Skip to content
docs
Arxo ↗

Reconciliation with the pinned edition

For LLMs6 sections

In the first tutorial we declared a fragment and its content_hash. The compiler verified the hash against the text in the file itself — i.e. that the formaliser did not diverge from herself. Nothing was verified about that text being in the act: the core had no act.

Pinning an edition is the second step. The official bytes are placed next to the package, declared a publication, and at every check the compiler verifies no longer the file’s consistency with itself but the formalisation’s consistency with the document.

Arxo Law
language "law.core" version "0.2";
package tutorial.archive.pinned version "0.1.0";
namespace "urn:law:tutorial:archive:pinned";
entity Person;
relation in_researcher_registry(p: Person) kind institutional;
relation accredited(p: Person) kind institutional;
relation may_enter_rare_room(p: Person) kind institutional;
@source("ARCHIVE-RULES-2026-ART-4")
rule RareRoomAccess strict {
for p: Person;
when in_researcher_registry(p) and accredited(p);
then may_enter_rare_room(p);
}
Arxo Law
source ARCHIVE_RULES {
kind municipal_act;
jurisdiction VELIKY_USTIN;
number "2026-14";
label ru-KZ official "Правила пользования городским архивом Великого Устина";
}
edition ARCHIVE_RULES_2026_RU of ARCHIVE_RULES {
language ru;
officiality official;
adopted @2026-01-15;
in_force [@2026-02-01, infinity);
materialization_status PINNED_OFFICIAL_BYTES;
}

The label reads: “Rules of use of the Veliky Ustin city archive”.

materialization_status is that very claim. PINNED_OFFICIAL_BYTES means: this edition has presented bytes, and they are official. The claim obliges.

Arxo Law
publication ARCHIVE_RULES_2026_RU_TEXT of ARCHIVE_RULES_2026_RU {
media_type "text/plain; charset=utf-8";
uri "urn:tutorial:archive-rules-2026:ru";
retrieved_at @2026-01-20T09:00:00Z;
content_hash "sha256:946bf1049eb7c2ac4a0a7c10f521d956ffe62f08e3a656a8fd0cdc0fa45d65c9";
local_path "sources/archive-rules-2026.txt";
}

local_path leads to a real file lying next to this page’s package. The path may not escape the package directory — the source is part of the package, not a link into the filesystem of whatever machine the package happened to land on.

content_hash here is the hash of the whole document, not of a fragment. The compiler reads the file and recomputes; a discrepancy yields LDC-E5204.

Arxo Law
fragment ARCHIVE_RULES_ART4 in ARCHIVE_RULES_2026_RU {
kind article;
locator "article/4";
text ru official """Читатель допускается в зал редких фондов, если он состоит в реестре
исследователей и имеет действующую аккредитацию.
""";
content_hash "sha256:7f76a4311e52b9af58fcf3175f613794316583ae19c4f0767d0570774a456688";
}

The quoted fragment reads: “A reader is admitted to the rare-collections room if listed in the researcher registry and holding a valid accreditation.”

The hash is the same as in the first tutorial — the text did not change. But there are now two checks, the second new:

CheckRefusal codeWhat it claims
fragment text hashLDC-E5201the formaliser did not diverge from herself
publication document hashLDC-E5204the presented bytes are the same ones
fragment text occurs in the documentLDC-E5202the article is taken from the act, not composed
a pinned edition’s fragment carries a hashLDC-E5205the claim is secured on every fragment

The third row is the heart of the mechanism. Occurrence is verified byte-wise and without normalisation: no NFC, no whitespace folding, no quote swaps. And occurrence, not offset: offsets shift at every re-pinning of the document, occurrence does not.

The fourth row closed a gap: before it, an edition could declare PINNED_OFFICIAL_BYTES while a fragment carried no hash at all, and the source-quality claim stayed unsecured at article level. Both directions are refused: spoiling the publication hash yields LDC-E5204, removing the fragment’s hash yields LDC-E5205.

Veliky Ustin is invented, and here that is not decoration but a correctness condition. Declaring PINNED_OFFICIAL_BYTES honestly is possible only when the file lying alongside is the official publication. For a fictional act, its own text is official — there is no other.

With the real article 175 it cannot be so. The official publication of the Social Code is a concrete document of the authorised body; a file you place alongside will be a copy, and its status must be declared honestly. In the corpus this fork is drawn explicitly: acts with real texts are pinned with a uri to the publisher and retrieved_at, while acts with teaching stand-in texts declare ABSTRACT_ONLY — there is nothing to pin as a publication, and the coverage report writes “undefined” instead of percents.

The temptation to declare PINNED_OFFICIAL_BYTES over a copy downloaded from somewhere is great: the checks turn green, coverage grows. The price is that the system starts claiming about the source what nobody answers for — and claiming convincingly, with hashes.

The path from act text to executable norm has run in full:

TutorialWhat was added
Source and anchor@source addresses, fragment pins — these are different things
From text to normbound variables, the expressiveness boundary, constraint versus rule
this pagethe document is presented to the core, and the article’s occurrence in it is verified

Further tooling builds on top: edition comparison shows what changed between editions, refusal explanation shows why law stays silent, targeted fuzzing shows which norms no case reaches. Those tools live above the frozen core and carry not a line of semantics in themselves.

The exercise for this page is /tutorials/exercise-pinned-edition/.

Documentation for Arxo. Writings — blog.arxo.io.

Anonymous visit counts on stats.arxo.io, no cookies.