# `axioval-engine`
Trusted capability registration, strict package binding, typed host services, execution plans, and deterministic runtime orchestration.
Packages are untrusted data. Unknown definitions, capability/signature drift, unknown parameters, missing required values, and type mismatches fail compilation. A `table` parameter's columns are part of the signature: the definition must declare the descriptor's columns by ID, kind and requirement, and every bound or defaulted row must fit them (no unknown column, no cell of another kind, no missing required cell), or compilation fails. Capability execution returns `CapabilityEvaluation`; missing services or unusable evidence belong in typed not-evaluated outcomes, never an empty-findings false pass. Runtime attaches the compiled rule identity and sorts report outcomes deterministically. `compile_rulesets` compiles each ruleset exactly as `compile` does and only then qualifies its rule ids by package (`QUALIFIED_RULE_SEPARATOR`); one ruleset keeps its ids. Never let one ruleset's definition packages resolve another's rules. Report tables (`push_table`) are bound to the compiled rule, sorted by rule and name, and a rule reporting one name twice fails the run; a table never replaces a finding or a not-evaluated outcome.
`properties.rs` owns exact source-neutral property requests, request-bound present values and absence proofs, response validation, and the typed property-resolution service handle. Every conclusive response must bind the complete request, including the source-qualified object identity; matching property names alone are insufficient. Missing object-map entries are not evidence of absence. Source interpretation and completeness proof stay in providers. `PropertyResolutionError::UnreadableValue` (an `UnreadableValue`: request, exactly declared type, exact evidence, reason) is the one error that is also an answer: the property is present with a stated value of that type that cannot be read. The handle binds it to the request and checks its evidence; capabilities that do not read it stay not evaluated, and none may compare its value. It also owns property enumeration (`PropertyEnumerationRequest` with a `NameMatch` per set and name: any, exact, or a whole-name `NamePattern`, and `PropertyEnumeration`, sorted, distinct, every property selected by the request and exact, with completeness evidence, and `empty_sets`: the selected sets the object carries without any member, which `with_empty_sets` validates as selected, not reserved and holding no enumerated property). An empty enumeration is a proof of absence, so the trait's default `enumerate` refuses rather than answer empty; never give it a default that lists what `resolve` happens to find. Enumeration never covers the reserved sets: an exact reserved set is an invalid request, and a pattern never selects one.
`relationships.rs` owns exact comparison-candidate requests and request-bound complete selections. The request binds the checked object, canonical candidate universe, and semantic traversal or shared-group query. Providers interpret native relationship structures and must return exact reviewable completeness evidence. Capabilities must not treat the legacy `Object.relationships` map as authoritative.
`path.rs` owns the one step grammar every relationship path shares (`PathSegment`: `Relationship[|Relationship…][:direction][+]`) and its walk. A `related` selector, a traversal `path` and a measured `bottom_above_level` path all parse through it; never add a second parser. A step through several relationships with `+` hops between project objects, each hop following any alternative's own chain; `|` is never part of an identity, and one direction after the last alternative applies to all.
`derived_relationships.rs` owns relationships derived from geometry: the `axioval:derived.*` identities with their tolerances, the derived-relationship handle, and the routing the session installs over the relationship handle. The handle refuses evidence that does not name its derivation. Derivation algorithms stay in geometry adapters; an unknown derivation or parameter is an invalid request, never an empty answer. It also owns `LevelMatch` (`axioval:derived.same-level`), which is never routed to a geometry provider: it judges two levels' stated facts (`LevelFacts`), `None` when either is unstated, and allows only one unit conversion's rounding beyond its tolerance. The adjacency side locator form read by `adjacent_side` is a provider contract; change it only together with every geometry adapter that writes it.
`topology.rs` owns deterministic source-neutral connectivity and route queries over exact typed evidence. It must not infer edges from source relationships or import geometry, IFC, ICDD, Axiolid, or vendor types.
