Skip to content
VERASPEC
Repository
Errata ledgerstable

§9 Coverage accounting

SetCountWhere
Studio PRD Appendix D issues15§2
Studio PRD §16 dispositions14§9.1
Errata annex items29§3
Errata annex editorial notes6§4
Architecture decision records8§5
Conformance-profile error codes (1.0 profile, tabulated in §6)53§6
Audit findings — breaking-major2§7.1
Audit findings — patch-correction82§7.2
Audit findings — additive-1.126§7.3
Audit findings — editorial9§7.4
Audit findings — process25§8
Audit findings — implementation-only45Appendix A
Audit findings, total189
Owner-review dispositions (23 Aug 2026)28§10
Findings raised after the review8§10.3

All 189 audit findings appear exactly once. No finding is unaccounted for, and no finding appears in two tables.

The 28 REV-nn rows are a separate namespace and are not counted among the

  1. They are dispositions of the 23 August owner review: sixteen verify a condition at source and, where an audit finding already named it, supersede that finding's documented — not patched disposition — the superseding row names the finding, and the finding keeps its single row in its own table. Twelve are standards-track rulings with no prior audit finding behind them. REV-29 continues that namespace from outside the review — it was raised on 25 August 2026, during decoder-corpus construction — and is likewise not one of the 189; §10.3 carries it.

The 53 counts the codes §6 tabulates — the 1.0 profile as first shipped. The registry has since grown additively for the 1.1-draft profile (83 codes as of 31 August 2026; packages/ver-validator/README.md is the normative enumeration); §6 stays a 1.0 table and is not re-tabulated here. is not among them: it is reserved and deliberately never emitted, which is why it has a note under §6 rather than a row (53 emitted + 1 reserved).

9.1 Studio PRD §16 traceability

The §16 review of the Studio PRD produced fourteen dispositions. §2 accounts for Appendix D; this table accounts for §16, so that a reviewer can close the loop without holding the Studio PRD, which is not in this repository. Where a subsection is out of scope for a standards-track branch, the row says so rather than leaving the absence to inference.

§16.xSubjectWhere it landedStatus
§16.1What "conformant decoder" meansannex E12 — a pinned implementation profile plus a reference corpus; results outside a profile are PROVISIONAL. The corpus is a 1.1 deliverableClosed
§16.2Behaviour on a present-but-unusable ICC profileannex E8 — fail closed; canonical identity withdrawn for such assets; no undeclared icc_error field, everClosed
§16.3Provenance actions the enum cannot expressledger D2 (§2 above) classifies the action value space; ADR-0004; drafted-in-1.1 §2Draft — ratification required
§16.4Derivation and lineage between RecordsADR-0005; drafted-in-1.1 §3 (parents[], recipe_sha256)Draft — ratification required
§16.5Redaction versus byte-exact preservationannex E15; drafted-in-1.1 §5 — the in-view redacted-value shape, and ADR-0006 decided (§10 REV-18): a producer-performed redaction in a 1.1 record REQUIRES a commitment, upstream_withheld names the never-held case, and 1.0.x is unchangedClosed
§16.6Semantic validation the schema cannot performthe profile validator, stages 3–13 (VER301VER1305) — §6 of this ledgerClosed
§16.7Perceptual digest widths and encoding1.0.1 schema delta 1 (alg-conditional patterns), validator VER801/VER802, example edit (a)Closed
§16.8Reproducible model-weight pinningADR-0007; drafted-in-1.1 §4; annex E29 records the 1.0.x readingDraft — ratification required
§16.9Reproducibility evidence beyond a mean cosinedrafted-in-1.1 §8 percentile fields (tolerance_cosine_p5, tolerance_cosine_worst) plus the reference-set manifest; annex note N5Draft — ratification required
§16.10Provisional versus authoritative resultsannex E12's PROVISIONAL/authoritative distinction. Enforcing it is deployment-side — who is trusted to publish authoritative results is out of standards scopeClosed (scoped)
§16.11Whether pixel_hash is the ecosystem dedup keyannex E27 — it is a rendered-identity grouping key, never a primary key; asset identity belongs to the deploying system. CLAUDE.md corrected in this branchClosed
§16.12Space immutability and descriptor driftspec §6.2 is already normative; the implementation gap is ledgered, not patched (EMB-02, QD-01, Appendix A); validator VER402 checks it against a --spaces registryClosed (gap ledgered)
§16.13Example artifacts are placeholdersannex E26 — a standing illustrative-artifact notice plus the five example editsClosed
§16.14Versioning and release governance`VERSIONING.md`, `COMPATIBILITY.md`, `CHANGELOG.md`, the standards/ver/<release>/ layout, and ADR-0001Closed

All fourteen are dispositioned, but two are dispositioned partly outside the standard, and the rows say so rather than implying full closure:

  • §16.10 — the standard defines the PROVISIONAL/authoritative distinction (E12); enforcing it is deployment-side. Which decoders a deployment trusts to publish authoritative results binds that deployment, not a Record.
  • §16.12 — spec §6.2's space-immutability requirement is already normative, so there is nothing to add to the standard; the reference pipeline's failure to honour it is ledgered as EMB-02 and QD-01 in Appendix A and is not patched on this branch.

Separately, the tenancy, privacy and publication policy of the Studio's own stage-16 review is Studio-side throughout, and the conformance profile documents it as out of scope (packages/ver-validator/README.md). Recording that here is the point — the absence is a decision, not a gap.