — two countdowns approaching breach both want Demanded — so it needs an arbitration rule of its own and cannot simply be built from the indicator's shape.

That is correct about the problem and the roster's own answer to it — legal levels 1 to 4 — is what creates it.

#Decision: refuse the premise rather than arbitrate

A countdown reports time remaining, which is a prediction. §2's Demanded rung is the View's ration for what is happening. The two are different claims, and the ration belongs to the second.

When the deadline passes, what exists is a breach — a condition — and conditions are alert's. Reporting one fact with two components and two allocations is the screen ADR-0055 refuses: *"two components saying one thing with two allocations is a screen that can disagree with itself about how loud the same fact is."*

So the ceiling is Directed, the roster's row is corrected from "1 to 4" to "1 to 3", and section F's arbitration problem dissolves: two countdowns cannot breach a cap neither of them can reach. No new arbitration rule is needed, because the thing that needed arbitrating was a rung this component should never have had.

This is ADR-0050's move, third instance. There, the roster said acknowledge was a component and the answer was that it was a rule. Here the roster says a countdown demands and the answer is that it predicts.

#The level is computed, and that is the component

There is no level prop. It is the only component in the set where that is true because the rung is *derived* rather than because there is only one.

slaCountdownLevel(spent) bands the fraction of the budget already used by the count of legal rungs — three rungs, three bands — so no threshold in the file is a number anyone picked, and a renumbered ladder re-bands itself instead of disagreeing with three constants.

The reason the caller may not pass a rung is the whole point: a countdown whose caller chose the level could be loud early, and being loud early about time is the one thing a countdown must not do. A screen that says *urgent* at 20% of budget spent teaches its reader to ignore it by 80%.

ADR-0044's floor is applied where the rung is computed, which no other component has had to do. Every component carrying an adverse variant refuses level={1} at the call site; there is no level here to refuse, so slaCountdownRung floors overdue at Marked however little of its budget it has overrun.

#And it takes its remaining time as data, which the engine required

Nothing in this component calls Date.now(). It receives spent as a number and its words as strings.

That is not tidiness. REPRODUCIBILITY_TOLERANCE is 0, and the engine renders every scene twice and asserts exact equality — *"anything else is a bug in the engine or a non-determinism in the renderer, and either is worth failing a build over."* A component that read the clock would render two different frames from one scene and fail the build between them.

The engine's determinism requirement is what makes this component pure, and it is worth stating because the requirement was not written with a clock in mind. A constraint that turns out to decide a design it was not written for is a constraint doing more than its author asked of it.

The consequence for a product is real and is the right one: the clock lives where the data lives, and the component draws what it is told. A countdown that ticks in the browser is a product concern, and every render of it is a frame the engine could measure.

#Nothing ticks

§2 grants sustained motion at level 4 alone and this ceiling is Directed, so a countdown cannot move continuously — the state is unrepresentable rather than declined.

It is worth naming because a countdown is the one component a reader would expect to tick, and ADR-0024 refused a spinner for the neighbouring reason: motion carrying no information is emission spent on decoration, and a clock that ticks tells a reader nothing the number does not.

#Rejected options

Build it at 1 to 4 as the roster says, and add an arbitration rule. What section F asks for. The rule would have to rank countdowns against each other — the nearest breach takes the ration — which is button-group's grant applied to time, and it would need an Arbiter to hold the set. Rejected because it solves a problem that should not exist: the ration is for conditions, and ranking predictions against each other to decide which one gets to interrupt an operator is a mechanism for interrupting an operator about something that has not happened.

Let the caller pass the level. Every other component works this way and it would have made this one unremarkable. Rejected because the caller is the product, the product wants attention, and a component whose loudness is a caller's choice has no defence against a caller who wants all of it. The derivation is the defence.

Take a deadline and compute the remaining time. The obvious API, and it is what a product wants to pass. Refused by the engine: two renders of one scene would differ, and REPRODUCIBILITY_TOLERANCE is 0. The fraction is the honest boundary — it is the one number that is true at the moment of render and stays true in the receipt.

Give overdue the demand rung, since a missed SLA is real. The strongest counter-argument: a breached response budget in a supervision system matters, and this record makes it quiet. Rejected because the breach is a condition and the system already has components for conditions — and because a screen where every overdue clock demands is a screen with no ration left for the machine that is actually on fire. The countdown says the budget is gone; the alert says what that means.

#Consequences

Roster 50, built 32 → 33. Section F has three rows left, and the roster's level column is corrected on one row for the second time (shell-header's was corrected in place by ADR-0046; this is the second).

The first component whose serialized level no caller chose. The react discipline table has no column for that and does not need one — the per-instance check reads the rung the component computed, exactly as it reads one a caller passed.

Scene 59 records one component at three levels with no level written in its generator, which is the derivation demonstrated rather than described.

linux-x64 is short by one unthemed scene and three themed ones, twelve Scope values.

#Measured

  • sla-countdown: 22 component tier tokens, 40 APCA floor checks all met, worst |Lc| 16.23 against an interior-light Ambient floor of 15.
  • The derivation in scene 59: fractions 0.15, 0.55, 1.1 → levels 1, 2, 3, with no level in the generator — *darwin-arm64, this pass*.
  • Scene 59: 1 demand of cap 1, and it is an Alert; three Scopes, worst emission 0.059326 against a field-night ceiling of 0.128641.
  • REPRODUCIBILITY_TOLERANCE is 0 — the constraint that made the component pure.
  • Themed set 173 → 176 fixtures, 57 scenes, joined both ways by themed:check.
  • Roster 50, built 32 → 33. pnpm battery — the verdict this pass is measured by.