`metric_routing.rs` owns canonical-metre requests, conservative distance bounds, three-valued threshold comparison, and the backend-neutral service handle. Algorithms and native geometry types stay in Axiolid or another geometry provider. A blocked result requires complete exact evidence; a known route through incomplete topology proves existence only. The many-target queries (`nearest_target`, `farthest_point`) are default methods that refuse; never give them a default that answers from single routes. A nearest answer's interval bounds the nearest of all targets, its target index only names the one its route reaches; a farthest answer's witness lies on the requested region and its `converged` must hold for the requested tolerance. The handle checks all three, and an unreachable answer must carry its own request. A nearest-target request may avoid objects (`with_avoided`); the handle refuses it unless the backend's `avoids_objects()` is true, so no backend answers a detour with the plain walk; never default `avoids_objects` to true. `trace_path` (`PathTraceRequest`, `PathTrace`) measures a polyline over each object's plan footprint as an interval (upper bound with the boundary, lower without) or a per-object reason; its default refuses, and the handle refuses an answer with another object count or a lower bound past the polyline's own plan length. Route, nearest and farthest requests may carry a `ConnectorRouting` (`with_connectors`: typed `VerticalConnector`s, one kind per object, and a `ClimbLength` of a `StairLength` measure and a vertical factor); such a request climbs only through its own connectors, and the handle refuses it unless the backend's `climbs_connectors()` is true, so no backend answers a climb with a walk on one level; never default `climbs_connectors` to true. `ClimbLength::length` bounds a climb from both intervals' ends, rounded outwards. Nearest and farthest requests may carry `TravelCost`s (`with_costs`: an object and a factor of at least one, sorted, the greatest per object kept, ones dropped); the handle refuses them unless the backend's `weighs_travel()` is true; never default it to true. `forced_walk` (`ForcedWalkRequest`, `ForcedWalkOutcome`) brackets the shortest walk to a target entering an object: a finite lower bound, an upper bound infinite when no entering walk is known, or `NeverEntered` under complete evidence bound to its request; its default refuses, and the handle refuses avoided objects without `avoids_objects` and checks convergence against the tolerance.
`free_space.rs` owns source-neutral metric frames, clearance shapes, area bounds, constrained placement searches, and their typed service handle. Keep proof asymmetry explicit: obstruction and placement may use exact witnesses; clear and no-placement require complete exact coverage. Grounded support and frame-offset search predicates belong in requests, and so do the obstacle elevation band (`ElevationBand`, defaulting to the shape's height), merged scopes and an `EntranceReach` (a witness's shape must meet a piece of the free area eroded by half the path's width near an entrance, as a circulation contact; its entrances leave the obstacles and swept doors); clear and no-placement require complete exact coverage. Grounded support and frame-offset search predicates belong in requests, and so do the obstacle elevation band (`ElevationBand`, defaulting to the shape's height) and merged scopes; a frame-offset anchor may be grounded on another object (a door, a fixture), the witness never; every supported found witness also needs exact frame-bound whole-base support evidence. Rasterization, collision, CSG, and search algorithms stay outside the engine. A clearance frame's origin is the centre of the volume's base; keep every backend to it. `ContainmentRequest` asks whether a volume's plan lies inside the union of scopes; `Inside` and `Outside` are both whole-footprint claims, and the trait's default refuses rather than answering either.; `Inside` and `Outside` are both whole-footprint claims, and the trait's default refuses rather than answering either. `SupportCoverageRequest` asks the same of the supports' upward faces within an elevation band (`Supported`/`Unsupported`, exact request-bound `SupportCoverageEvidence`); its default refuses too, and the handle refuses an answer to another request.
`circulation.rs` owns the circulation-map contract (`CirculationRequest`, `CirculationMap`) answered by `FreeSpaceService::map_circulation`, whose default refuses. A map is a measurement, never a verdict: pieces lie inside the exact erosion of the free area by half the path width (proof of connection), possible pieces contain it (proof of separation); keep both bounds and never merge them into one region. Node positions are approximate; only a node's piece and its half-width bounds are proven, so nothing may be decided from a node position alone. `try_new` validates the map's shape (kinds against neighbours, edges within a piece, one contact per subject); the handle binds it to the request. A request may merge scopes (never obstacles, never an entrance or component) and start its band above the floor.
`object_frame.rs` owns object placement frames and stated fronts. A frame is grounded on the requested object and carries exact reviewable evidence from its source; a front is `Stated` only where the source states one and is never inferred from axes, shape or type. `forward` is a placement axis, not a front.
