Skip to content
Skip to main content
Novel Systems home
Decision log
D-042August 4, 2026

A published figure has one owner, and a script enforces it

Decided

Every operational figure that appears on more than one surface is declared in exactly one module and interpolated everywhere else, and scripts/check-claim-consistency.mjs fails the build when one is typed as a literal somewhere it is not owned. Eight rules, one per contradiction that actually shipped. It runs in prebuild and verify.

Alternative: correct the sixteen strings and move on. This was the obvious option and it is what the memo asked for.

Why not: the sixteen entries in FLAGGED-CLAIMS.md Part 4 were not sixteen mistakes. They were one mistake made sixteen times — a figure typed by hand in a second place, which then aged independently of the first — and every one of them had been written by somebody who believed the number they were typing. Nobody copies a stale figure on purpose. Correcting the strings fixes the sixteen and does nothing about the seventeenth, and the seventeenth is written the same week by the same well-intentioned person updating a page.

The uncomfortable part is the arithmetic. A single-owner constant is only worth anything if the second copy is impossible rather than discouraged, and nothing in review reliably catches "this number is right today". The homepage RPO was wrong by a factor of two hundred and forty and survived every read of that file until it was diffed against another page.

Two design choices worth defending:

*It strips comments before matching.* The doc comments added while closing these entries quote the retired wording deliberately — a constant that says "this used to claim X, and X was false" is worth more than one that says nothing, because it tells the next reader why they should not put X back. A checker that could not distinguish a quotation from an assertion would fire on every explanation of its own reason for existing, and the cheapest way to quiet it would be to delete the explanations. That is the same failure mode as D-037: a control whose easiest resolution is the unsafe one is worse than no control.

*Each rule names the constant that owns its figure and aborts if that declaration is gone.* A rule pointing at a renamed constant still passes. It passes because it has nothing to compare against, which is indistinguishable from passing because the code is correct — and the pipeline stays green either way. Blind checks are more dangerous than absent ones, because an absent check does not tell you anything reassuring.

Verification: each of the eight rules was tested by writing the original shipped wording into a scratch module and confirming that rule fails. A guard that has never been observed to fail is a guard nobody has tested.

What would make this wrong: if the rules start firing on legitimate copy often enough that people reach for the allow list as a reflex, the guard has become a tax rather than a control and the patterns are too broad. The correct response is to narrow the pattern to the specific claim, not to widen the exemptions — a rule loosened until it stops firing catches nothing, but still looks like coverage.