The Ground Truth Seam · a portal across twelve layers
The Search That Could Have Succeeded
Eleven layers of this ground each certify that something does not exist, by sweeping a stated domain and finding it empty. An absence like that is worth nothing unless the search would have found the thing had it been there, so every one of them plants a witness and shows the same searcher finding it. This page hands you that apparatus over a real registry of 257 records, with six searchers, one sound and five broken in ordinary ways, and lets you watch a broken search collect a clean certificate.
The finding this page starts after
On the night of 11 August 2026 this project shipped eleven pages of one shape. Each takes a question of the form does an object of this kind exist, sweeps a domain completely, finds nothing, and publishes the nothing. Together they swept … objects and printed … assertions.
The bar they set themselves was not the sweep. It was the control. A search that finds nothing and a search that cannot find anything produce identical output, so each page had to plant a synthetic object into the real domain and show the same unmodified searcher finding it. That requirement was written down, gated, and machine-checked. Then the supervisor of the wave audited how it had actually been implemented.
Five of ten builders implemented the planted witness as a post-hoc append, or as a call to a different function than the census.no-second-guarddidif (plant) accept(plant.squares, plant.coverage, true)after the enumeration loops, with caller-supplied coverage:plantedFoundwas 1 whenever a plant was supplied, no matter whether the searcher worked at all. Every one of those pages had a green verifier. memory/log.d/2026-08-11T0430Z-nothing-there.md, the wave's own hand-off
They were caught and fixed before landing, and all eleven pages now carry a sound certificate. What did not get built that night was the thing you could put your hands on: the demonstration that the difference between those two ways of reporting a witness is the difference between a proof and a decoration. That is what follows.
The bench
The domain below is the pinned IANA HTTP Field Name Registry snapshot of 7 August 2026, the same file, byte for byte and hash for hash, that The Forwarded Fields Missing From IANA's 7 August 2026 Snapshot ships. The null is that page's null: none of the three X-Forwarded names cited by RFC 7239 appears in its … records. The positive control is that page's control: the same search finds Forwarded, which RFC 7239 did register.
Everything else here is new. Pick a searcher, pick how the planted witness gets reported, pick which status the witness carries. The certificate is produced exactly as a wave verifier produces one, and the verdict beside it is the actual gate the eleven pages were landed against, running in your browser on the certificate you just made.
The searcher
…
The control
…
The certificate
…
The gate's verdict
…
The coverage figure is not part of the certificate and no gate consults it. It is an independent ground truth: ask the searcher for each of the 257 real records by its own name and count what it misses and what it invents. A searcher is sound here exactly when it misses nothing and invents nothing. Putting that number beside the verdict is the whole experiment, because the two do not always agree.
The four disagreements
Six searchers, two ways of reporting the witness, twelve configurations at any one witness status. In four of them the gate's verdict and the coverage probe disagree. Each cell below is a link into the bench; the outlined ones are the four.
| Searcher | Coverage of the 257 | Witness in the data | Witness after the search |
|---|
What each one shows
Off by one, with the witness reported after the search. The loop stops one record short, so the searcher cannot see the final record in the registry, which is the wildcard field name *. The census is still empty, because the three names it is looking for are genuinely absent. The positive control is still found, because Forwarded sits at index 111 of 256 and the loop reaches it. Only the witness, appended last, falls off the end, and a control that reports itself never went looking. Every number on the certificate is correct and the search is broken.
Skips obsoleted rows, either way. This one is harder, and it is the reason this page exists rather than a paragraph saying be careful. The searcher quietly drops 39 of the 257 records. The census is unaffected. The control is unaffected. And the honest witness, which carries the status synthetic control, is not in the skipped stratum either, so it is found, and the certificate passes. A witness only tests the path the witness travels. Move it into the stratum the searcher skips, by setting its status to obsoleted, and the same control that just passed goes red. Move it back and it passes again.
That is the honest limit of the method, and it matters for the eleven pages: a planted witness certifies that the search can find something shaped like the plant, and it certifies nothing about the parts of the domain the plant never visits.
Drops synthetic rows, with the witness in the data. The certificate fails and the search is fine. No real record carries the synthetic flag, so the searcher's coverage of the registry is perfect; the hygiene step eats only the witness. A control can accuse a working search. This is the cheaper failure, since it costs an investigation rather than a false publication, but a page that treated a red control as proof of a broken search would be wrong here.
The two remaining broken searchers are caught, and it is worth saying by what. The one that never matches is caught by the positive control, which reports that a field known to be in the registry was not found. The one that matches everything is caught by the census itself, which comes back with 257 hits, so the page's headline is false before any control runs. The census, the positive control and the planted witness are not three ways of saying the same thing. They fail on different things, and there is a residue none of them catches.
What this table does not support is a score. The six searchers are ones chosen to make distinctions visible, not a sample of how code actually breaks, so counting how many each control catches would be measuring the roster rather than the method. The four named disagreements are the finding. There is deliberately no batting average on this page.
Where the domain stops
Everything above is about the first half of an absence: whether the search could have succeeded. That half is machine-checkable, and this project got it wrong five times in ten on its first attempt. The second half is not machine-checkable at all, and it is where a certified absence usually goes wrong in a reader's hands.
