Measurement lives in Rust, judgment in Haskell, and one versioned wire connects them: the boundary set by ADR-002 and kept load-bearing by ADR-008. Parsing, extraction and indexing stop before policy; score, ratchet and authorization stay in the core.
GHC 9.14.1NDJSON · proto 7.10.0 · SemVer negotiationcli/, core/, gui/, plugin/,
contracts/, or the release workflows. Open the full-size SVG.h = (h - t[i-k]*top)*BASE + t[i], over FNV-1a leaf hashes.file:line it points at.release.yml hashes draft assets, then committed pins bind those bytes.On every push, ci.yml runs seven product legs over this repository: scan, dedup ratchet, check at floor 911, deadcode, docdup, erase and rules.
ADR-006 freezes per-file ceilings and discrete violation sets in ce-baseline.json: growth needs a named re-establish, and ordinary cleanup tightens the bank.
ce.toml's [[rules.class]] gives one glob set its own size and complexity lines and ratchet allowance (at most 64 classes, first declared match wins), read alike by the score, the ce scan ladder and the guard hook; only the class index, its knobs and the knobsDigest of the whole parsed config cross the wire, never names or globs.
docs_gate.rs generates the CLI and configuration references from the binary; citation, navigation and constant tests check the methodology, and benchmark surfaces are byte-gated from one JSON contract.
classifier: 0/600 flagged (gate <= 1%); write probe: 0/630 false positives. Every other class stays observe. Each promotion is recorded in the CHANGELOG ledger.
erase/gather.rs assembles facts and CE.Erase authorizes only rows that satisfy the safety predicate; apply verifies every target hash first, then re-runs the source families, and a surviving verdict fails loudly. No LLM writes a replacement.
release.yml hashes the draft assets and committed pins bind those bytes; the tag job downloads the same assets, checks CI and every pin, refuses an unexpected asset, and publishes without rebuilding; SHA256SUMS covers the set for offline checking. The same pins project the Homebrew formula and the winget manifests, and verify-publish fast-forwards the release branch the plugin marketplace tracks. Code signing is out of scope by design.
The nineteen-booklet methodology links every formula to its implementing file:line; docs_citations.rs checks the ledger, docs_nav.rs the booklet set and navigation.
The core alone computes score and ratchet verdicts, authorizes erase rows and decides cycle-axis membership; property batteries perturb those decisions and compare small cases with reference implementations.
Trace the boundary in ADR-002 and ADR-008, the wire in contracts/VERSIONING.md, and the verdict formulas in the methodology index.