LOADOUT_SETS_SPEC.md

music/LOADOUT_SETS_SPEC.md

THE LOADOUT SETS SPEC — the design contract the engine implements (REVISED)

CANON SUBORDINATION — this document is PROPOSAL-TIER: it serves canon and never outranks it.
The canon: the CVD · the T1 foundation docs · the T0 registries (registries/) · the spine
(docs/spine/CH_*.md) · the region pages (_source/02_Tier_2_Region_Pages/). Authority order: docs/DOC_MAP.md § 0.
Canon served (scanned from this document's own citations — widen it by hand where it is thin):
CVD §13 · CVD §17 · T1_Ability_Tree · T1_Combat_System_Spec · T1_Integrity_Paths_Worldstates_Master · (+1 more tier) · T0_Bonus_Option_Registry · T0_Bonus_Pool_Registry · T0_Imprint_Affix · T0_Loadout_Set_Definition · (+5 more t0)
READ THAT CANON FIRST — open it and derive from it before you build anything from this document.
If this document disagrees with canon, CANON WINS and this document is the defect — fix the
document, never the canon. Nothing here is applied until it is ratified into canon.

Status: SPEC-ONLY (engine work lands on the 5090). This document closes the named schema-pass

deferrals on the ruled §9/§10 build-agency layer and composes them with the twentieth-sitting

pick-economy ruling. It invents no numerical or naming canon: where a ruling leaves a genuine

fork, §11 presents options with a recommendation and the strongest objection, per the standing

decision protocol.

Revision record — what this pass changed and why

This is revision 2, authored against the fresh-context critic verdict

W3_LOADOUT_SETS.md.verdict.json (GO_WITH_FIXES; 3 MAJOR, 5 MINOR, 2 INFO; 24 quotes opened,

0 fabricated citations, 0 Josh-tier forks silently ruled) and three director rulings issued with

it. Every finding is applied. The changes that alter substance rather than wording:

it on WS_045 at owner_kind=companion and left ratified T1_Integrity §8.11.6 L581 pointing

consumers at WS_027 — two homes for one fact, in the very system that invokes "one writer,

one home." DISCLOSED REVERSAL: the critic's own fix recommended relocating the ratified

pointer to WS_045. The DIRECTOR RULED THE OTHER WAY — the ratified line wins, and this

spec, being the schema pass L581 names, authors the loadout columns AT WS_027 rather than

relocating persistence away from it. The reasoning: a T1 ratified text outranks a T0 mint

under the authority hierarchy, and the same ratified sentence pair already homes familiar

persistence at WS_012 (§8.11.7), so per-owner homing is the ratified pattern rather than a

new one.

display_name_text on T0_Loadout_Set_Definition, which tooth T-A9 cannot see: its scope is

hard-coded to the option and pool tables over PLAYER_SURFACE_COLUMNS

(harness/check_build_space.py L132, L575-577). A player surface outside the firewall is the

repo's "a rule that cannot be made to fire is not armed" class.

predicate: 3 of 11 realm rows carry a delta and two of those three are not suppressions, so

the tooth as written false-reds legal data — the noisy-gate-conceals defect this repo has

already paid for.

director's cross-spec ruling composing this spec with the sibling

RIFT_DUNGEON_SCAFFOLDING_SPEC.md.

false-red is FUTURE-CONDITIONAL and the lever is the selection-input key shape, not

budget_scope; the derived spec-purpose contract is declared UNARMED until its data lands.

addendum §10.6 pointer dropped in favour of §11, which is where the EAM sentence actually is.

No quote changed; every one was verified present and faithfully used.

Authority read (CVD > T1 > T0), every claim below cited to it, anchors re-derived this pass:

(L234-269) — Josh-ruled 2026-07-26, the governing rulings.

Purposes, and Combat Build Sanctums" (L561-580; L581 is the next section's header) — **owns

the loadout mechanic**; and the pick-economy siblings at L502-528.