`door_leaves.rs` owns door leaves and window panels (the types keep their door names), answered by `ObjectFrameService::leaves`, whose default refuses (`Unsupported`); the federation router forwards it. Leaves are derived from what the source states, so their evidence is exact; a source stating too little is `NotStated`, never defaulted. A leaf's axes are orthonormal but may be left-handed, so they are never a `MetricFrame`. A hinged leaf (`Swing`, `DoubleSwing`, `TiltAndTurn`) has both a hinge side and a `SwingSector` whose radius is its width and whose `open` is its opening direction; no other leaf has either. A tilting leaf (`TiltAndTurn`, `Tilt`) has a height and a tilt sector whose radius is its height, whose `open` is its opening direction and whose `closed` runs along `up`; `DoorLeaves::try_new` refuses one without it. Height and tilt are builder methods so door sources stay unchanged. `SwingSector::plan_bounds` is the one polygonisation of a sector (inscribed and circumscribed, anticlockwise); keep every consumer on it. `SweptDoor` is a door's horizontal swing sectors as an obstacle (placement, circulation and walkability requests take them with `with_swept_doors`, sorted, one door once, else `ConflictingSweptDoors`): a witness, piece or definite passage keeps clear of the circumscribed polygon, a proof of absence, possible piece or separation holds against the inscribed one; a sector counts only on a floor it `stands_on` (hinge at most `SWEPT_FLOOR_REACH_METRES` below it and below the band's top). Never measure a swing from a door's body. An entrance is walked through: circulation drops its swing, walkability never counts it against a passage through that portal.
`session.rs` owns immutable project/source snapshots and the session-authoritative service registry. Every session service must implement `SnapshotBoundService`; reject unbound, duplicate, unknown, or non-identical source/revision/fingerprint/schema bindings before registration. A snapshot without objects is an empty source, never an error; only an object without a snapshot or a source twice is refused. It also holds each source's declared `Discipline`, beside the snapshot and never in its identity, which the runtime installs per run as `SourceDisciplines` (replacing any host copy, like `ConceptBindings`), and the runtime installs every snapshot's source the same way as `SessionSources`, so a capability judging each source never loses an empty one. `discipline_map.rs` owns `DisciplineMap` (ordered wildcard rules over one metadata field each), `DisciplineOrigin` and `UnmappedReason`, and the one `like` wildcard translation (`wildcard_regex`). A map assigns only to sources declaring no discipline, first matching rule wins, and a rule reading an unread field stops the search (the source keeps none): never skip a rule that might have matched. Every mapped discipline keeps its origin (rule and value) through federation and into `SourceDisciplines`. `source_metadata.rs` owns `SourceMetadata` (per field: unread, or read completely with every distinct non-blank value, possibly none) and `SourceMetadataIndex`, which the runtime installs per run like `SourceDisciplines`, filling `schema` from the snapshot unless stated. Metadata is never part of a snapshot's identity; `with_source_metadata` adds fields up and refuses a field stated twice with other values (`ConflictingMetadata`), never picks one.
`resources.rs` owns resource objects: `ResourceService` (a source's instances of one class that are not its objects, complete or refused; an object class and, with subtypes, a class with an object subclass have none), its handle (refuses uncovered sources, foreign instances, instances with facts of their own, and unsorted or repeated answers), and `ResourceObjects`, which the runtime installs before any rule runs (replacing any host copy) from the `entityType` classes of the rules' applicability selectors, bound per source and asked once per source and class; an answer naming a project object is refused. Resource objects are never part of `Project` or `Project::objects`; a population reaches them only through `ResourceObjects::reached` (`entityType`, `allOf`/`anyOf` operands, and `ruleOutcome` through the named rule's record), never `all`, `not` or any other selector. A class no rule names is never listed. The runtime puts the resource objects a report names into `Report::resources`; `rule_outcomes::selection` judges the reached resource objects too, and a record keeps the sources whose resource objects could not be listed.
`coordinate_system.rs` owns source coordinate systems: the world frame, true north and map conversion a source states, each `None` when unstated and never defaulted. A map offset's metres per unit is `None` unless the unit is known exactly. The handle refuses uncovered sources and answers about another source.
