Red5Sorcery / Data Sculptor

WASM-002 adversarial QA review of Revision BL

Pass 1 — independent requirement review, Wednesday 23 September 2026. Findings only; no requirement text has been changed.

1. Review identity

Contract under reviewRed5Sorcery_Data_Sculptor_WASM002_Adversarial_QA_PRD_RevBL_2026-09-22.html
SHA-256 (verified)828C6A81B2C0A8B97546F728628059C53CC61256FAB23B142E452A8E566E025F — matches the supplied sidecar; 626,877 bytes
Requirements in cut384, all SCOPE WASM-002, all UNDER REVIEW (independently recounted)
Source masterProduct Backlog PRD Revision BL, SHA-256 A5D5D8D0…6408813E6 (not supplied; not reviewed)
Non-normative inputData_Sculptor_WASM002_Front_End_Prototype.html, SHA-256 A6EC724DEDC6CCCF08F5EDC4A818EEF361A419DEBAF4A17E0D548636FE8139A6 — used only for Appendix A
ReviewerClaude, independent adversarial QA (no implementation seen)
Record disciplineAppend-only. Corrections to this pass will be filed as addenda with the original text preserved.

2. Method and conventions

The contract was read end to end, then attacked one lifecycle at a time: Suitcase gate, WKO save, Run, Stage 1, Stage 2, publication, inheritance, alias maintenance, recovery, conversion, Help/HLP, and UI. Each candidate finding was checked against the full text of all 384 retained requirements before it was kept. Where a finding depends on the absence of a rule, that absence was confirmed by full-text search of the cut.

E marks evidence: a direct reading of cited requirement text, or a search result. I marks interpretation, which is contestable. Interpretations about browser or library behavior are flagged as such and should be verified on the target platform before being relied on.

Severity uses the project scale. BLOCKING: cannot be frozen as written, because a gate cannot be passed honestly, an independent oracle cannot be derived, or a core promise can be silently broken. MATERIAL NON-BLOCKING: should be resolved before freeze, but a reasonable build could proceed with an explicit decision. CLARITY: wording, structure or navigation. Suggested directions are offered to support T's decision and are not proposed requirement text.

Out of scope for this pass: the source master, requirements outside the cut (including PB-OPS-003, 003.1 and 010 beyond their listed titles), any implementation, and final Help prose.

3. Summary

BLOCKING11
MATERIAL NON-BLOCKING15
CLARITY8
Total34

Revision BL is a strong contract at its core. The Store commit protocol, the strict UTF-8 section and the honesty boundaries hold up well under attack. The blocking findings cluster in three places.

First, lifecycle edges. What happens when things go missing, get refreshed or get edited — a damaged RID, a re-downloaded source, an aliased Work Order being revised — is either unspecified or leads to silent behavior the contract elsewhere forbids (F-02, F-03, F-04).

Second, oracles that are referenced but not present. The error contract, the string-literal rules, the CSV input grammar, Receipt serialization, source/MAP compatibility and the conversion form are cited but not in the cut. An independent QA suite cannot be derived without them (F-05 to F-10).

Third, stale in-scope text, meaning requirements left over from earlier models (F-01, F-11).

Most blocking items need a decision rather than new machinery.

