ObligationDeclaration
What a conformance harness says about one injectable obligation of SeamConformanceSuite — the mid-session transport death, the membership drain, the self-dial.
Why this exists
Each of those obligations is gated on a harness hook rather than a fabric SeamCapabilities flag, and its accountability used to be a String?: a tracking URL meant "not implemented yet", null meant "proven". Two states, three situations. There was no way to say this obligation does not apply to this fabric, by design, so a by-design inapplicability had to be filed as an unimplemented gap — and 9 of the 16 harnesses routing at #1442's mid-session-death umbrella were exactly that.
That is not bookkeeping. An umbrella titled "harness has not implemented mid-session-death injection" tells a contributor burning the list down that the three kuilt-nw entries are unfinished work, and the obvious "fix" — making NwSeam latch Torn when it loses its remote — would undo #1513 and break redial. A comment in one harness is not what that reader reads; a declaration the suite enforces is (#2568).
The vacuity this type has to avoid, and how each arm pays for itself
CLAUDE.md: "an 'I cannot reach this state' opt-out moves the vacuity one level up, where it is harder to see." A NotApplicable arm the suite simply believed would be strictly worse than the tracked gap it replaces — it converts a visible, listed shortfall into an invisible, self-certified green. So no arm is taken on trust. Every arm, on all three obligations, is cross-checked against the harness's own injection hook, whose return value the harness cannot fake without actually injecting:
| Arm | Injection hook must | And the suite additionally asserts |
|---|---|---|
| Proven | inject (true) | the obligation itself runs and passes |
| Gap | not inject (false) | the URL is non-blank |
| NotApplicable.ContractDiffers | inject (true) | the obligation's own postcondition fails |
| NotApplicable.NotConstructible | not inject (false) | the reason is not cheaply refutable — mid-session death only |
That last cell is the one asymmetry, and it is deliberate rather than an omission: a refutation needs a stimulus the suite can apply without the harness's help, and only the mid-session-death arm has one (make the counterpart depart). The membership-drain and self-dial declarations get the hook cross-check and the prose toll, and nothing more.
NotApplicable.ContractDiffers is the strong arm, and the strength is the point: a harness cannot claim its fabric deliberately answers the event differently without performing the event and being watched. It also inverts into a regression guard — the day someone re-introduces tear-on-peer-loss in NwSeam, NwConformanceTest's declaration goes red, because the fabric now satisfies an obligation the declaration says it deliberately does not.
What the arms cannot detect
NotApplicable.NotConstructible is the honest weak arm. Nothing can prove a negative existential — "no injection of this event exists under this harness" — so what the suite does instead is refute the one way the claim is cheaply false, per obligation (for a mid-session death: if the survivor latches
Tornwhen its counterpart leaves, then a tear is reachable here and the stated reason is wrong). A harness that could inject the event through some other route it simply has not written is indistinguishable from one that genuinely cannot — and that distinction is exactly what Gap is for. Only the prose and a reader separate them.A refutation drawn from an absence is worth exactly as much as the stimulus behind it — the trap this vocabulary itself fell into on review, and the reason
SeamConformanceSuite.departCounterpartis a hook rather than a hardcodedjoiner.close(). The no-tear conclusion is identical whether the topology survived a departure or no departure ever happened:MuxServerLoomConformanceTest's joiner is a channel view whoseclose()departs nobody (#2665), so the arm was green by absence. The suite now asserts the counterpart really left the survivor's roster first, and a harness whose counterpart cannot be made to depart may not use this arm at all.NotApplicable.ContractDiffers's deviation check is a bounded negative observation (
the postcondition did not hold within a window). UnderrunTest's virtual clock that window is virtual, which is strong for an in-process fabric — every eligible continuation runs before the bound expires — and weaker for a real-IO harness, where the deviation is asserted before the real transport has necessarily had wall-clock time to answer. It cannot catch a fabric that tears eventually, only one that tears promptly.Gap says nothing about whether the URL leads anywhere. It is the same toll SeamConformanceSuite.everyFalseCapabilityDeclaresAGap charges a capability gap: a sentence a reviewer can go and read.
Every arm's prose is unchecked. A harness that declares the right arm for the wrong reason passes. The arm constrains the shape of the claim and the hook constrains its consistency; the reason is for the human.
Inheritors
Types
The obligation should hold here and is not yet proven — a shortfall someone is tracking.
The obligation does not apply to this fabric or this harness by design — not a shortfall, and not something to "fix". Two arms, split by whether the claim can be demonstrated here; the split is deliberate, because collapsing them would price the demonstrable case at the undemonstrable one's rate and hand every future harness the cheaper arm.
The harness injects the event and the obligation holds — there is nothing to declare away.