L11-12; §5A two-currencies L163 and distinct-grants L197; §5B/§5B.1/§5B.2 L200-222; §5H

L493-529; §5I.1 L537-545 (L539 the single-index split, L541 every-level-pays-a-pair, L545 the

schema-pass deferral); §5I.2 L547; §5I.3 L555; §5I.4 L561. **Owns the ability-side selection

state each set carries.**

L543-549, §8.11.5 L561-567, §8.11.6 L569-581, §8.11.7 L583-595, §8.11.8 L597-612, §8.11.9

L616-622, Tier-C cross-cite L721. **Owns parity when the relationship moves, and owns where

ally persistence rides (L581).**

2026-07-28 twentieth sitting, applied at ledger 28z, including the rider at L26: "Gate" reads

LEVEL GATE corpus-wide — no rename pass.

T0_Bonus_Pool_Registry [DRAFT v0.1] (7 rows), T0_Bonus_Option_Registry [DRAFT v0.1]

(12 rows), T0_Spec_Purpose_Registry [DRAFT v0.1] (6 rows), T0_Imprint_Affix [DRAFT v0.1],

T0_Vril_Site_Registry [ACTIVE v0.1] (42 rows), T0_Realm_Ruleset_Registry [DRAFT v0.1]

(10 realm rows + the RLM_0000 baseline), T0_Worldstate_Variables [ACTIVE v0.1] rows WS_012,

WS_027, WS_028, WS_043, WS_044, WS_045, WS_046.

sole-owner note); harness/check_build_space.py (teeth T-A1..T-A13; the not-armed-is-declared

convention L10-15; the fixture convention L769-771); docs/DESIGN_GAP_REGISTER.md L1141-1142

(the live gate_index schema flag).

no-lockout law L93-96; the pocket-interior sanctum rule L464-468 and L634-637).

---

1. What this spec closes

Five ratified texts explicitly route their remaining shape to "the schema pass." This document is

that pass's design contract:

schema pass." → closed at §4 and §5.

the ruling rather than a stated term of it, revisitable at the schema pass." → confirmed at §3.

the schema pass." → held, with the derivations restated as data at §7 and §11 F-1 / F-8.

interim interpretation … pending the schema-pass ratification, which is where the split is

confirmed or redrawn." → confirmed as written at §6, with the two edges it names resolved.

which will carry loadout state alongside the loyalty fields once the schema pass authors the

columns; until that pass lands, no consumer may read a loadout field on WS_027." → **the

columns are authored at §4 and §7.1**, which is what lifts that embargo. §8.11.7's parallel

sentence homes the familiar side at WS_012 alongside the spread.

at §5.

---

2. THE SWAP LINE — the central contract

A loadout set is an assignment over permanent entitlement, never a second copy of the

character. Everything the player *is* stays outside the set; everything the player *chose* rides

inside it. Three strata, each cited:

2.1 PERMANENT — identity, never per-set, never swapped

experience." A set cannot carry a different mastery level.

§5I.4 L561) is character state.

at a trade compound (reagents, multi-day in-game time, faction-standing implications, L~208).

respec'd"; Devices 2/4/6 rebond only through the trade-compound ritual, and "EAM polish moves

with the device."

"Mythic is earned, never dropped … the completed final mastery questline for the capability is

the only source."

"intrinsic to the person and leave with them."

2.2 PER-SET — the swapped payload

T1_Combat §14 (L567): "Each set holds its own gear, its own ability selection, and its own bonus

picks, and quick-changes as a unit rather than piece by piece." That sentence is the ruled

composition, and T0_Loadout_Set_Definition.composition_kinds already states it as data on all

three rows: gear;abilities;bonus_picks. Read exactly:

(WS_046.instance_id), never containers (see §8.4).

runes carried on that equipment" as a property of the equipment. Swapping a set therefore

swaps imprints as a consequence of swapping items, with no separate imprint state and no

re-roll surface (see §8.8).

this build fields: ability_selection_refs[].

loadout_set_id as "the reachability key."