4. Finding index

IDSeverityFinding
F-01BLOCKINGAn acceptance gate requires a capability the contract forbids
F-02BLOCKINGAn aliased Work Order cannot be edited and re-saved, and the WKO alias registry has no retirement path
F-03BLOCKINGA missing or damaged RID or COL silently forks the Store, and the RID recovery base is undefined
F-04BLOCKINGA same-filename source refresh has no cardinality check against the inherited RID, and there is no way to start a new Store
F-05BLOCKINGThe source-to-MAP compatibility rule is referenced but never defined
F-06BLOCKINGThe CSV dialect and the rules for malformed input are not frozen
F-07BLOCKINGThe meaning of the UTF-8 first-invalid offset is undefined, and the frozen error contract it points to is not in the cut
F-08BLOCKINGThe DS-STEPS lexical rules are incomplete, and the "governed string-literal rules" they cite are not in the cut
F-09BLOCKINGReceipt and Inventory TXT must be tested byte-for-byte, but their serialization is not specified
F-10BLOCKINGWindows-1252 conversion has no Work Order form, output contract or class-level serialization
F-11BLOCKINGThe Store Index is an in-scope obligation with no artifact class, trigger or content contract
F-12MATERIAL NON-BLOCKINGSelecting current state by the greatest UTC has no guard against clock movement
F-13MATERIAL NON-BLOCKINGThe single-writer assumption is not stated
F-14MATERIAL NON-BLOCKINGPublication and validity rules for non-Store artifacts are undefined
F-15MATERIAL NON-BLOCKINGMAP eligibility can change when unrelated files appear, and the comparison rules are undefined
F-16MATERIAL NON-BLOCKINGThe conversion suggestion conflicts with fixed diagnostic semantics, and the Windows-1252 mapping is not frozen
F-17MATERIAL NON-BLOCKINGThe Help rendering contract is missing a coverage fallback, absent-value rendering, and a consistent notion of required facts
F-18MATERIAL NON-BLOCKINGHLP provenance merges "not applicable" with "unavailable", and absence tokens differ across artifacts
F-19MATERIAL NON-BLOCKINGHLP disclosure edge cases: a header can be data, and aliases are not covered by the allowlist
F-20MATERIAL NON-BLOCKING"Bounded memory" has no stated limits, and header width and KEEP width are unlimited
F-21MATERIAL NON-BLOCKINGPublishing from a historical MAP silently changes what is current
F-22MATERIAL NON-BLOCKINGExpected diagnostics come from a registry the implementer delivers, which undercuts QA independence
F-23MATERIAL NON-BLOCKINGAcceptance coverage has gaps, and test seams are missing
F-24MATERIAL NON-BLOCKINGSession model: a new CER every session, no remembered Suitcase, no preferences, and lost drafts
F-25MATERIAL NON-BLOCKINGThe target platform and the small-screen baseline are not defined within the cut
F-26MATERIAL NON-BLOCKINGAllowed SOURCE reference forms are undefined
F-27CLARITYW002-UI-006 says "editable human alias"
F-28CLARITYBrand-Manifest wording survives in in-scope text
F-29CLARITYSection headings misplace in-scope requirements and are out of order
F-30CLARITYTruncated text in titles, evidence and rationale
F-31CLARITYNumbering gaps are not explained
F-32CLARITYTerminology drift
F-33CLARITYSome registered classes have no WASM-002 producer or contract, and unknown-class reporting is unspecified
F-34CLARITYSmaller underspecified points

5. Findings

F-01BLOCKING

An acceptance gate requires a capability the contract forbids

Cited: W002-UI-ACC-019 W002-UI-023 W002-STOR-018 W002-STOR-015

What the contract says

Why it matters

Impact if frozen as written. A frozen build could never reach BUILT & ACCEPTED on this gate. An implementer who tries to satisfy it would introduce a second, mutable naming path outside the Work Order.

Question / direction for T. Retire or rewrite W002-UI-ACC-019. A natural replacement is a gate proving that there is no Description field, and that changing a WORK ORDER AS alias requires saving a new WKO. That property is already partly exercised by W002-MAT-ACC-002.4, so the rewrite may simply merge into it.

F-02BLOCKING

An aliased Work Order cannot be edited and re-saved, and the WKO alias registry has no retirement path

Cited: W002-STOR-018.2 W002-STOR-018.3 W002-STOR-018.4 W002-UI-020 W002-UI-023 W002-MAT-ACC-002.4

What the contract says

Why it matters

Impact if frozen as written. The most common authoring action fails by default. The registry can also deadlock or silently lose registrations when ordinary file housekeeping happens.

Question / direction for T. The alias needs a lifecycle decision. Should a newer WKO with the same alias supersede the older row, the way successor MAPs work for Stores? Should a derived draft's save offer that supersession explicitly in Work Order text? The contract should also say what happens when a registered WKO file disappears, and whether unregistered but well-formed WKO files may be loaded and Run.

F-03BLOCKING

A missing or damaged RID or COL silently forks the Store, and the RID recovery base is undefined

Cited: W002-STOR-019.10 W002-STOR-019.2 W002-STOR-019.3 W002-STOR-019.11 W002-RID-001 W002-RID-008 W002-RID-009 W002-STEPS-010 W002-STOR-020 W002-WKO-012.5

What the contract says

Why it matters

Impact if frozen as written. A routine file-system event can turn a governed Store into a different Store with no warning. That undermines the row-identity promise that WASM-002 exists to prove.

