Three-Valued Outcome
Every attempted intervention resolves to APPLIED, REFUSED or INDETERMINATE — and INDETERMINATE is never rewritten.
- Standing
- STATED CHECKABLE RUNNABLE EXECUTED STAGED PUBLISHED REPRODUCED
- Last checked
- never run
- Source
- none — this record cites no check
- Limit
- The witness lives in super/ and is referenced, not copied. It establishes that one round's settle-in-place design was refuted — it does not establish that the tree's other components carry the third value. INDETERMINATE has no forge counterpart, because films are total.
- Next rung
in_tree— the super/ witness is referenced, not copied, so this catalog cannot run it. Staging it here — so the refutation of the predecessor round's settle-in-place design can be re-run rather than quoted — is the step.
Why this page says STATED — the derivation, not the word
- ✗ a witness is named
- ✗ its evidence kind is one the ledger already uses
- ✗ the witness path resolves in this tree
- ✗ its rung is in_tree or above
- ✗ a run is recorded for these exact bytes
- ✓ no claim is cited that could be REFUTED
- ✗ a counterexample is shipped (required once WITNESSED)
- ✗ not staged on this site, so it cannot run from the page
WITNESSED requires every line above to hold. The label is computed from them by build.mjs and cannot be typed into the registry — the build refuses a record that carries it.
Intent
Two values are not enough for an action on a world you do not fully control. A timeout abandons the request but not the work: the effect may be about to land. Recording that attempt as failed is a lie the future may contradict; recording it as succeeded is a guess. INDETERMINATE is a fact about an attempt, kept as such forever.
Technical register
Super D.1.3c·2d·2 intervention provenance: outcome vocabulary APPLIED | REFUSED | INDETERMINATE; 'INDETERMINATE is a fact about an attempt. It is never rewritten.' The same document's §0 refutes its predecessor round's settle-in-place design: Ampd.Receipts has no update-in-place operation, and the re-observation that would repair INDETERMINATE (Pty::winsize()) has zero callers. A witness is sound after a death and unsound after a timeout.
Problem
Distributed systems teach the Two Generals problem and then write boolean return types anyway. An intervention that timed out gets retried, and the retry applies twice; or it gets marked failed, and the world quietly holds an effect nobody recorded.
Solution
Return three values. Append a new record for any later observation rather than rewriting the attempt. Distinguish a death (witness sound) from a timeout (witness unsound). Name the re-observation the design depends on, and check that it exists.
Real-world analogy
A letter posted to a friend abroad. Delivered, returned to sender, or — for a while, maybe forever — unknown. Writing 'lost' on your copy because a week passed does not make it so.
Structure — on the surface
An illustration on a compute surface: loci above, carriers below. Press Play or Step; the takeaways collect as you go. Nothing here is evidence — the witness section is.
The chapter in WRL — and the chain so far
Chapter 18 of 32 — the fragment _patterns/wrl/chain/three-valued-outcome.wrl, sealed alone by wrl.js
; THREE-VALUED OUTCOME — two claims in one batch: one Applied (tv_open is configurable), one Rejected
; (tv_fixed is not). The third value has no forge counterpart: a Film is total. tv_in is the entry.