Where those first three fields physically ride depends on the owner, per §4: the player's on

WS_045, a companion's on WS_027, a familiar's on WS_012. The field vocabulary is one

vocabulary; the home is per owner, because that is where the ratified texts put persistence.

2.3 DERIVED — never stored, never swapped as a field

not swap because it is not a stored field. §5I.2 (L547-553): "Spec purposes are already

implicit in the catalog and the pools make them selectable … Spec purposes carry role tags

into §14A. The tagging is what lets the sweeps count builds per role." The purpose refs live on

the *option* row (T0_Bonus_Option_Registry.spec_purpose_refs) and on the *pool* row

(T0_Bonus_Pool_Registry.spec_purpose_refs), so a set's spec purpose is the read of the

purposes carried by the options that set holds. Storing a per-set purpose would mint a second

writer over the same fact and would let a set claim a role its picks do not support — exactly

the mis-attribution the §14A.5 build-space sweeps exist to catch.

seven live pool rows today, so the derived read resolves empty for every set until the

populate lands. The populate is a §7.1 work order, the empty state is declared here rather

than presented as a working contract, and §9's not-armed list names it.

bonus_pick_refs[] = the read of WS_043 … one writer, one home."

2.4 The derivation that keeps §5B.1 alive

The single most consequential reading in this spec, stated so a downstream agent cannot get it

wrong: **the ability selection that swaps is the prepared/equipped set, not the Mastery Point

allocation.**

Grounds. §5A (L197) separates the two economies by design — "Mastery Points and bonus picks are

distinct grants, not competing spends … The player never trades an ability unlock against a

bonus." §5I.1 (L545) then reserves the point layer explicitly: "§5B.1 remains the authority on

point reallocation." If a set carried MP allocations, then a free quick-change at a waterfall

would be an unlimited free Mastery Point respec, and §5B.1's entire cost architecture — reagents

gathered through Herbalism and Alchemy field work, multi-day ritual time, faction-standing

implications, the three canonical free-respec beats at Ch 38 / Ch 55 / post-Ch 77 — would become

dead text that no player would ever pay. Two ratified systems cannot both be true under the other

reading; under this one, both are.

This reading is what the phrase "equipment-and-ability set" means to the player, so it is

surfaced as a confirm-only item at §11 F-10 rather than left as an unflagged inference.

---

3. The pick economy inside a set (composing the twentieth-sitting ruling)

RULED (d), 2026-07-28: **24 picks per developable capability — 12 minor on the twelve levels,

12 major on the twelve level gates; solo-reachable 22** (level 12 Magus is Tier-C MMO only).

T1_Ability_Tree §5I.1 as landed at 28z (L541): "Every level pays a pair … a developable

capability carried to level 12 has taken 24 picks — twelve minor and twelve major"; and L539:

"The split follows the §2 single level index."

Composed with loadout sets, that yields the following invariants.

holds 7 minor and 7 major entitlements in Fire, permanently. Each unlocked set holds its own

independent assignment of those 14 picks. Three sets do not grant 72 picks — they grant three

profiles over the same 24-pick entitlement.

over entitlement, so an assignment that outruns entitlement is a save-corruption class, not a

build. Tooth T-LS-ENTITLEMENT.

T0_Bonus_Option_Registry.exclusion_group and tooth T-A11 evaluate per (capability, level,

lane, set). Two sets holding mutually exclusive options is the feature, not a violation —

it is precisely the "carry more than one selection profile" §5I.1 (L545) names.

applied). The design requirement is unchanged: T0_Bonus_Pool_Registry.pick_budget=1 is a

per-set budget, so three sets each holding one pick at the same (capability, level, lane) is a

legal build. The correction is where that requirement lands in code. Verified implementation:

t_a12(pools, options, selection) (harness/check_build_space.py L624-662) arms a static

clause today and evaluates its held-set sum only when selection state is supplied, keyed on

pool_id, and consults budget_scope solely for the global branch. So (a) with

selection=None the clause is NOT ARMED and cannot false-red anything today, and (b)

re-reading budget_scope=tier does not reach the arithmetic. THE CONTRACT: when the sweep or

gate supplies selection state, it must key it on

(capability_ref, level_index, lane, loadout_set_id) and T-A12's held-set sum must group on

that key. budget_scope=tier documents the per-set intent for human readers; it is not the

mechanism. Stated as a future-conditional defect: without the set dimension in the key, the

first armed run would read a legal three-set build as over budget.