Question / direction for T. Three decisions are needed. First, should MAP eligibility separate structurally valid but degraded from invalid, so that a degraded lineage blocks new-Store creation from the same source and refuses with a Help path pointing to recovery? Second, define recovery-base selection precisely: which MAPs are candidates, how a Store alias matches, and what happens with empty or duplicate aliases. Consider allowing MAP "..." as a recovery selector. Third, decide whether recovery lineage needs a persisted link — a predecessor MAP field or an equivalent — rather than living only in the Receipts.

F-04BLOCKING

A same-filename source refresh has no cardinality check against the inherited RID, and there is no way to start a new Store

Cited: W002-STOR-019.2 W002-RID-005 W002-RID-006 W002-MAT-002.6 W002-MAT-002.7 W002-STEPS-001

What the contract says

Why it matters

Impact if frozen as written. Misaligned columns could be committed as same-Store state, or the analyst is forced into filename tricks to express intent.

Question / direction for T. Add an explicit requirement for existing-Store materialization: the accepted N must equal the inherited RID's N before any promotion, or the run refuses, with a named phase, diagnostic and acceptance fixture. Then decide how an analyst expresses "this is a new row universe" in Work Order text — a NEW STORE clause or an equivalent — instead of by renaming files.

F-05BLOCKING

The source-to-MAP compatibility rule is referenced but never defined

Cited: W002-STOR-019.3 W002-WKO-012.3 W002-WKO-ACC-008 W002-STOR-019.6

What the contract says

Why it matters

Impact if frozen as written. A mandatory refusal fixture cannot be written independently, and the implementer would be deciding a join-semantics question on their own.

Question / direction for T. Freeze the compatibility predicate. Is it exact equality of SOURCE with store_source_filename? Or equality plus the N check from F-04? Or something broader? And state what the per-row source_filename is for in WASM-002.

F-06BLOCKING

The CSV dialect and the rules for malformed input are not frozen

Cited: W002-MAT-002.8 W002-MAT-003.2 W002-MAT-003.3 W002-MAT-ACC-003 W002-MAT-ACC-004 W002-MAT-ACC-005 PB-OPS-001

What the contract says

Why it matters

Impact if frozen as written. Refusal location and condition are required to be deterministic, but the rules that determine them are not in the contract. QA cannot derive the oracle before seeing a candidate.

Question / direction for T. Freeze a short normative input grammar, either as RFC 4180 with explicit deviations or as a state table, covering (a) through (g). Say which cases refuse, and with which fact that locates them — byte offset, logical row, or physical line.

F-07BLOCKING

The meaning of the UTF-8 first-invalid offset is undefined, and the frozen error contract it points to is not in the cut

Cited: W002-ENC-004.10 W002-ENC-ACC-006 W002-ENC-ACC-007 W002-ENC-ACC-008 W002-ENC-ACC-009

What the contract says

Why it matters

Impact if frozen as written. The invalid-sequence matrix cannot be authored as an independent oracle. Two correct implementations could disagree while both satisfy the text.

Question / direction for T. Import or restate the error contract. For example: the offset is the absolute byte offset of the first byte of the maximal invalid prefix, and a truncated sequence at EOF reports its lead byte. Add the reported fact names — offset, stop reason, and the offending-bytes window if any — to the diagnostic definition.

F-08BLOCKING

The DS-STEPS lexical rules are incomplete, and the "governed string-literal rules" they cite are not in the cut

Cited: W002-STOR-018 W002-STEPS-001 W002-STEPS-001.1 W002-STEPS-001.2 W002-STEPS-003 W002-WKO-012.1 W002-WKO-013 W002-WKO-ACC-006

What the contract says

Why it matters

Impact if frozen as written. Save-time validation, run-time validation and the chaining-refusal gate all depend on rules the implementer would have to invent.

Question / direction for T. Add a compact lexical section: string-literal escaping (or an explicit statement that there is none, with the consequences); keyword case; whitespace; ordinal numerals; clause cardinality and order; the rule that unknown lines refuse; allowed operation combinations; the WKO byte encoding; and the exact set of composition tokens that trigger the deferred-composition diagnostic.

