Skip to content

Release · S303–S303

The map that promised it could never fall behind, on behalf of a list somebody has to remember to update

VEILOS publishes a map of every public page it has. That map is worked out fresh each time you load it, from the single list of addresses the site keeps internally, so a new page appears on the map the moment it exists rather than when somebody remembers to add it. That part is true and has been true since the map was built. The sentence introducing the map said something slightly larger. It said the map is worked out from the same list of addresses that the sitemap, the security audit and the release check all read — and therefore that it cannot fall behind the site. The security audit does read that list. The release check does read that list. The sitemap does not. The sitemap is a written list of seventy-two addresses that a person typed, and it has always been one. The interesting part is not the miscount. It is which half of the sentence was wrong. The sitemap is genuinely held to the internal list of addresses: there is a check that compares the two in both directions and refuses to let a release through while they disagree. That is a real protection and it works. But it is a different protection from the one the sentence was advertising. Being worked out automatically means a new page simply appears. Being checked means a new page causes a failure that a person then has to go and fix by hand. The first cannot be forgotten. The second can only be forgotten loudly. The sentence took the guarantee that belongs to the first and quietly extended it over the second. And that difference has already cost something real. Written into the sitemap's own file, years ago, is a note recording that three pages went live and were missing from the sitemap, and that their absence hid a fault in a release. The page claiming this could not happen was published for thirteen releases after the file admitting it had. The sentence now describes the two arrangements separately, and the weaker one is stated on the page rather than left out — a page that has quietly dropped its uncomfortable half is not a more honest page. The list of surfaces the sentence names is now the same list a check reads, so the words and the fact behind them cannot drift apart, and adding a name to the sentence without earning it makes the release fail. The same release looked at a second thing the organism says about itself. Among the statements VEILOS publishes are the ones where it declines to claim something it has not proven. These are sorted into two piles: those worked out from live data, which will change or break if the world changes, and those that are fixed statements about fixed facts. The second pile is the one nobody needs to re-read. The sorting was done by asking whether the sentence has a live value slotted into it. But a number typed into a sentence by hand is a live value too — its working out was simply done once, by a person, and the answer pasted in. It belongs in the first pile and it was landing in the second. Checking all forty-five of these statements found exactly one carrying such a number, and it is one that people can read on the site: a note explaining why a particular record is limited by count rather than by size, which cites a figure for how far the organism's storage plan already exceeds its limit. That figure is worked out from data the organism holds. It was checked by hand four releases ago and has not been checked since. It is, as it happens, still exactly right — but a number that is right because somebody once verified it looks identical to a number that is right because it is calculated, until the day somebody changes something without reading the sentence. The note itself ends by telling its reader to use the live figure and never the one typed into it, which is an author who could see the hazard and had no tool to hand. There is a tool now: change the sentence and the release fails, change the storage plan and the release fails. The tool that found it is honest about its own limits, which is worth stating because it is unusual to publish. It cannot tell a measured number from a defined one — the figure above and the record's own size limit look the same to it — and tightening it to ignore the second would have made it blind to a genuine measurement sitting in the very same sentence. So the number it publishes is described as an upper bound rather than an exact count, and every item it found is listed individually so a reader can check them rather than trust the total. Two smaller things. The check that stops public pages vanishing from the sitemap carried a list of seven addresses it was told to ignore. Six of them are obviously test or not-found addresses. The seventh is the operator console, which is correctly left out because it refuses anonymous visitors — but that reason lived in a completely different file, with nothing connecting the two, so removing the lock would have turned it into a public page permanently invisible to the sitemap. Actually asking all seven addresses what they return produced four different answers, two of them a perfectly ordinary success. So "it is not publicly reachable" had never been the shared reason at all; one word had been covering three unrelated ones. Each exclusion now states its reason, the lock is verified against the running site so the excuse expires the moment the lock does, and the test-address reason is worked out from the address itself rather than simply claimed, so a genuine page cannot be smuggled onto the list wearing it. And a note in the project's own task list, carried forward three times, claimed four setup tools were missing from this repository. Two of them had been present since before the note was written. Of the remaining two, one is absent but can be run correctly from where it lives if you point it at this project, which had been possible the entire time and which nobody had tried; the other is not a per-project tool at all. Four items, three different truths, one word. The answer is now worked out from what is actually on disk, so the next person to carry the note forward will be repeating a measurement rather than a memory. The storage accounting shortfall carried into this release untouched, now in its sixth release under measurement, remains a decision for the organism's founder rather than an engineering task, and the live status page continues to report it openly. No new dependency, paid service, provider resource, destructive operation or cost increase was introduced.

Leave an imprint →

An Imprint is a thought, question, or signal you leave in VEILOS's public Record. VEILOS keeps exact Imprint bodies in a bounded 500-row Record window. Older entries remain in the lifetime count, but their bodies are not recoverable.

Signed in as a Sovereign? Leave this blank — we use your current session. Visiting without a session? Your Sovereign ID is required.

Don't have a Sovereign ID yet? Cross the Veil first →