Errata ledgerstable
§2 Appendix D — the fifteen known issues
These are the issues the Studio PRD carried into this work. All fifteen are dispositioned; five remain gated on ratification and none on an open decision — D8 closed when ADR-0006 was decided on 23 August 2026 (§10 REV-18).
| ID | Title | Source | Classification | Disposition | Status |
|---|---|---|---|---|---|
D1 | Perceptual digest widths are unconstrained; the golden example carries a 96-hex pdq/1.0 value against §5's 256 bits | App. D #1 | patch-correction | fixed-in-1.0.1 — schema delta 1 (alg-conditional patterns), example edit (a), annex E22; validator-rule VER801/VER802 | Closed |
D2 | The provenance.chain[].action enum cannot express actions real pipelines perform (publish, export, compose) | App. D #2 | additive-1.1 | ADR-0004; drafted-in-1.1 §2.3 (open value space, closed core set) | Draft — ratification required |
D3 | icc_error is instructed by the Studio PRD but is unrepresentable in a closed record | App. D #3 | patch-correction | fixed-in-1.0.1 annex E8 — ICC failure fails closed; no undeclared field, ever | Closed |
D4 | The schema performs no semantic validation: no embedding→space referential integrity, no role↔kind match, no availability completeness, no conditional availability_basis | App. D #4 | patch-correction | validator-rule VER301–VER308, VER401–VER405, VER501, VER601–VER606, VER701–VER705, VER901 (profile vera-profile/1.0) | Closed |
D5 | weights_sha256 has no defined preimage for multi-file checkpoints, so the mandatory weight pin is unverifiable | App. D #5 | additive-1.1 | ADR-0007 accepted, construction revised (§10 REV-19): weights_sha256 is not redefined and keeps annex E29's reading in perpetuity; the reproducible pin is the new model.bundle.manifest_sha256 under bundle_digest_alg, drafted-in-1.1 §4 | Draft — ratification required |
D6 | §6.2's reproducibility test is a bare mean cosine — no per-item floor, no percentile, no minimum reference-set size | App. D #6 | additive-1.1 | documented — annex editorial note N5; drafted-in-1.1 §8.2 (tolerance_cosine_p5, tolerance_cosine_worst, reference-set manifest) | Draft — ratification required |
D7 | No field is designated the ecosystem dedup key; pixel_hash-as-primary-key is a doctrine the standard never stated | App. D #7 · §16.11 | patch-correction | fixed-in-1.0.1 annex E27 — pixel_hash groups rendered identity, it is never a primary key; CLAUDE.md corrected in this branch | Closed |
D8 | §7.5's redaction literal {redacted, reason, salted_sha256} is rejected by the redactions[] schema, and salted_sha256 is optional there | App. D #8 · §16.5 | open-ADR → additive-1.1 | fixed-in-1.0.1 annex E15 for the shape question (two objects, two places); the mandatoriness question is ADR-0006 — DECIDED (revised Option A, version-gated: commitment REQUIRED for a producer-performed redaction in a 1.1 record, upstream_withheld for the never-held case, salted_sha256 → commitment_sha256 + commitment_alg); drafted-in-1.1 §5; validator-rule VER1001/VER1002/VER1005 unchanged for 1.0.x | Closed |
D9 | The iptc availability key and the iptc-iim segment family are two spellings of one family | App. D #9 | patch-correction | fixed-in-1.0.1 annex E21 — the two keys are the same family; renaming is a 2.0 narrowing | Closed |
D10 | canonical_visual is bound to a role by contains but never to a kind: "visual" descriptor | App. D #10 | patch-correction | validator-rule VER701/VER705 (and VER501 for the reference); drafted-in-1.1 §11.1 for joint spaces | Closed |
D11 | No size limits anywhere: no maxItems, no maxLength on base64 payloads, no bound on dim | App. D #11 | additive-1.1 | validator-rule VER103/VER104 (profile policy, warning-level in 1.0); drafted-in-1.1 §7 — three distinct quantities: serialized record ≤ 10 MiB, decoded inline raw ≤ 6 MiB, decoded single vector ≤ 6 MiB. The earlier 16 MiB decoded-raw figure was unreachable inside a 10 MiB document and is corrected (§10 REV-06) | Draft — ratification required |
D12 | c2pa.status has no unverifiable state, while §9 imposes an unconditional MUST to validate | App. D #12 | additive-1.1 | fixed-in-1.0.1 annex E28 for the 1.0 interim reading; drafted-in-1.1 §6 (unverifiable + error_detail); validator-rule VER1101/VER1103 | Closed |
D13 | Every hash in the golden example is a trivial placeholder; the example is illustrative, not verified | App. D #13 · §16.13 | patch-correction | fixed-in-1.0.1 annex E26 + example edits (a)–(e); remaining placeholders are labelled illustrative, not repaired | Closed |
D14 | Duplicate space_id within one Record is undefined behaviour | App. D #14 | patch-correction | fixed-in-1.0.1 annex E18 — duplicates are non-conformant; validator-rule VER401; drafted-in-1.1 §11.4, which makes the prohibition normative specification text (it was profile-only in 1.0.x). JSON Schema cannot express key-uniqueness over an array of objects, so enforcement stays in the profile (VER401) for the life of VER 1.x — there is no encoding to move it into, which draft §15.4(a) records as a limit of the language rather than a compatibility trade | Closed |
D15 | embedding.dim/dtype are optional and unrelated to the referenced descriptor's values | App. D #15 | additive-1.1 | fixed-in-1.0.1 annex E24 (present ⇒ MUST equal; absent ⇒ descriptor applies); validator-rule VER601/VER602/VER606; ADR-0008 for 1.1 mandatoriness | Closed |
Accounting: 15 of 15 dispositioned — 10 Closed (D8 joined them when ADR-0006 was decided on 23 August, §10 REV-18), 5 Draft (D2, D5, D6, D11, and the 1.1 half of D12/D15). None Open.
