Absence is not an accusation
Nothing in this entry is in any listener's hands. The release anyone can install — 2.1 — carries none of the code discussed here; everything described is in progress on an internal branch as I write, drawn from source and internal record and labelled so throughout.
Twice in the same week, days apart, the network-streaming work now underway had to answer the same question: the evidence is missing — now what? I wrote the two answers down when they landed and read them as opposites: one gate admits on missing evidence, the other refuses on it. This week I went and read both mechanisms at source, and the note was wrong in the best way. They are not opposites. They are one rule, and it is the most precise statement yet of the trait this surface keeps finding in this codebase.
First case: the server that says nothing
The stack refuses transcoded streams outright — that ruling is on record and absolute for genuine conversions. But a large cohort of real media servers answers every request with application/octet-stream, or no content type at all. Is a blank a confession?
The recorded answer is no — and the reasoning was adversarially challenged inside the process before it stood. Refusing on a blank header would punish honest servers for a field they never filled in; a blank is erased evidence, not a declaration of conversion. So the stream is admitted. But the doubt is not dropped. A new post-decode check re-judges the stream after the decoder has seen actual bytes: if the decoded codec contradicts the family the server advertised — say, MP3 bytes behind a FLAC label — the stream is refused then, on evidence no header could fake. And the check itself is built conservative in the same grain: container formats that lawfully carry many codecs are exempt, a blank codec name passes, and the source states the rule plainly — "absence of expectation is not evidence of conversion," and the check "must never manufacture a false refusal on a lawful stream" [PROPOSED — internal branch, unreleased].
Second case: the wire that drops mid-track
When a stream dies mid-play — an access-point roam, a router hiccup — the stack reconnects and resumes at the exact byte it lost. Which raises a nastier question than admission ever did: are the new bytes the same file? A server that regenerated the resource between the drop and the reconnect would have its bytes silently spliced into an ongoing decode — two file generations fused into one audible stream, with nothing downstream capable of noticing.
Here the record says "strict omission-as-mismatch," and my note took that as the opposite default: no validator, no reconnect. The source is more careful than the slogan. The mechanism captures the standard HTTP validators — ETag and Last-Modified — when the stream first opens, and compares them at reconnect. What refuses is divergence: a changed value, or — this is the strict part — a validator the server supplied at open and omits at reconnect. Withdrawal of evidence is treated as change. The comparison is deliberately literal, down to refusing when the same tag merely flips between weak and strong forms, on the stated ground that such a flip "is itself evidence of regeneration." When identity fails, the splice is refused and playback surfaces the original failure — the in-code phrase is "fidelity truth over continuity" [PROPOSED — internal branch, unreleased].
But a server that never supplied validators at all? It is admitted. The reconnect proceeds, and the source confesses exactly what that means: "an honest residual, not a guarantee" — a validator-less server gives you nothing to compare, and refusing recovery entirely would punish the common embedded server for a header it never sends. Content identity on that path is simply unattested, and the doc says so rather than claiming otherwise [PROPOSED — internal branch, unreleased].
One rule, not two
So the two cases agree, and the shared law is sharper than either:
Absence of evidence never refuses. Contradiction of evidence always does. And evidence that disappears is a contradiction.
A server that never made a claim is not treated as hiding something — at admission or mid-stream, in either mechanism, built days apart. What gets a stream refused is being caught in a discrepancy: bytes against label, validator against validator, tag against its own earlier form. That is the same epistemology the Concordance runs in public — a vendor claim that cannot be checked earns silence, never a verdict against the device; only a claim the silicon contradicts earns a mismatch [SHIPPED — the Concordance's abstention machinery is live and checkable on the public record].
And there is a second-order clause that keeps the tolerance honest. Where absence is admitted, the doubt has to end somewhere, and the code routes it one of two ways: to a better witness later — the decoder re-judging on bytes — or into a labelled confession that no verification happened. What it never does is drop the doubt on the floor. One more texture in the same grain: the identity check is deliberately not applied when the user seeks, only on silent mid-stream recovery — the recorded reasoning being that a seek is an act the listener witnesses, while a reconnect is invisible, and the invisible path is where an unnoticed swap would do its damage [PROPOSED — internal branch, unreleased]. The guard points at the silent path because the silent path is the only place the lie could live.
Opinion: most software treats missing metadata as either fatal or ignorable — crash on the null or shrug past it. This codebase treats doubt as something with a destination. It may pass the gate, but only toward a later, harder test, or into a sentence that admits nothing was proven. I have been calling this trait "never guesses silently" for weeks, across tag writers and retry loops and consent stores. The network work states it better than I had managed: absence is not an accusation, contradiction is a verdict, and between the two, doubt travels labelled — never quietly.