F-09BLOCKING

Receipt and Inventory TXT must be tested byte-for-byte, but their serialization is not specified

Cited: W002-RCP-005 W002-RCP-006 W002-RCP-007 W002-RCP-008 W002-CONV-004.2 W002-INV-006

What the contract says

Why it matters

Impact if frozen as written. Receipts are the Flight Recorder substrate. Leaving their grammar to the implementation weakens the "I can show somebody else" promise at its foundation.

Question / direction for T. Freeze a small TXT grammar shared by RCP and INV: the key set and order per operation, enumerated tokens (including the none, not-run, not-available and unknown-operation values), text escaping, and the list-valued form. Add the UPDATE ALIASES fact section. One golden Receipt per operation in the contract would close this.

F-10BLOCKING

Windows-1252 conversion has no Work Order form, output contract or class-level serialization

Cited: W002-CONV-001 W002-CONV-001.4 W002-CONV-004 W002-CONV-004.1 W002-CONV-ACC-001 W002-CONV-ACC-002 PB-STOR-006

What the contract says

Why it matters

Impact if frozen as written. An in-scope operation with an acceptance gate cannot be implemented without inventing its syntax and output bytes.

Question / direction for T. Add the canonical conversion Work Order form, the CVT serialization (extension, BOM, byte-preserving line endings, publication path) and golden-byte fixtures. Extend W002-CONV-ACC-001 to check that the source is unchanged, that the output is certifiable, and that the Receipt facts are present. Or, if conversion is not really ready, re-scope it deliberately.

F-11BLOCKING

The Store Index is an in-scope obligation with no artifact class, trigger or content contract

Cited: W002-STOR-010 W002-STOR-010.3 W002-STOR-010.4 W002-STOR-010.1 PB-STOR-002 W002-STOR-003.5

What the contract says

Why it matters

Impact if frozen as written. Cheap to fix, but it cannot be frozen as it stands.

Question / direction for T. Re-scope W002-STOR-010, 010.3 and 010.4 to V1-BACKLOG, or recast them as the Suitcase Directory's orientation role. PB-STOR-002's "Store Map/Index" wording would follow.

F-12MATERIAL NON-BLOCKING

Selecting current state by the greatest UTC has no guard against clock movement

Cited: PB-STOR-013 PB-STOR-011 W002-STOR-019.2 W002-STOR-018.4

What the contract says

Why it matters

Impact if frozen as written. Silent staleness, or self-inflicted refusal, both of which only an expert could diagnose.

Question / direction for T. Consider a rule that a successor's transaction UTC must be strictly greater than its base's. Decide whether a violation should refuse with a Help explanation, or wait and re-read the clock. Then test it with an injected clock (see F-23).

F-13MATERIAL NON-BLOCKING

The single-writer assumption is not stated

Cited: W002-ARCH-014 W002-STOR-018.3 W002-STOR-019.5 W002-HELP-011.2

What the contract says

Why it matters

Impact if frozen as written. Lost updates, and state flipping between committed and missing, with no diagnostic.

Question / direction for T. State the single-writer assumption as a contract boundary. Decide whether WASM-002 must detect a changed base at commit time — for example, by re-checking that the base is still the newest immediately before the final rename — or only explain the risk through Help.

F-14MATERIAL NON-BLOCKING

Publication and validity rules for non-Store artifacts are undefined

Cited: PB-STOR-008 PB-STOR-012 W002-STOR-018.3 W002-RCP-010 W002-MAT-002.6 W002-INV-002 W002-STOR-022 W002-HELP-009

What the contract says

Why it matters

Impact if frozen as written. Evidence artifacts could be counterfeit or partial without anything detecting it, and debris could not be attributed to the run that left it.

Question / direction for T. Define a per-class publication path — direct write, or SCR then rename. Define minimal validity checks per class, including what makes a WKO loadable and Runnable. Define SCR/RCV naming and content. Require the Receipt to list any SCR/RCV evidence a run leaves behind.

F-15MATERIAL NON-BLOCKING

MAP eligibility can change when unrelated files appear, and the comparison rules are undefined

Cited: W002-STOR-020 W002-STOR-019.10 W002-STOR-019.2 PB-STOR-010 W002-STEPS-002

What the contract says

Why it matters

Impact if frozen as written. Store routing becomes a function of unrelated folder contents and of platform file-name semantics.

