Files
hq/00-META/checks/README.md
T
jschoubben b4607dfc03 Numbers are identity; the reading order is a generated, checked index
Decided after measuring what renumbering actually costs: 96 references in code
comments across two repositories, none of which would have failed to compile.
They would have pointed at the wrong reasoning, which is worse than a broken
link because nothing reports it.

So a number identifies a record and never changes. It cannot also be a
position -- a position moves when the set changes, and an identity that moves
is not one.

The reading order moves into an index generated from each record's `topic:`.
Six topics, in the order somebody learns the system.

The index is WRITTEN rather than only generated on demand, which reverses what
this repository previously said. The reason it said otherwise is that a
hand-written index drifts -- but a reader looking at the folder on a forge sees
the folder, not a command, and the drift objection is answered by checking
rather than by refusing to write one. That is §5's own rule: a rule states how
it is checked.

Two checks, both confirmed to bite. index.py fails when the written order no
longer matches the records. records.py fails when a record has no topic or one
nobody defined -- the quiet failure being a record that vanishes from the order
rather than appearing in the wrong place.
2026-08-28 23:39:18 +02:00

2.7 KiB

Checks

python3 00-META/checks/records.py      structure: links, citations, supersession, topics
python3 00-META/checks/index.py        the reading order in 02-DECISIONS/README.md is current
python3 00-META/checks/index.py --write  regenerate it

Non-zero exit on any problem, so it can be a gate rather than a report.

Why this exists. Until now nothing in this repository was verified by anything but reading, which is how a superseded decision stayed live in the constitution for days and in 01-to-be/README.md alongside it. Both were found by a person looking. how-we-build §5 says an unenforced rule is indistinguishable from a wrong one, and costs more, because people believe it — this repository was carrying several.

Every check here failed on something real before it passed. A check that has never failed is indistinguishable from one that cannot.

Check Asserts Found
links every relative link resolves — (run ad hoc during authoring; now permanent)
rests-on decisions: and extends: name records that exist and are accepted the class behind both incidents
live-citation a governing document citing a superseded record names its replacement in the same paragraph 01-to-be/README.md citing ADR 0022 as live guidance
supersession if A says it was superseded by B, B says it supersedes A ADR 0012 never declared that it superseded 0011
numbering the number in the filename is the number in the heading —
topics every record names a topic the index knows —
(index.py) the written reading order matches what the records say —

What is deliberately not checked

  • 02-DECISIONS/ and 01-RESEARCH/ may cite superseded records freely. A decision record discusses history; research records what was observed. Flagging those would produce noise on correct documents, and a check that cries wolf gets suppressed — which costs more than not having it.
  • 03-DESIGN/00-as-is/ may rest on a superseded record. It describes what runs, and what runs was built under whatever was decided at the time (ADR 0006: as-is describing a superseded decision is exactly what as-is is for).
  • Whether a citation's prose is still true. Only whether the record it points at is live. A document can cite an accepted record and describe it wrongly, and nothing here notices.

So "governing" means 00-META/ and 03-DESIGN/01-to-be/ — the documents that tell somebody what to do.

Adding a check

State what incident it would have caught, and make it fail before you make it pass. A check whose failure has never been observed is a guess about its own correctness.