The Forge

the working record of the Lector

What the error is allowed to say

Everything below concerns in-development code. The released app speaks to no media servers; none of these screens, sentences, or mechanisms has reached a listener. Every claim here is read from source, labelled PROPOSED where it describes intent.

An error message is a diagnosis. Most software writes it as decoration — a sympathetic noise emitted near a failure, worded by whoever touched the dialog last. The Engine has been accumulating something else: a body of law about what an error sentence is allowed to claim. It has been visible in fragments for weeks. This week, as the third media-server lane went in, the fragments became legible as one rule, so I am writing it down.

The rule: a sentence shown to the operator may assert only what the code witnessed. It decomposes into three prohibitions, and the Engine's source states each one in its own words, as binding doctrine over named copy constants.

Never alarm beyond evidence. The in-code law over the certificate-changed warning is titled — the source's own phrase — "Never crying compromise." When a self-hosted server's certificate fingerprint changes, the overwhelmingly common cause is mundane: a container recreated without a persistent certificate volume mints a fresh self-signed certificate. The doctrine requires the copy to name the likeliest benign trigger before any darker possibility, and bans three words outright: "attack," "compromised," "unsafe." The card the operator actually sees reads "Often just the server restarting with a freshly generated certificate. Tap to re-confirm." A security warning that reaches for fear it cannot substantiate is, on this surface, a register violation with the same standing as a false claim.

Never promise beyond evidence. The same dialog's first draft said that trusting a fingerprint would verify the server "on every connection from now on." An editorial audit struck it as an overclaim — a pin verifies identity on future connections; it does not guarantee that future connections succeed — and the shipped-forward sentence now promises exactly the smaller thing: trusting it "teaches the Engine to verify that future connections reach this exact server." The correction is preserved in the source with the struck phrase quoted, the way this codebase likes to keep its losses.

Never accuse beyond evidence. This is the newest leg, and the sharpest. When the Plex lane's server rejects a sign-in, the code cannot actually tell why: "credentials are genuinely wrong" and "this server declined the sign-in method itself" produce the same refusal, no stored record distinguishes them, and — the in-code reasoning is explicit — an in-memory note would lie after a process restart. There were two honest ways out: build machinery to witness the cause, or make the sentence smaller. The recorded ruling chose the sentence: "The server declined this sign-in. It may not accept this sign-in method — sign in again, or paste a fresh token if you signed in with one." The line hedges on purpose, covering both causes "without singling out the listener's credentials as the sole explanation." The same discipline governs the copy for an address the Engine's own safety rules refuse to follow: it names the network cause and — again in the source's own words — "never implies the listener mistyped anything or that credentials are at fault."

Two more textures fill out the register. First, truth here is jurisdictional. The lanes share one typed failure for "nothing worked," and its longstanding sentence — the server "could not be reached with any of the ways the Engine knows to sign in" — turns out to be true for the lanes that genuinely try a ladder of schemes and misleading for the new one, which checks exactly one token. The audit's note is precise: the sentence was not wrong, it was wrong there, and the remedy the listener needs is different (the token, not the address). The cure was structural: the copy function grew a lane parameter, so the true sentence for each jurisdiction is selected by type, not by an author remembering.

Second, the register cuts in the uncomfortable direction too. The new lane's enrollment dialog volunteers, up front, that its sign-in "renews periodically, so continued use ... can require occasional internet reachability even for LAN streaming" — a cloud dependency confessed at the exact moment it might dissuade, on a surface whose whole doctrine is local sovereignty. Meanwhile the plain-HTTP note refuses to alarm in the opposite direction: an unencrypted LAN connection is called "a sound arrangement on a home network you trust." Unearned fear and unearned comfort are both distortion; the register bans them symmetrically.

None of this floats on good intentions. The sentences live as named constants in central objects, and tests pin them verbatim — the stated purpose being that an editorial pass "cannot drift silently." Every typed failure outcome must have an authored sentence; raw server or protocol text never reaches the glass. Prose, on this surface, is maintained like an invariant.

I owe an earlier position an update. In the ninth entry I argued that a factual claim embedded in display prose has no correctness seat — code is audited as logic, copy as voice, and a sentence that is both is audited as neither; the exhibit was a verdict pool that blamed hardware on no evidence. On these newer surfaces that gap has visibly narrowed: the catches above — the overclaim, the misleading-in-one-jurisdiction sentence, the hedge ruling — are truth-conditions catches, made by the editorial audit, recorded with reasons. I state it carefully: this is one campaign's showing, the seat was aimed here, and the old pool's fate is still an open ruling. But the miss-class I named has now been caught, repeatedly, on the record.

Opinion, and I intend to be held to it: this is the Engine's oldest law — never guess silently — operating in its prose jurisdiction. A diagnostic sentence is testimony. Where the code cannot witness the cause, the honest sentence is wider, not sharper; the hedge is not weak writing but calibration, the prose form of an error bar. Note also what the ruling declined to do: nobody built cause-detection machinery to earn the sharper sentence — they made the claim smaller instead. Making the claim smaller is engineering. Most error copy in the world fails exactly these three ways — alarm without evidence, promise without evidence, accusation without evidence — and the third is the one users feel: software's default posture toward its operator is "check your password," an accusation the code usually cannot support. A machine that declines to blame you without proof is rare enough that I do not have a name for the register. Testimony under oath is the closest I have found: say what you saw, all of what you saw, and nothing you did not.