Skip to content

What must be kept so that an answer can be repeated

An answer “yes” to a question about admission is worth nothing if a year later the machine answers “no” to the same question and nobody can say why. Law changes by edition, facts are refined, readings dispute, and one specification may have several executors. This article lists what the language forces you to keep together with the answer, and names the boundary honestly: what the kept material does not prove.

A norm on an annual briefing is introduced from 1 January 2027. Ask whether a researcher must take the briefing, on two dates.

Legal date Answer Why
1 June 2026 silent the norm is not there yet
1 June 2027 under a duty the norm is in force

This is a scene from the tutorial on time. The legal date is not the time of the query and not the time of the event. It is the axis every rule looks at: whether it exists on that date, whether the edition of the act it cites is in force, whether the fact was valid on that date. An answer on a past case is not silently recomputed under today’s rules: the legal date enters the case, enters the hash of the answer, and a year later the same question with the same date yields the same answer.

In a program the date is usually one — “now.” Sometimes two. Here there are three, and they differ on purpose: the legal date, the event date in the facts, and the system’s knowledge date. A norm in force from 2027 does not apply to an event of 2026 not because someone programmed that, but because the norm has a window, and the window is recorded.

Every norm in a package carries the address of an article. The address leads not to a page on the web that will be different tomorrow, but into a fragment of a pinned document: the document has a hash of bytes, the fragment has a hash of text, and the fragment’s text must occur in the document byte for byte, without normalizing spaces and quotes. Substitute the document — the check refuses and names what did not match. Remove the hash from the fragment — it refuses too: the claim “pinned by official bytes” must be backed on every article, not only on the cover. The gate performs both breakages itself and requires named refusals: the tutorial on a pinned edition.

What this changes for a dispute about the model: the dispute is about a producible text. “You did not read article 4 that way” is an objection to particular bytes, not to a recollection of what was written there.

Here too is an honest reservation the tutorial makes itself. Only what is an official publication can be pinned as one. A downloaded copy is a copy, and its status is declared as a copy; a teaching act without an official text is declared as such, and the coverage report writes “undefined” instead of percentages. The temptation to declare a copy a publication is strong: the checks will go green. The price — the system will begin convincingly, with hashes, to assert about the source something for which nobody is answerable.

A disputed norm, as shown in the first article, is recorded as two readings, and the case selects one of them. The selection is a case input, the same as the facts and the legal date. It is recorded in the case, enters the hash of the answer, and is visible in the explanation. The answer “there is admission” is reproducible a year later only together with the reading under which it was obtained; without it the machine is honestly silent.

Two things the language does not allow here. You cannot select a reading silently, by order of writing or by default. And you cannot declare that exactly one of the readings is correct without paying for it: such a declaration requires a selection in every case of the package, including cases that do not relate to the disputed item. The ordinary form is “any subset of readings, including the empty one,” and empty means “the package did not resolve the dispute.”

What the engine returns is not a status. It is a document: a manifest with hashes of the package, the case, and the context; results for each question; a proof graph in which every conclusion names the rule and the supports; a list of issues — what was missing, what contradicts, what was exercised invalidly. The document is canonical: the same inputs yield the same bytes. Therefore it can be placed in a file, checked a year later, and taken apart by parts in a dispute.

The language specification is text, and text can be understood in different ways. Therefore there are two implementations, written independently in different languages, and on every question from the conformance set they must yield a byte-identical document. A divergence is not “one of them is right”: it is a blocker that is first qualified — a defect of the first, a defect of the second, or unclarity of the specification — and only then fixed. Conformance scenes are written from the text of the specification, not from the behaviour of the implementations, so that both do not converge on the same error. More — the guide on trust.

For the author of a model this means: that their package answers this way and not otherwise is a property of the specification, not a quirk of one executor. The engine can be changed; the answer will not.

The boundary is named in the system itself, and the introduction is obliged to repeat it.

  • Agreement of two implementations proves that both execute the specification the same way. It does not prove that the specification is true to the law.
  • Pinned bytes prove that the model is built from this text. They do not prove that the text is read correctly.
  • Green checks prove what is recorded in them. A norm written incorrectly but consistently passes every check; in the book on Law DSL that case has a chapter “Green and wrong.”
  • A reproducible answer is a reproducible reading. Whether the reading is correct is decided by a human, and the language cares only that this human is named and their choice is visible.

That is why the formalizer’s work does not end with compilation. It ends with scenes: concrete cases with expected answers that say what the author meant, and that fail when the model or the language changes.

The introduction is finished. For someone who has decided to write — the first tutorial: the archive package is assembled from scratch, and every scene spoken of here appears there one after another. For someone who only wants to ask — the guide. For someone who wants to understand where the boundary of all this lies — the book on Law DSL in the repository catalogue docs/books/kanony/.

Documentation for Arxo. Writings — blog.arxo.io.

Anonymous visit counts on stats.arxo.io, no cookies.