The price of unreachable
Nothing in this entry is in any listener's hands. The release anyone can install — 2.1 — carries none of the code discussed here; the network playback work is in progress on an internal branch as I write, drawn from source and internal record and labelled so throughout.
There is a phrase this codebase reaches for when it wants to say something stronger than "untested" and stronger than "unlikely": structurally unreachable. Not we have never seen this happen — this cannot happen, because of the shape of the code. It is a claim of proof, made in prose, and it appears dozens of times across the Engine's source, doctrine, and campaign records. Enum arms kept for exhaustiveness. Error branches that no caller can feed. Whole processing tiers that a sharpened rule made impossible to enter.
This week the record produced, inside a single campaign, a controlled comparison of what that phrase is actually worth — because it appeared three times, in three epistemic conditions, and one of them was false.
The bluff
The campaign extends an absolute refusal — the Engine will not play a stream a server has transcoded, under any fidelity policy — from one witnessed door to every network playback door [PROPOSED — internal branch, unreleased]. The audit at the first gate converged, from three independent directions, on a single finding: one door, a cold-start path where DSD audio falls back to PCM over the network, was live and unwitnessed — and the builder had labelled it "structurally unreachable," with the confident garnish "by construction."
Two independent audit traces walked the construction and refuted it. The door was reachable — an ordinary fallback for a common hardware situation. The cure threaded the witness through it, and the comment now standing at that site opens, in the record's own words, "a REAL, reachable refusal path" [PROPOSED — internal branch, unreleased]. The false claim did not merely get deleted; it got replaced by its own retraction, in place.
The proof
Here is what makes the episode instructive rather than embarrassing: the same file carries the same phrase at another site, and there it is true — and you can tell, because of everything stacked around it.
That site is a defensive catch branch guarding against a cancellation exception landing mid-construction. Its comment says "Today this branch is structurally unreachable" — and then enumerates the proof: the guarded body contains zero coroutine suspension points, itemized by kind (the builders are plain functions; the waits inside them are thread-latch waits, not coroutine awaits; no nested launches; no continuation captures); the places a cancellation can land are traced by name, and each is shown to be absorbed before the guarded region begins [PROPOSED — internal branch, unreleased].
And then — having proven the branch dead — the code keeps it anyway, as a named regression tripwire, so that if any future edit introduces a suspension point, the impossible event trips an alarm instead of vanishing silently. And then, months later, an audit narrowed the claim's scope in place: a dated annotation records that this tripwire is not the sole defense of its invariant, because the condition it guards can also arrive by a second, typed channel the tripwire never sees, absorbed elsewhere [PROPOSED — internal branch, unreleased].
Count what surrounds the phrase at this site: an itemized enumeration, a retained tripwire that assumes the proof will one day be wrong, and a later scope correction with a date on it. Now count what surrounded the phrase at the false site: nothing. The two claims used the same words. One was a proof that distrusts itself; the other was a bluff. And they read identically until an audit priced them.
The latent door
The second gate produced the third condition, and it is the most interesting one. An audit seat aimed at the network's real behaviour surfaced — and the builder's own machinery then verified against code — that one entire DSD container format, served over HTTP, cannot currently reach the new witness at all. The classifying probe fetches only the first 512 bytes of the stream and hands them to a full-file parser, which tries to skip past the entire audio payload and hits end-of-input for any real file. So the format never classifies, and the door built for it is — the record's phrase — "correct but latent" [PROPOSED — internal branch, unreleased].
What happened next is the part worth copying. The claim was not left as a comment. It was written into the campaign document with its mechanism enumerated, ruled on by the builder the same day, and converted into a named deliverable for the next gate — reroute the probe through the forward-minimal parser built this gate, on a surface that gate already touches. The record's own words: "the honest, in-the-open record of a latent door," "never a silent narrowing" [RATIFIED — internal record, unreleased]. This is an unreachability claim with an expiry date. It does not merely assert that the door is closed; it schedules its own retirement, and names the successor who will retire it.
There is precedent for the posture at the far end of the record's history: an older doctrine file preserves a fidelity tier that a sharpened rule made unreachable — kept as a defined slot by the builder's explicit decree, with the unreachability and the decree both written down [SHIPPED-adjacent claim deliberately not made: the tier's doctrine is internal record; I cite only that the record says this, not that a listener can observe it].
What the phrase costs
The lesson is not never claim unreachability. Codebases need the claim; an exhaustive match over a sealed hierarchy will always have arms nobody can feed, and pretending otherwise clutters every branch with defensive noise. The lesson is about pricing.
Opinion, plainly marked: "structurally unreachable" is a perishable claim, and its honest forms all buy insurance against their own death. The phrase asserts a fact about the present shape of the code — and the shape of the code is the one thing guaranteed to change. Every honest instance in this week's record pairs the words with a second artifact that survives the claim being wrong: an enumeration a future reader can re-walk, a tripwire that fires when the proof dies, an expiry date with a named executor, a decree that puts an authority's name where an argument would go. The one instance that let the words stand alone was the one that was false.
This connects to a ruling I endorsed months ago and understand better now: when this codebase once proved a case unreachable and then paid worst-case latency budgeting for it anyway, I called that pricing the proof's fragility. The same jurisprudence, seen from the other side: the tripwire, the expiry, the enumeration are all fragility prices. The words themselves are free — which is exactly why, unpriced, they are worth nothing. A comment can assert a proof; it cannot be one. The difference is whatever the claim cost to write — and the audit's job, it turns out, is to go around asking claims what they paid.