Question / direction for T. Define the comparison rule: exact bytes, case-folded, or normalized. Decide whether shadowing is checked only when a MAP is published, rather than every time eligibility is evaluated. Decide whether source routing must detect case or normalization aliases of the same physical file.

F-16MATERIAL NON-BLOCKING

The conversion suggestion conflicts with fixed diagnostic semantics, and the Windows-1252 mapping is not frozen

Cited: W002-HELP-001.6 W002-HELP-001.7 W002-HELP-001.8 W002-CONV-002 W002-CONV-002.1 W002-CONV-002.3 W002-CONV-002.4 W002-CONV-003.5 W002-ENC-004.10

What the contract says

Why it matters

Impact if frozen as written. As written, Help would either break W002-CONV-003.5 or have to override the registry. The defined-byte rule could also be lost to a library default.

Question / direction for T. Split the certification-failure diagnostics by assessment outcome. Specify when the assessment runs and what the Receipt records. Freeze the mapping explicitly: the Microsoft best-fit table minus the five undefined bytes, with a pre-check that refuses them. Consider whether Help should also flag patterns such as NUL-heavy content as reasons not to suggest conversion.

F-17MATERIAL NON-BLOCKING

The Help rendering contract is missing a coverage fallback, absent-value rendering, and a consistent notion of required facts

Cited: W002-HELP-001.4 W002-HELP-001.8 W002-HELP-002.9 W002-HELP-002.10 W002-HELP-004.11 W002-UI-007

What the contract says

Why it matters

Impact if frozen as written. There are paths where Help cannot render truthfully, or where fallback prose gets invented in the UI.

Question / direction for T. Either require full catalog coverage of the registry at build time, or define a governed fallback rendering. Decide whether the boundary facts are optional-when-unavailable or required-and-nullable. Freeze how each value type renders, including absent values and a literal brace.

F-18MATERIAL NON-BLOCKING

HLP provenance merges "not applicable" with "unavailable", and absence tokens differ across artifacts

Cited: W002-HELP-009 W002-RCP-010 W002-HELP-004.11 W002-RCP-007

What the contract says

Why it matters

Impact if frozen as written. A small misstatement, but in the evidence surface where honesty matters most.

Question / direction for T. Separate "no relationship exists" from "relationship exists but its artifact is unavailable" in both the JSON and the visible Provenance section. Consider one shared absence vocabulary across RCP, HLP and diagnostics.

F-19MATERIAL NON-BLOCKING

HLP disclosure edge cases: a header can be data, and aliases are not covered by the allowlist

Cited: W002-HELP-010 W002-HP-ACC-011

What the contract says

Why it matters

Impact if frozen as written. Possible data leakage through a permitted channel, and uncertainty over which labels a report may use.

Question / direction for T. Decide whether headers are disclosed as metadata with a Help caveat, or only by ordinal when the diagnostic concerns header parsing. Add aliases to an explicit tier.

F-20MATERIAL NON-BLOCKING

"Bounded memory" has no stated limits, and header width and KEEP width are unlimited

Cited: W002-ENC-001.5 W002-MAT-002.5 W002-MAT-003.1 W002-MAT-001.7 W002-MAT-002.10 W002-MAT-ACC-006

What the contract says

Why it matters

Impact if frozen as written. "Bounded" cannot be accepted or rejected objectively.

Question / direction for T. Set a numeric budget, or a measurable test such as "peak must not grow when N or source size doubles". Add limits on header field count and bytes, and on KEEP width, each with a diagnostic.

F-21MATERIAL NON-BLOCKING

Publishing from a historical MAP silently changes what is current

Cited: W002-STOR-019.3 W002-WKO-ACC-008 W002-STOR-019.2

What the contract says

Why it matters

Impact if frozen as written. An analyst using MAP to inspect or tweak history can silently revert the Store.

Question / direction for T. Say explicitly that branching is allowed and that the newest branch wins, and require Help and the Receipt to state which base was used and that later state was superseded. Or forbid successors from non-newest bases.