[relay:tv_in]{sig_in, sig_out}
[spinner:tv_open](w=16, n=8, rotor=quarter_turn_z, configurable){sig_in, socket}
[spinner:tv_fixed](w=16, n=8, rotor=quarter_turn_z){sig_in, socket}
[orb:tv_a]{pose}
[orb:tv_b]{pose}
[tv_in] --sig--> {[tv_open], [tv_fixed]}
[tv_open] --socket--> [tv_a]
[tv_fixed] --socket--> [tv_b]Its test bench _patterns/wrl/chain/three-valued-outcome.bench.wrl — drives the entry for this chapter's own film; never part of the chain
; TEST BENCH — drives this chapter's entry alone; the chain replaces it with a wire from an earlier chapter
[pulser:tv_bench](every 1){sig_out}
[tv_bench] --sig--> [tv_in]module + bench seal to → sem-db31df29ee2f684ed12d78d7f50b2c3437579fca66806c6d6a95d053526bc978
Run inputs — a ScenarioV1, the forge's own document, bound to this world's id and never part of it (D3) · ScenarioDigest scen-00d3d5041764cea601d… (the run inputs' own identity, computed by the forge)
| epoch | writer · seq | op | target | rotor | label |
|---|---|---|---|---|---|
| 1 | w1 s1 | SetRotor | tv_open | 255.0.0.0 | SetRotor tv_open 255.0.0.0; SetRotor tv_fixed 255.0.0.0 |
| 1 | w1 s2 | SetRotor | tv_fixed | 255.0.0.0 | SetRotor tv_open 255.0.0.0; SetRotor tv_fixed 255.0.0.0 |
Reduced by the reference reducer (pure Python); parity with the other reducer not run for this world.
Receipts in the last epoch's Film
receipt:w=1,s=1,accepted=70,apkey=0.1.255.0.0.0,epoch=1,outcome=Applied receipt:w=1,s=2,accepted=46,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable)
The Film, epoch by epoch (6)
epoch 1 · sha256:869d37ee6167e6253ccd77193eaafa55bf24e48ef048fadb1adeec2c0352b351
FILM v0.7 t=1 spinner:tv_fixed:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=tv_b,config=fixed spinner:tv_open:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00ff,0000,0000,0000,socket=tv_a,config=configurable orb:tv_a:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=tv_open,fault=0 orb:tv_b:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=tv_fixed,fault=0 pulser:tv_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:tv_in:cur_out=0,next_out=1 wire:w__tv_bench__tv_in:cur=1,nxt=1 wire:w__tv_in__tv_fixed:cur=0,nxt=0 wire:w__tv_in__tv_open:cur=0,nxt=0 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=1,s=1,digest=70,pkey=0.1.255.0.0.0,payload=SetRotor:tv_open:255.0.0.0 claim:w=1,s=2,digest=46,pkey=0.0.255.0.0.0,payload=SetRotor:tv_fixed:255.0.0.0 receipt:w=1,s=1,accepted=70,apkey=0.1.255.0.0.0,epoch=1,outcome=Applied receipt:w=1,s=2,accepted=46,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable) recognition:w=1,s=1,state=unambiguous recognition:w=1,s=2,state=unambiguous
epoch 2 · sha256:b3344b5f330218dc8b45a651a1a7bff6eb0d4d32ea02097b6b49ea1fab71f26d
FILM v0.7 t=2 spinner:tv_fixed:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=tv_b,config=fixed spinner:tv_open:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00ff,0000,0000,0000,socket=tv_a,config=configurable orb:tv_a:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=tv_open,fault=0 orb:tv_b:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0100,0000,0000,0000,controller=tv_fixed,fault=0 pulser:tv_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:tv_in:cur_out=1,next_out=1 wire:w__tv_bench__tv_in:cur=1,nxt=1 wire:w__tv_in__tv_fixed:cur=0,nxt=1 wire:w__tv_in__tv_open:cur=0,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=1,s=1,digest=70,pkey=0.1.255.0.0.0,payload=SetRotor:tv_open:255.0.0.0 claim:w=1,s=2,digest=46,pkey=0.0.255.0.0.0,payload=SetRotor:tv_fixed:255.0.0.0 receipt:w=1,s=1,accepted=70,apkey=0.1.255.0.0.0,epoch=1,outcome=Applied receipt:w=1,s=2,accepted=46,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable) recognition:w=1,s=1,state=unambiguous recognition:w=1,s=2,state=unambiguous