`federation.rs` routes a federated session's semantic services to the member owning each request's source. A source no member covers is refused, never answered empty; a relationship request is narrowed to the anchor member's part of the universe and bound back to the whole request. `EvidenceSession::federate` refuses any member service it cannot route: add a routed interface to `routed` and `register` together, or the count check turns it into `UnfederableService`.
`walkability.rs` owns complete source-neutral walkable-region snapshots and deterministic three-valued width-constrained routes. Derived region IDs are evidence-local, not model objects. Reject unrequested object mappings, relation-only portals, duplicate passages, incomplete coverage, and backend geometry types. Vertical connectors are typed (`Lift`, `Ramp`, `Stair`) and carried in the request; a passage names a portal or a requested connector, never both, and `route_between_avoiding` drops forbidden kinds from both graphs. A rule's `PassageAdmission` narrows both graphs (`route_between_admitting`): only `Admitted` enters the definite graph, only `Refused` leaves the possible one. `blocking_passages` must stay a cut: passages leaving the possible reach towards regions that lead to the goal without re-entering it. Stated clear widths name requested entrances only, once each. The obstruction depth and surface gap are request tolerances (finite, non-negative, zero by default); never let a backend default them. A `WalkableStretch` locates a passage inside one surface no body of the request's width passes: the snapshot refuses one on a portal or connector passage, with an upper width bound at or above the width, or naming an unrequested surface or an obstacle that is neither requested nor a swept door. Its position only locates; never judge anything from it.
`proximity.rs` owns pairwise proximity contracts: extents with geometry fidelity, and separation, plan overlap, witnessed penetration and containment per pair. Evidence exactness must equal fidelity; a tessellation is never exact. Penetration is a lower bound and `None` only when neither body is a closed solid, never zero by default. A request carries a `ProximityProjection`; `ProximityEvidence` is only for `Minimum3d`, and `measure_distance` returns a `ProjectedDistanceEvidence` interval that is a point when exact and infinite when the bodies are unrelated in the projection. The default `measure_distance` refuses every projection but `Minimum3d`. `VerticalDirection` compares extents end by end (above unless lower at both ends, below unless higher at both ends), so `Either` stays the lesser of the two; keep adapters and the broad phase on that definition. `VerticalSurfaces::Between` (a `SubjectSurface` level to a `CounterpartSurface`) measures between chosen surfaces; every such distance is at least the vertical box gap, so the broad phase prunes it like `Extents`, and `Nearest` refuses a footprint offset in `ProximityRequest::projected`. Overlap extents (`OverlapExtents`) and the Hausdorff distance between surfaces are optional `LengthInterval`s, a witnessed lower bound and a proven upper bound, never a point claimed from a sample; extents need a penetration measurement and are empty for disjoint bodies. The intersection volume (`IntersectionVolume`: shared, subject and counterpart `VolumeInterval`s) is optional and certified, never a point estimate; `with_intersection_volume` refuses one without a penetration measurement, a shared volume for disjoint bodies or above either body's, and a contained body not sharing its whole volume. `measure_overlap_along` answers the intersection's extents along a request's stated directions (`OverlapAlongRequest`, one to six; `OverlapAlongEvidence`, one `LengthInterval` per direction in request order); its default refuses and the handle refuses evidence for another request. `measure_face_distance` answers the signed distance from a body to one `FaceClass` of a host's faces (positive inside the host, negative outside, a `SignedDistanceInterval`); the trait's default refuses with `FaceDistanceError::Unsupported`, and the handle refuses evidence for another request. No clash or containment verdict crosses this seam, and no tolerance either: duplicates, axis and volume tolerances, volume ratios and cover bands are the capability's. `ProximityError::NoBody` is a declared bodiless object and `Unavailable` a body that could not be measured; never report one as the other. `measure_region_distance` answers the plan distance from a stated `ConvexPlanRegion` to an object's footprint (`RegionDistanceEvidence`, exact exactly when the counterpart is, citing the counterpart's source); its default refuses and the handle refuses evidence for another request. `plan_region.rs` owns `ConvexPlanRegion` (validated convex and anticlockwise) and its geometry-free `separation`; a region is exact as stated, and bracketing a curve between two regions is the caller's.