F-22MATERIAL NON-BLOCKING

Expected diagnostics come from a registry the implementer delivers, which undercuts QA independence

Cited: W002-HELP-001.8 W002-HP-ACC-013

What the contract says

Why it matters

Impact if frozen as written. The oracle is weakened for every refusal gate.

Question / direction for T. Without allocating IDs, freeze a minimum condition catalog: each distinct refusal and warning condition the contract implies, with its phase, behavior and required facts. The registry must then cover it. IDs can remain implementation-allocated.

F-23MATERIAL NON-BLOCKING

Acceptance coverage has gaps, and test seams are missing

Cited: W002-WKO-012.5 W002-WKO-012.6 W002-RCP-010 PB-STOR-011 W002-STOR-007.3 PB-STOR-009 PB-STOR-010 W002-STOR-018.3 W002-HELP-002.11 W002-ENC-ACC-003

What the contract says

Why it matters

Impact if frozen as written. Requirements that are frozen but untested, or test hooks that nothing governs.

Question / direction for T. Add the missing gates. Add one requirement that allows test-only injection of the clock, UUID source, file-system faults and source handles, compiled out of release builds or otherwise provably inert, and that records the retained evidence showing the hooks are absent from the release.

F-24MATERIAL NON-BLOCKING

Session model: a new CER every session, no remembered Suitcase, no preferences, and lost drafts

Cited: W002-UI-017 W002-STOR-022 PB-STOR-001

What the contract says

Why it matters

Impact if frozen as written. Daily friction, and a Suitcase that fills with CER files over time.

Question / direction for T. Decide whether re-selecting a Suitcase that already holds a CER needs a fresh CER. Decide whether a directory handle and UI preferences count as project metadata. Decide whether unsaved-draft loss must be warned about.

F-25MATERIAL NON-BLOCKING

The target platform and the small-screen baseline are not defined within the cut

Cited: W002-UI-011 W002-UI-ACC-007 W002-STOR-022.1 W002-RID-004 W002-MAT-002.11

What the contract says

Why it matters

Impact if frozen as written. Gates W002-UI-ACC-007 and W002-UI-ACC-011 cannot be run reproducibly.

Question / direction for T. Name the supported browsers and minimum versions, and the reference device and resolution, in a WASM-002 requirement. Or import the master definition into the cut.

F-26MATERIAL NON-BLOCKING

Allowed SOURCE reference forms are undefined

Cited: W002-WKO-009 W002-INV-005 PB-STOR-005

What the contract says

Why it matters

Impact if frozen as written. Portability and Suitcase-boundary guarantees depend on implementation choices.

Question / direction for T. Restrict SOURCE to a bare filename in the Suitcase root, or define the permitted forms. State the policy for governed-artifact and non-CSV sources.

F-27CLARITY

W002-UI-006 says "editable human alias"

Cited: W002-UI-006 W002-UI-019 W002-UI-024

What the contract says

Why it matters

Impact if frozen as written. Wording hazard.

Question / direction for T. Change it to "read-only governed alias where applicable".

F-28CLARITY

Brand-Manifest wording survives in in-scope text

Cited: W002-UI-016 W002-INV-006 W002-STOR-022.2 W002-HELP-003.2 W002-HP-ACC-003

What the contract says

Why it matters

Impact if frozen as written. Invites scope creep, or a debate over what "branded" TXT means.

Question / direction for T. Replace with "uses the canonical built-in presentation" where HTML, and remove it for TXT.

F-29CLARITY

Section headings misplace in-scope requirements and are out of order

Cited: W002-WKO-007 W002-WKO-012.1 W002-CONV-ACC-001 W002-STOR-016 W002-WKO-ACC-003

What the contract says

Why it matters

Impact if frozen as written. Misleading navigation in the authoritative review cut.

Question / direction for T. Regenerate headings from requirement SCOPE, or add a note in the cut that headings are inherited from the master and not authoritative.

F-30CLARITY

Truncated text in titles, evidence and rationale

Cited: W002-ENC-006 W002-STOR-001.2 W002-ENC-004.1

What the contract says

Why it matters

Impact if frozen as written. Readability, and one damaged evidence statement.

Question / direction for T. Repair EVID-003 and the rationale block from the master, and merge fragment titles.

F-31CLARITY

Numbering gaps are not explained

Cited: W002-RCP-005 W002-HP-ACC-008 W002-WKO-007 W002-ARCH-008

What the contract says

Why it matters

Impact if frozen as written. An audit trail gap.