epoch 3 · sha256:76e6f56934e9863f9e5262e19bf7e0e0e774e78dae64ef9dee51c8b0eed11ac3
FILM v0.7 t=3 spinner:tv_fixed:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=tv_b,config=fixed spinner:tv_open:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00ff,0000,0000,0000,socket=tv_a,config=configurable orb:tv_a:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=00ff,0000,0000,0000,controller=tv_open,fault=0 orb:tv_b:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=00b5,0000,0000,00b5,controller=tv_fixed,fault=0 pulser:tv_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:tv_in:cur_out=1,next_out=1 wire:w__tv_bench__tv_in:cur=1,nxt=1 wire:w__tv_in__tv_fixed:cur=1,nxt=1 wire:w__tv_in__tv_open:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=1,s=1,digest=70,pkey=0.1.255.0.0.0,payload=SetRotor:tv_open:255.0.0.0 claim:w=1,s=2,digest=46,pkey=0.0.255.0.0.0,payload=SetRotor:tv_fixed:255.0.0.0 receipt:w=1,s=1,accepted=70,apkey=0.1.255.0.0.0,epoch=1,outcome=Applied receipt:w=1,s=2,accepted=46,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable) recognition:w=1,s=1,state=unambiguous recognition:w=1,s=2,state=unambiguous
epoch 4 · sha256:5d45ed37cdb32eed988e41c0a2f175cc947c813ef2e36bff252460971831c781
FILM v0.7 t=4 spinner:tv_fixed:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=tv_b,config=fixed spinner:tv_open:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00ff,0000,0000,0000,socket=tv_a,config=configurable orb:tv_a:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=00fe,0000,0000,0000,controller=tv_open,fault=0 orb:tv_b:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=0000,0000,0000,00ff,controller=tv_fixed,fault=0 pulser:tv_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:tv_in:cur_out=1,next_out=1 wire:w__tv_bench__tv_in:cur=1,nxt=1 wire:w__tv_in__tv_fixed:cur=1,nxt=1 wire:w__tv_in__tv_open:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=1,s=1,digest=70,pkey=0.1.255.0.0.0,payload=SetRotor:tv_open:255.0.0.0 claim:w=1,s=2,digest=46,pkey=0.0.255.0.0.0,payload=SetRotor:tv_fixed:255.0.0.0 receipt:w=1,s=1,accepted=70,apkey=0.1.255.0.0.0,epoch=1,outcome=Applied receipt:w=1,s=2,accepted=46,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable) recognition:w=1,s=1,state=unambiguous recognition:w=1,s=2,state=unambiguous
epoch 5 · sha256:860c76292b550f5bccf5a06141ae5d69fdaf46c1048fc9364fb90395937f3c3c
FILM v0.7 t=5 spinner:tv_fixed:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=tv_b,config=fixed spinner:tv_open:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00ff,0000,0000,0000,socket=tv_a,config=configurable orb:tv_a:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=00fd,0000,0000,0000,controller=tv_open,fault=0 orb:tv_b:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=ff4c,0000,0000,00b4,controller=tv_fixed,fault=0 pulser:tv_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:tv_in:cur_out=1,next_out=1 wire:w__tv_bench__tv_in:cur=1,nxt=1 wire:w__tv_in__tv_fixed:cur=1,nxt=1 wire:w__tv_in__tv_open:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=1,s=1,digest=70,pkey=0.1.255.0.0.0,payload=SetRotor:tv_open:255.0.0.0 claim:w=1,s=2,digest=46,pkey=0.0.255.0.0.0,payload=SetRotor:tv_fixed:255.0.0.0 receipt:w=1,s=1,accepted=70,apkey=0.1.255.0.0.0,epoch=1,outcome=Applied receipt:w=1,s=2,accepted=46,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable) recognition:w=1,s=1,state=unambiguous recognition:w=1,s=2,state=unambiguous
epoch 6 · sha256:f42430da56d2d8e7c82ac6616a5d6625fbcc99ac6d7fe818c295578d29370b41