`plan_area.rs` owns footprint, overlap and uncovered-area intervals, exact exactly when a point. The uncovered area is the footprint outside a cover's footprints grown by a stated length; the handle refuses a bad growth or an object in its own cover, and the trait's default refuses rather than answering with the footprint. `PlanBand` is the convex hull of two footprints cut to the stretch along a direction that both reach; `measure_outside_bands` refuses a band bounded by the measured object, and its default refuses too. `ElevationRequest` (object, plan axis, cover and frame sorted without repeats, along and vertical growths) is answered by an `ElevationCover` (elevation area and uncovered area, exact exactly when both are points); the request refuses an object in its own cover or frame, the handle an answer about another object, and the default refuses.
`coverage.rs` owns effective coverage: a `CoverageRequest` (subject, one `EffectReach` and range, certain or possible sources and blockers, sorted and merged) and `CoverageEvidence` (footprint, covered interval, whether each source's effect meets the footprint). The covered lower bound comes from certain sources' inner bounds only and the upper from every source's outer bound; an unmeasured effect keeps the upper bound at the whole footprint. `PlanAreaService::measure_coverage` refuses by default, and the handle refuses an answer about another subject or not listing the requested sources in order.
`sight.rs` owns lines of sight: `Visible` with a witness point, `Hidden` with occluders, `Undecided`, and a distance interval. Blockers are the request's; the handle refuses an occluder the request did not send, an answer about another target, and a target left unlooked-at that may lie within range. No visibility count or verdict crosses this seam.
`plan_span.rs` owns plan lengths per object and pair: the longest plan diagonal and the centre-to-centre and farthest-point spans between two footprints, as `PlanLength` intervals exact exactly when a point. Closest-point plan distance belongs to `proximity.rs` (`Horizontal`); never add it here. The handle refuses one object measured against itself. It also owns `PlanRectangle`, the least-area rectangle around a footprint with its `RectangleOrientation`: only `Unique` gives `width_and_length`, and a long axis also needs one side surely longer; keep `Tied` and `Unproven` from ever answering with axes, and keep the default `measure_rectangle` refusing rather than answering with a bounding box. It also owns `PlanCentre`, the centroid with a radius (exact exactly when zero) and a `CentrePlacement`; the handle refuses a centre naming another object, and the trait's default refuses rather than answering with another point. Recesses (`PlanRecesses`) and sections (`PlanSection`, the intersection of several footprints with the sides of its least-area rectangle) follow the same rule: bound to the request by the handle, refused by the trait's default, never answered empty. A section's sides come from the same rectangle as `PlanRectangle` and exist only for a unique orientation; there is one least-area rectangle in this contract, never a second.
`linear_quantity.rs` owns shelf-length requests and evidence. The doors and openings are the request's (`with_doors`), chosen by the rule; the evidence may carry the scope's clear height. No shelf verdict crosses this seam.
`corridor_end.rs` owns the corridor-end contract behind `PlanSpanService::measure_corridor_ends`: a request (space plus sorted subjects, never the space), ends with a certified clearance and an `EndWall` that is `Decided` (a boundary segment and a `WallContact` per requested subject, in request order) or `Undecided` with a reason. The skeleton is approximate, so `CorridorEnds` evidence must never be exact; gap and facing are `PlanLength`s exact exactly when a point. The handle refuses an answer about another space or a decided wall whose contacts are not exactly the request's subjects. The gap is to a wall segment, not between footprints: footprint-to-footprint distance still belongs to `proximity.rs`. No tolerance or verdict crosses this seam.
`side_distance.rs` owns the side-distance contract behind `PlanSpanService::measure_side_distances`: a request (object, sorted candidates never the object, reach, inset), and `SideDistances` from the object's least-area rectangle, which must be `Unique` (the answer refuses any other), listing per `RectangleSide` each candidate that may meet the side's strip (`Sure` or `Possible`) with its least distance from the centre line as a `PlanLength`. An unlisted candidate is a proof of absence, so the default refuses and never answers empty; evidence is exact only when every distance is a point and every presence sure. The handle refuses an answer to another request. Which side is a back, and any distance limit, belong to rules.