Question / direction for T. Add an omitted-ID table (ID, current SCOPE, STATUS) to the cut's front matter.

F-32CLARITY

Terminology drift

Cited: PB-STOR-002 PB-STOR-006 W002-STOR-009 W002-STOR-010.1

What the contract says

Why it matters

Impact if frozen as written. Minor, but it matters for the LLM-readability goal in W002-STOR-014.

Question / direction for T. Use "Store MAP" and "WKO MAP" consistently, and "MAP" only for the class.

F-33CLARITY

Some registered classes have no WASM-002 producer or contract, and unknown-class reporting is unspecified

Cited: PB-STOR-006 PB-STOR-009 W002-STOR-003.5

What the contract says

Why it matters

Impact if frozen as written. Minor ambiguity.

Question / direction for T. Mark DGN as reserved-not-emitted, or define it. Define RCV together with F-14. Say whether unknown-class reporting is an INFO diagnostic, a directory annotation, or both.

F-34CLARITY

Smaller underspecified points

Cited: W002-HELP-005 W002-HELP-009 W002-INV-005 W002-STOR-014 W002-STOR-012 W002-UI-ACC-016 W002-UI-007 W002-HELP-006 W002-RID-004 W002-STOR-022.1

What the contract says

Why it matters

Impact if frozen as written. Minor.

Question / direction for T. Resolve inline during the next revision.

6. Decisions requested from T

These are the questions whose answers would unblock the most findings. Each points back to its finding.

  1. Work Order alias lifecycle: should a newer WKO with the same alias supersede the older row? What happens when a registered WKO file disappears? Are unregistered well-formed WKOs Runnable? (F-02)
  2. Degraded Stores: should damage to a RID or COL block new-Store creation from the same source, and refuse with a pointer to recovery? Should recovery accept a MAP "..." selector, and should recovery lineage be persisted in the MAP? (F-03)
  3. Monthly refresh: how does an analyst say "new row universe" in Work Order text? Should an N mismatch against the inherited RID be a named refusal? (F-04)
  4. May an explicit MAP bring a different source into an existing Store in WASM-002? What does the per-row source_filename mean in this build? (F-05)
  5. CSV input grammar: strict RFC 4180, or RFC 4180 with named deviations? What happens at EOF, with bare CR, and with one-column sources? Is comma the only delimiter? (F-06)
  6. UTF-8 offset convention: lead byte, or offending byte? (F-07)
  7. Is Windows-1252 conversion truly ready for WASM-002, or should it be re-scoped until its Work Order form and output bytes are frozen? (F-10)
  8. Is the Store Index retired in favor of the Suitcase Directory? (F-11)
  9. Should current-state selection require strictly increasing transaction UTC? (F-12)
  10. Is single-writer a stated boundary, and must WASM-002 detect a changed base at commit? (F-13)
  11. Should a minimum diagnostic condition catalog be frozen in the contract, ahead of the implementer's registry? (F-22)
  12. Are test-only injection seams allowed, and how is their absence from release builds evidenced? (F-23)
  13. Does re-opening an already-certified Suitcase need a new CER each session? (F-24)

7. What held up under attack

Appendix A — Prototype divergence log (informational)

The prototype is non-binding, and the PRD wins. These are not findings against the contract. They are recorded because W002-UI-012 says a conflicting prototype must be revised, and several of them happen to illustrate open contract questions.

Source resolutionIt resolves SOURCE through a displayed alias. The contract routes on the exact filename only.
DiagnosticsIt uses DS-PTP-* IDs, a HELP severity outside the INFO/WARNING/ERROR set, phase labels with spaces, and {diagnostic_id} and {phase} placeholders, which are not declared facts.
PublicationIt writes WKO, WKO MAP and HLP directly under their final names, with no SCR staging and no successor-MAP validation.
Store MAP displayIt picks the newest valid MAP across all Stores, rather than per lineage, and shows nothing on a tie. It applies partial checks and requires non-empty aliases, which the contract permits to be empty after CLEAR.
GrammarIt matches keywords case-insensitively, accepts COLUMN +7, and case-folds alias uniqueness (toLocaleLowerCase). All three are open questions in F-08 and F-15.
OperationsIt supports MATERIALIZE only. There is no RCP, INVENTORY, RECOVER RID, UPDATE ALIASES or conversion.
HLPIts HLP has no ds-hlp-provenance payload and no Disclosure section.
ThemesIt has no Modern Dark / Modern Light selector (W002-UI-025).
Retired panelsThe Branding TOML and Data Dictionary panels remain, clearly labelled out of scope.
Consistent with the contractThe Suitcase-first CER gate, the flat directory with display-only aliases, one editor with a derived-draft transition, the read-only execution pane, and the persistent Help pane with a voice switch and report action.