FILM v0.7 t=6 spinner:tv_fixed:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00b5,0000,0000,00b5,socket=tv_b,config=fixed spinner:tv_open:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,rotor=00ff,0000,0000,0000,socket=tv_a,config=configurable orb:tv_a:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=00fc,0000,0000,0000,controller=tv_open,fault=0 orb:tv_b:policy=forge_motor_widemac_tz_sat_v1,quat4,w=16,n=8,pose=ff02,0000,0000,0000,controller=tv_fixed,fault=0 pulser:tv_bench:mode=periodic,p=1,phase=0,armed=0,done=0,nf=1 relay:tv_in:cur_out=1,next_out=1 wire:w__tv_bench__tv_in:cur=1,nxt=1 wire:w__tv_in__tv_fixed:cur=1,nxt=1 wire:w__tv_in__tv_open:cur=1,nxt=1 admit:policy=admit_candidate_min_firstreceipt_v1,fact_capacity_fault=0,receipt_capacity_fault=0,capacity_fault=0 claim:w=1,s=1,digest=70,pkey=0.1.255.0.0.0,payload=SetRotor:tv_open:255.0.0.0 claim:w=1,s=2,digest=46,pkey=0.0.255.0.0.0,payload=SetRotor:tv_fixed:255.0.0.0 receipt:w=1,s=1,accepted=70,apkey=0.1.255.0.0.0,epoch=1,outcome=Applied receipt:w=1,s=2,accepted=46,apkey=0.0.255.0.0.0,epoch=1,outcome=Rejected(not_configurable) recognition:w=1,s=1,state=unambiguous recognition:w=1,s=2,state=unambiguous
Composes with the 17 chapters before it
The chain through this chapter — every earlier fragment, this one, and the links — seals to sem-1247b4e08baaf67f7ca331fa61cfea9f3a2febc2517247ed70e80f5242d0fb75: 71 objects, 65 edges (was 66 / 60; every earlier object and edge is still present — checked, or the build refuses).
Links only the chain carries
; the once-clock's chain, after it has gone quiet, is what this chapter's attempts ride on [pq_b] --sig--> [tv_in]
How to read this board
Five kinds of object, two kinds of wire, and one band per Part of the book. Signal flows left to right: it starts at a clock, travels through relays, and ends at a door — or turns a spinner, which drives an orb. Nothing below is the book's own vocabulary; each line is quoted from where the definition lives.
| shape | is | and so |
|---|---|---|
| a clock; the only source of signal | Every signal on the board starts at one of these. Nothing else can make one. | |
| a pass-through, so signal can travel | One arrives, any number leave — a relay that fans out is the board's router. | |
| a sink; signal arrives and stops | It latches what reached it and passes nothing on. A door is where a path ends. | |
| rotation: takes signal, drives a pose | The only object on the board that holds a value a claim can rewrite — and only if its config says configurable. | |
| the thing that gets moved | It is driven, never driving: an orb is what you watch to see whether anything happened. | |
| not a WRL role — the book's own drawing of the receipts in the epoch's Film | It counts what the run admitted, and turns red on a Rejected outcome. | |
| SignalWire | signal: a sig_out to a sig_in | Legal from a Pulser or Relay, into a Relay, Door or Spinner. This is how the board moves. |
| SocketControl | control: a socket to a pose | Legal only from a Spinner into an Orb. At most one may land on any input port — fan-in is a typed refusal. |
Hover any object for what it is, which chapter put it there, and every field of its line in that epoch's Film — split into what it is doing now and how it was built. Click to pin the readout, then click a wired name to follow the signal. The field definitions come from TRVM/forge/film.py (the emitter), TRVM/forge/forge_state.py (nf, derived from the decoded counter and never from t), TRVM/forge/lower_e2a.py (the commit/react law), TRVM/FORGE_SEMANTIC_IR_v1_MEASURE.md §1.3; the shapes from WRL/learn.html and WRL/docs/spec/README.md. The build refuses if a Film emits a field this key does not explain.