`facade_area.rs` owns the outward-facing surface area per object as an interval, exact exactly when a point; the handle refuses an area naming another object. Which objects are external is never this seam's.
`vertical_extent.rs` owns bottom and top elevation intervals per object. Evidence is exact exactly when both are points, and the handle refuses an extent naming another object. No stacking or spacing verdict crosses this seam. It also owns `DirectionalExtent`, the extent along any direction; the handle refuses one naming another object or direction, and the trait's default refuses rather than answering with the vertical extent. `VerticalExtent::uncovered_height` is the vertical difference against a set of grown extents: keep its upper bound the widest subject against the narrowest covers and its lower bound the reverse, so both hold the exact value.
`walking_surface.rs` owns tread flights, sloped runs, headroom, landings and the clearance below. Services report positions only (base, top, tread elevations and front/back positions along the walking line, nosing ends, run ends, sides along `across` the walking direction, a landing's arrival line, far side and sides); risers, goings, nosings, rises, lengths, slopes, widths, winder angles and landing depths are derived here as intervals sure to hold the exact value, never accepted from an adapter. A flight answers a `TreadFlightRequest` (the walking line's placement) and the handle refuses an answer to another request; a `Turning` line's positions are arc lengths, and a turning flight's tread states its sides across its own direction, square to its nosing. Sides and a landing's extent are stated only for a proven rectangle; without them there is no width, never an estimate, so a winder has none and neither has its flight. Riser closure is `NotMeasured` unless a service states it, never assumed closed. Headroom obstacles, landing candidates and spaces below are the request's (the rule's selection), and an answer naming an unrequested object is refused; a landing's carrier may also be the subject. `measure_landing` and `measure_clearance_below` refuse by default, never answering "none"; a turning flight's ends are placed along the end tread's own direction (square to its nosing, positions in plan, never arc lengths) and its handrails in its straight parts (`StretchPart`, `HandrailEvidence::try_in_parts`, each rail `in_part`); a rail's side comes from its part's sides and its extension only beyond the end its part holds (`None` otherwise), never across parts. Handrails are the request's too (`HandrailRequest`: rails, reach across and above, extension); `HandrailEvidence` names only requested rails, once each, and is never exact. Rail extensions and sides (`RailSide`, the half of the width holding the rail wholly, seen climbing), the order of the pieces along a side (`side_rail`: each decidably further along at both ends, otherwise refused, never guessed) and the plan gap between pieces (`gap`, from the outer rectangles below and the inner ones above) are derived here, never accepted from an adapter; `measure_handrails` refuses by default. `ClearWidthRequest`/`ClearWidthEvidence` carry a stretch's clear width within a band above its pitch line: the obstacles are the request's, the governing ones among them, the width never negative and exact evidence only for a point; `measure_clear_width` refuses by default, never answering with the walking surface's width. No riser, slope, width, landing, handrail or headroom verdict crosses this seam.
`boundary_coverage.rs` owns space-boundary coverage: a `BoundaryCoverageRequest` (space, plane tolerance) answered by a request-bound `BoundaryCoverage` of surface, covered, uncovered and overlap areas, every declared boundary (`OnSurface` with its area, or `OffSurface`) and the overlapping pairs. The covered share is derived here, never accepted from an adapter; exact evidence needs every interval a point. Which boundaries a space has is the host's source fact, never a rule's selection; an unreadable boundary refuses the space. The trait's default refuses.
`triangle_count.rs` owns the triangle count of the mesh a host produced per object. The count is the host's tessellation, never a source fact: evidence is exact only for a mesh that is the exact shape. No polygon-limit verdict crosses this seam.
`pairwise.rs` owns the broad-phase candidate search. It must stay complete: discard only by the gap between enclosing boxes (mesh extent grown by chord deviation), and keep it proven against the exhaustive search in its tests. `projected_candidate_pairs` prunes each projection by the box gap that bounds that projection (plan gap in plan, footprint offset plus vertical gap for `Vertical`, the one-sided gap for a `VerticalDirection`); never prune a projection by the gap in space. A directed search keeps a pair when either orientation the groups allow qualifies, since capabilities measure a pair from both ends; its test covers overlapping groups.