ability unlock against a bonus." Confirming §5A's flagged applied reading: bonus picks cost no

Mastery Points, and a set switch moves no points.

entitled globally and unassigned in every set. Auto-filling it would silently author a

build the player never chose, which the cardinal rule forbids in spirit and the sweeps would

read as a phantom pick. The UI obligation is to surface the pending choice per set; the data

default is empty.

---

4. Selection-state schema (closing §5I.1's deferral)

No new registry, and no relocation of ratified persistence. One field vocabulary, three homes,

one writer each — the homing is per owner kind because that is exactly how the ratified texts

already place ally persistence.

lane, loadout_set_id; keyed replace, never append. This is the loadout-aware pick

store for every owner kind, and its own note states why the set key is there: it "is what

makes the sweep's in_run / loadout_swap / respec_costed / fresh_run classing measurable against

the ruled §14 loadout switch rather than against a relocated respec venue." Pick state does

not fragment across owners; the owner rides the key's capability_ref resolution.

index and a gate index. See the re-key at §7.1 (PENDING F-7 on the column name only).

owner_kind, owner_ref, set_id (FK T0_Loadout_Set_Definition.set_id),

gear_instance_refs[], ability_selection_refs[], is_active.

persistence rides this roster object, "which will carry loadout state alongside the loyalty

fields once the schema pass authors the columns." This pass authors them: the same field

vocabulary as above (set_id, gear_instance_refs[], ability_selection_refs[], is_active,

repeating per unlocked set) lands as a loadout_sets[] member of the per-companion object,

beside the loyalty fields it already carries. Authoring the columns is what lifts L581's

embargo — until this lands, no consumer may read a loadout field there, because it does not

exist.

persistence "rides the per-companion roster object at WS_027 and the familiar bond state at

WS_012, extended with the spread and its level-up choice state at the schema pass." The

familiar-side loadout columns are the same vocabulary minus gear under F-4's recommendation,

so this touch is PENDING F-4 and is a populate rather than a migration either way.

See §5 for what happens to the bonus value.

The one-home rule, stated so no consumer guesses: a companion's loadout state is read from

WS_027 and nowhere else; a familiar's from WS_012; the player's from WS_045. WS_045's

owner_kind discriminator remains in the mint as the declaration that all three carry ONE shape

— §8.11.6's "no mirror table, one shape plus an owner discriminator" is a statement about shape,

not about storage — and its domain note is amended at §7.1 to say so, because a T1 ratified line

outranks a T0 note under the authority hierarchy. Tooth T-LS-ONEHOME arms the rule both ways.

---

5. respec_class semantics — the deferred column, defined

T0_Bonus_Pool_Registry.respec_class is deferred on all seven live rows. Proposed enum:

a switch venue, at no material cost, and it writes only WS_043 at that set's key.

multi-day in-game time, faction-standing implications) and writes a WS_044 entry.

cannot be unwound. No live pool needs this today; the value exists so the case is expressible

without a later schema migration.

**RECOMMENDATION: set_local on both lanes, on all seven live rows and as the authoring

default.** The costed-respec architecture stays exactly where canon puts it — on Mastery Points

(§5B.1) and device bondings (§5B.2) — and the pick layer is the free, expressive layer that

loadout sets exist to multiply. This is a RECOMMENDATION, not an application: it is F-2, and the

§7.1 touch row carries the PENDING F-2 flag.

Grounds: T1_Combat §14 (L567) states without qualification that each set holds "its own bonus

picks." If majors were costed, half of every set would not actually be part of the set, and the

ruled "quick-changes as a unit" would be false for the transformative half of the build. §5I.1

(L545) frames sets precisely as the mechanism that lets "one protagonist carry more than one

selection profile."