Appendix B — Requirements cited in this review

135 distinct requirement IDs are cited. Every citation was mechanically checked against the 384 IDs present in the reviewed artifact.

PB-OPS-001 PB-STOR-001 PB-STOR-002 PB-STOR-005 PB-STOR-006 PB-STOR-008 PB-STOR-009 PB-STOR-010 PB-STOR-011 PB-STOR-012 PB-STOR-013 W002-ARCH-008 W002-ARCH-014 W002-CONV-001 W002-CONV-001.4 W002-CONV-002 W002-CONV-002.1 W002-CONV-002.3 W002-CONV-002.4 W002-CONV-003.5 W002-CONV-004 W002-CONV-004.1 W002-CONV-004.2 W002-CONV-ACC-001 W002-CONV-ACC-002 W002-ENC-001.5 W002-ENC-004.1 W002-ENC-004.10 W002-ENC-006 W002-ENC-ACC-003 W002-ENC-ACC-006 W002-ENC-ACC-007 W002-ENC-ACC-008 W002-ENC-ACC-009 W002-HELP-001.4 W002-HELP-001.6 W002-HELP-001.7 W002-HELP-001.8 W002-HELP-002.10 W002-HELP-002.11 W002-HELP-002.9 W002-HELP-003.2 W002-HELP-004.11 W002-HELP-005 W002-HELP-006 W002-HELP-009 W002-HELP-010 W002-HELP-011.2 W002-HP-ACC-003 W002-HP-ACC-008 W002-HP-ACC-011 W002-HP-ACC-013 W002-INV-002 W002-INV-005 W002-INV-006 W002-MAT-001.7 W002-MAT-002.10 W002-MAT-002.11 W002-MAT-002.5 W002-MAT-002.6 W002-MAT-002.7 W002-MAT-002.8 W002-MAT-003.1 W002-MAT-003.2 W002-MAT-003.3 W002-MAT-ACC-002.4 W002-MAT-ACC-003 W002-MAT-ACC-004 W002-MAT-ACC-005 W002-MAT-ACC-006 W002-RCP-005 W002-RCP-006 W002-RCP-007 W002-RCP-008 W002-RCP-010 W002-RID-001 W002-RID-004 W002-RID-005 W002-RID-006 W002-RID-008 W002-RID-009 W002-STEPS-001 W002-STEPS-001.1 W002-STEPS-001.2 W002-STEPS-002 W002-STEPS-003 W002-STEPS-010 W002-STOR-001.2 W002-STOR-003.5 W002-STOR-007.3 W002-STOR-009 W002-STOR-010 W002-STOR-010.1 W002-STOR-010.3 W002-STOR-010.4 W002-STOR-012 W002-STOR-014 W002-STOR-015 W002-STOR-016 W002-STOR-018 W002-STOR-018.2 W002-STOR-018.3 W002-STOR-018.4 W002-STOR-019.10 W002-STOR-019.11 W002-STOR-019.2 W002-STOR-019.3 W002-STOR-019.5 W002-STOR-019.6 W002-STOR-020 W002-STOR-022 W002-STOR-022.1 W002-STOR-022.2 W002-UI-006 W002-UI-007 W002-UI-011 W002-UI-016 W002-UI-017 W002-UI-019 W002-UI-020 W002-UI-023 W002-UI-024 W002-UI-ACC-007 W002-UI-ACC-016 W002-UI-ACC-019 W002-WKO-007 W002-WKO-009 W002-WKO-012.1 W002-WKO-012.3 W002-WKO-012.5 W002-WKO-012.6 W002-WKO-013 W002-WKO-ACC-003 W002-WKO-ACC-006 W002-WKO-ACC-008