# Claims review — 0.2.46

- base: v0.2.45
- head: 696c694
- surface: sha256:e9d01e4e6f99670242922cf7c7d960d85adb9ca786d238d8a5f4279bc1c3eb43
- verdict: pass
- reviewer: maintainer, after a figure this file's process approved reached a
  public archive and turned out to describe one machine

The surface hash is unchanged from 0.2.45. No file in `docs/claims/surfaces.json`
was touched: this release changes two guards, adds a third, and corrects a
changelog. That is exactly why the substantive finding below is not a finding
against the diff, and recording it here anyway is the point.

## Findings

none, against the claim surfaces.

## The reason this record is not empty

**A number that no claim-surface check could see was published to a mailing
list, and the process that let it through is this one.**

`324 Turkish lines across 22 packed doc files` was written into the 0.2.43
changelog and, on 22 August, into a message on the SCITT list. It is not
reproducible. Run v0.2.42's own `pack_locale.mjs` in a clean worktree and it
prints **310 across 20**. Copy in two gitignored files under `docs/audit/` that
sit on one machine and in no commit, and it prints **324 across 22**. The
figure measured a working directory.

Every gate held and none of them was pointed here:

- `claim_discipline` scans surfaces for retracted phrasings. A number is not a
  phrasing.
- `denetci` compares the surface hash. `CHANGELOG.md` is not a surface, on
  purpose, because a changelog is a record rather than a claim about the
  present.
- `pack_locale` printed the figure. It had no reason to doubt its own output,
  and it was correct about the tree it was given.
- `version_claim` compares what npm shipped against the tag. It compares
  contents, not the provenance of the files that produced them.

So the defect was not that a check failed. There was no check whose subject was
*"is the tree this measurement was taken over the tree this repository
describes"*. `test/pack_tracked.mjs` is that check, and it is the whole
deliverable of this release. The two label repairs are consequences.

**What it does not close.** It establishes that the packed set matches the
repository plus `dist/`. It says nothing about figures measured over anything
else — a corpus, a database, a run on another machine — and nothing about
whether a number in prose was copied correctly from a run that did happen. A
figure written by hand into a document is still a hand-written figure; the only
one now mechanically pinned is the locale remainder, in
`docs/claims/locale-residue.json`.

## Not a finding, recorded so the next reader does not re-derive it

The first attempt to show `pack_tracked` red used the two `docs/audit/` files
that caused the original defect. It stayed **green**, and correctly: 0.2.43
excluded `docs/audit` from the package, so those files are no longer packed
from any tree. The red was produced instead with a stray file under `docs/`,
which is where the class still bites.

Worth stating because the near-miss is instructive: a red test built from the
historical culprit can pass for a reason that has nothing to do with the check
being wrong, and a reviewer reading only the green would have concluded the
guard worked. It did work. The demonstration did not.