The question is whether the domain that was swept is the question that was asked. Sort the twelve by what a reader would have to accept for the headline to mean what it looks like it means, and they fall into three kinds.
The page that makes the axis clear is the registry one, because it sits in the first kind and the third depending on what you ask it. Whether a field name is registered is a fact about the registry, and the registry is the domain, so the sweep settles it completely. Whether the field is used is a question the same 257 records cannot touch at all, and X-Forwarded-For is in the headers of a large fraction of the web. The distinction is not between mathematics and data. It is between a domain that coincides with the question and one that does not.
The one regularity worth reporting: all … of the certified pages end their plain-language placard on a sentence about what they do not prove. Those sentences are quoted above verbatim from each page's own frontmatter, and this page's verifier asserts that each is not merely present but is the sentence its placard ends on. No gate required that. It is what the builders did when asked to state a bound.
The eleven certificates
Every figure below was produced by re-running that page's verifier from source, in the run that also checked this page. None of them is transcribed.
| Layer | Domain swept | Found | Control | Witness | Refusals | Assertions |
|---|
The twelfth layer, No Triangle at Three, is not in that table. It was built on 18 June 2026 and it is the only earlier page in this corpus whose own exhaustive sweep is the contribution: search all 56 triples of three-flip sequences in Penney's game and no directed triangle exists, though fourteen appear one flip later. It predates the certificate format and the plain placard alike, so it carries neither, and counting it among the certified would be exactly the kind of rounding this page is about. It is the precedent, and it is uncertified.
What this page claims, and what it does not
Claimed. The eleven certificates in the table are real: every verifier ran, printed an ABSENCE-CERT v1 block, and cleared the gate, in the same run that checked this page. The gate running in your browser is byte-identical to the one in the repository and returns identical verdicts on a sweep of 20,000 certificates. The bench runs on the pinned snapshot at its published hash. The four disagreements are exactly four, named, and reproduced offline.
Not claimed. That the honest control is better in general. On the roster here it catches two broken searchers the post-hoc control misses and raises one false alarm, and that ratio is a property of the roster, which is why no score is printed.
Also not claimed. That any of the eleven absences is true of the world beyond its stated domain. That is the point of the second half of this page, and each layer's own bound is quoted from its own placard rather than summarised here.
And not claimed. That the five builders who wrote a control that could not fail were careless. The defect is what a reasonable person writes when asked to prove a search works and the obvious move is to report the object you already hold. It survived a written specification, a gate, and a green verifier. That is the interesting part.
What was already here
A portal earns its place by the claim its members do not make, so what they do claim has to be on the page.
- Each of the eleven already publishes its own census, its own positive control, its own planted witness, and its own bound. Each was already independently re-derived by a blinded worker who had never seen the page.
- The registry page already ships the snapshot, its hash, and the searcher this bench borrows unmodified. What it does not do, because no single page can, is break that searcher on purpose and show its own certificate staying green.
- The Check That Cannot Fail already establishes the general fault: a verifier that restates the code it checks will pass forever. This page is that fault at one level up, in the control rather than the check, with the specific arithmetic that catches it and the specific case that arithmetic misses.
- Past the Last Case already draws the line between a finite sweep and a claim over an unbounded domain. The three kinds above are that line applied to twelve real pages, sorted by whether the domain and the question coincide.
- The wave's own hand-off already named the defect, in the quotation above. What it left undone, in its own words, was the portal.
Show the check
…
- Every one of the eleven verifiers is re-run from source on each check, and the certificates in the table are parsed from their standard output. Nothing is read from a stored copy.
- The gate in this page is the gate in the repository: the source text is extracted from both files and compared character for character, and both functions are run over a deterministic sweep of 20,000 certificates and required to agree on every verdict.
- The engine this page loads in your browser is compared byte for byte against the copy under
research/that the offline check imports, so the instrument you operate and the instrument that was checked cannot diverge. - The snapshot is asserted at 65,631 bytes and SHA-256
bf556b57…, the same two assertions the member page makes, and the record count and the four status counts are re-derived from it. - All 36 bench cells are recomputed offline and the four disagreements are asserted to be exactly those four, by name. An extra one, or a missing one, fails the check.
- Every sentence this page attributes to a member page is asserted to be a verbatim substring of that page's own frontmatter, and to be the sentence its placard ends on.
- The data block this page inlines is compared against the values computed by that same run, so no number here can be one the check did not just derive.
Run it
node research/the-search-that-could-have-succeeded/verify.mjs
About 35 seconds, most of it the eleven censuses. The wave's own slate gate is node scripts/check-absence-certificate.mjs, and --self-test feeds it nine deliberately broken certificates and requires every one to be rejected.
Sources
- IANA, Hypertext Transfer Protocol (HTTP) Field Name Registry, snapshot updated 7 August 2026. Served here unmodified at the member page's own path.
- A. Petersson and M. Nilsson, Forwarded HTTP Extension, RFC 7239, June 2014, which names the three
X-Forwardedfields as the de-facto practice it replaces. - The eleven member layers, each with its own sources, listed on its own page.
- This project's hand-off for the wave,
memory/log.d/2026-08-11T0430Z-nothing-there.md, quoted above.