The board so far: one band per Part, signal flowing left to right; relays that fan out are routers, doors are switches, pulsers are clock domains. Hover an object — or click the board and walk it with the arrow keys — for its role, its Part and what it is wired to. This board is the chain’s sealed shape; no Film drives it, so it has no state to report, and the whole board in the conclusion is where every object’s state is read epoch by epoch. Wheel zooms · drag pans · double-click fits.
Syntax — quoted from the tree at build time
The rule, verbatim (super/docs/reviews) super/docs/reviews/D_1_3C_2D_2_INTERVENTION_PROVENANCE.md:723
**INDETERMINATE is a fact about an attempt. It is never rewritten.**
Forces
Three values make every caller handle a case it would rather not. The temptation is to 'settle' INDETERMINATE later by re-observing — which needs the re-observation to exist and the record to be rewritable, and this specification found it had neither. Keeping the attempt's fact and adding a new fact is the honest shape.
Applicability
Any side effect over a boundary you do not control: terminal writes, remote calls, agent actions on a user's machine, payments.
Transformations
- appending a later observation beside an INDETERMINATE attempt
- treating REFUSED as a normal outcome
- rewriting INDETERMINATE to APPLIED or REFUSED
- retrying an INDETERMINATE attempt as if it had failed
- a settle-in-place that the ledger cannot perform
A refusing transformation is not one that is discouraged: it is one that, applied, makes the invariant above false. The word is the tree's, and it is the same word the join uses.
Consequences
Interventions become auditable as attempts, and duplicates become visible instead of silent. The honest status: STATED, with the specification's own refutation of its predecessor printed beside it.
Failure mode it answers
False Quiescence — Declaring completion because no currently observed worker has work. Paid for at: REVISION_REGISTER.md:99 (CompletedScan renamed CompletedSweep; doesNotAssert added)
Witness
No witness. This pattern is STATED — the tree has no check for its invariant.
Counterexample
No counterexample shipped (required only when WITNESSED).
What to take away
- from the animationApplied, refused, and one that timed out; the third stayed what it was.
- from the syntaxINDETERMINATE is appended beside, never rewritten — the ledger has no update-in-place.
- from the literatureTwo Generals; at-least-once versus at-most-once delivery; the third value is what idempotency keys exist to compensate for.
- from the witnessSTATED: the witness is a review in super/, and its §0 is the refutation of the round before it.
Invariant basis — and how each piece bears
| basis | bears | status |
|---|---|---|
cell 17 | necessary | proved cells.json |
Satisfying a basis is local. Nothing here implies global adequacy unless a theorem or a composition rule says so.
Prior art — and what is not claimed
| work | relation | what it shares | where it differs |
|---|---|---|---|
| Two Generals | antecedent | there are questions a message exchange cannot settle | none claimed |
| at-least-once vs at-most-once delivery | antecedent | the third outcome is the practical consequence of the impossibility | delivery semantics name the tradeoff; the pattern names the outcome vocabulary |
| Lamport, 'happened before' | antecedent | partial order as the honest account of distributed time | none claimed |
Novelty not claimed. Distributed systems have had three-valued outcomes since the field began. The witness lives in super/ (referenced, not copied), and its §0 refutes the predecessor round's settle-in-place design — that refutation, not the trichotomy, is the tree's result.
Realizations in the tree
- super/docs/reviews/D_1_3C_2D_2_INTERVENTION_PROVENANCE.md:210
- super/docs/reviews/D_1_3C_2D_2_INTERVENTION_PROVENANCE.md:723
Relations with other patterns
Intervention Provenance STATED · Proven Quiescence PROPOSED↩ · Refusing Join WITNESSED
A ↩ marks a relation named on the other page. Relations are symmetric here and the reverse is derived, so neither side can go missing by being written once.