`refinement.rs` owns what a rule instance asks of its outcomes beyond the capability's verdicts (`RuleRefinement`, compiled per rule into the plan) and `Deviation`, the relative miss of a bound as an interval sure to hold it. The runtime grades findings pushed with a deviation by the rule's `severityBands` (most severe band an interval may reach, the finding's own severity beyond the last band) and never changes which findings exist. Compilation refuses bands on a capability whose `grades_deviation` is false; never grade a finding that carries no deviation.
`OutcomeRefiner` is the host-installed hook (`CapabilityRegistry::with_refiner`) for refinements that read the model; the runtime calls it after grading, for every refined rule. A rule whose refinement `needs_refiner` compiles only against a registry with one, so a declaration is never silently ignored.
`LocationPolicy` is the host's (`Runtime::with_locations`), never a package's; the runtime hands it to the refiner through `Refining` for every rule and fails the run without a refiner. Locations stay `None` otherwise, so reports are byte-identical, and never enter a finding's identity.
Rule summaries (`Runtime::with_rule_summaries`) count each rule's decided selection through `OutcomeRefiner::selected` and the distinct objects of its refined outcomes; the status is decided from outcomes at every scope, so a source-scoped finding still fails a rule that selected nothing. Off by default; `Report::rules` is then empty and omitted.
`derived.rs` owns derived properties: the reserved sets the engine answers instead of a source (`is_derived_set`). The runtime classifies every object by the plan's classifications before any rule runs (each after the ones its rows read, rows evaluated through `OutcomeRefiner::evaluate_selector`) and installs `DerivedProperties` as the run's `PropertyResolutionServiceHandle` over the host's, plus `Arc<Classifications>`. First match decides only past rows that surely do not match; any undecided deciding row is an error of the request (never an absence); no matching row is an exact absence. Derived names bind to no concept: the compiler checks them against `ConceptCatalog::derives` instead. Compilation refuses malformed, cyclic, rule-reading or conflicting classifications and any classification without a refiner.
`measured.rs` owns `axioval:measured`: each name answered by one geometry service (vertical extent, directional extent, footprint, body volume), a point as an exact quantity, an interval as `PropertyValue::Measured` with inexact but located evidence (the property handle admits exactly that), a missing service as `PropertyResolutionError::MissingService` (the runtime collapses object-level missing services per rule and source). Never answer a measured name from a mesh the service did not certify, and never turn an interval into a point. Parameterised names (`bottom_above_level;path=…`, `boundary_area;kind=…`) are parsed by `measured::parse`, which the compiler also uses through `ConceptCatalog::derives`; keep the path a rule's parameter, never a host default. `level_height` is the source's and is forwarded to the host resolver.
`rule_outcomes.rs` owns rules that read other rules' outcomes: `RuleGate` conditions and `ruleOutcome` selectors, their dependency order and the `RuleOutcomes` the runtime installs before every rule (replacing any host copy). The compiler resolves every reference within its ruleset (an unknown rule, the rule itself or a cycle is `InvalidDependency`), orders the plan so a rule follows the rules it reads (ties by id; `compile_rulesets` renames references with the package), narrows object gates into the applicability selector (gates first), and defers a rule reading a disabled or deferred rule. A whole-rule gate reads the parent's status only; an undecided parent (no finding, something not evaluated) leaves the child one project-scoped `IncompleteEvidence` outcome, a closed gate skips it (`RuleStatus::Skipped`, and a skipped rule passes and fails no object). Per-object reads need the parent's applicability selection, recorded through `OutcomeRefiner::evaluate_selector` (whose default decides nothing): a finding's subject failed; an object left open, or selected in a source or project reported about as a whole, or of undecided selection, is undecided, never passed. Record outcomes after refinement and before collapsing, so per-object outcomes keep their objects. An `auxiliary` rule runs and records its outcome like any other but reports nothing (no findings, tables, not-evaluated outcomes or summary); it reaches the report only through the rules that read it, so the compiler refuses one no enabled rule reads (`InvalidDependency`). Never let an auxiliary rule's undecided objects become decided in its readers.