Strongest objection: Lane B picks are identity-changing by design — §5H.2 / §14A: a single

fireball becoming three, area detonation on impact, casting while moving. Making them free

toggles at every well risks draining the felt weight out of the game's most dramatic

progression beats, and turns theorycraft into menu-shuffling rather than commitment. The

counter, and the reason the recommendation stands: the weight in this system was deliberately

placed upstream — on *earning* the level gate, which requires a quest-unlock event and not a

numerical threshold alone (CVD §17.5, restated at T1_Combat's Lane B paragraph). The gate is

the commitment; the pick is the expression. And the ruled AAAAA balance doctrine (§10) makes

build breadth the measured objective — "hundreds to thousands of equally important and useful

builds" — which a costed major-pick respec directly suppresses by taxing exploration.

Consequences to record:

keeps the ledger honest (it logs costed, irreversible transitions) and prevents ledger spam

that would drown the mastery_point and device_bonding entries it exists to carry.

declared here rather than dropped, so that if a future pool authors as ritual_costed the

ledger shape is already correct. This is a declared inert value, never a silent deletion.

reversible data.

---

6. Companion and familiar parity

6.1 Slots are player-level, and persistence rides the ally's own object

§8.11.6 (L575) asks the schema pass to confirm or redraw its interim split. **This spec confirms

it as written**, because the live data already states it and no consumer has contradicted it:

T0_Loadout_Set_Definition.owner_scope = player_level, applies_to_allies = TRUE,

departs_with_companion = FALSE on all three rows. In §8.11.6's own words the slots "are

player-level unlocks: they persist with the player, apply across whoever is on the bench, and

never depart with a companion, because the player bought the slot rather than buying it into the

person." One purchase, every owner.

Confirmed with it: gear and carried imprint runes are transferable and return on departure;

levels, attribute spread, and proficiency picks are intrinsic and leave with the ally; the

player's spent choice budget is not refunded.

Where the state lives, ruled (critic finding 1; director ruling, reversal disclosed). The

slot ENTITLEMENT is player-level; the ally's ASSIGNMENT against that entitlement is the ally's

own state and rides the ally's own object — WS_027 for a companion, WS_012 for a familiar —

per ratified §8.11.6 L581 and §8.11.7. Revision 1 put companion loadout state on WS_045 at

owner_kind=companion and left L581 pointing elsewhere; the critic agreed there were two homes

and recommended moving the ratified pointer. The director ruled the opposite direction: the

ratified line wins and the schema pass authors the columns where L581 says they go. Recorded as

a reversal rather than smoothed, because the next reader of §8.11.6 must be able to see that the

two documents now agree on purpose and not by accident.

The three rows read together, so nothing is orphaned:

where they may be switched, and the departs_with_companion=FALSE invariant.

6.2 The departure transaction

§8.11.2 (L549) binds the two clauses into one contract: a DEPARTED event "is not complete until

both the reroute set and the return are resolved." Engine contract:

transaction sweeps every entry in that companion's WS_027.loadout_sets[] — all unlocked

sets, not merely the active one. Gear parked in an inactive companion set is the exact case a

naive implementation loses, and losing it converts what §8.11.6 (L577) calls "a relational

consequence" into "a resource penalty" — the same failure T1_Combat §14 (L579) and addendum §9

(L168) name in their own words as a "loot punishment." (Attribution corrected this pass: the

phrase "loot punishment" belongs to T1_Combat and the addendum; §8.11.6's wording is "resource

penalty.")

6.3 The quick-change is an ally-role change

§8.11.7 (L591) is the sharpest single line for this system: "the loadout-set quick-change at a

vril site is therefore also an ally-role change, and a party can be recomposed at the sanctum

rather than only at level-up." The sanctum is where party composition happens. Two consequences:

player's plus each companion's — because a party recomposition is one decision, not four. The

UI reads across the three homes; per-owner homing is a persistence fact, never a screen fact.

transaction (see §7.3 atomicity), spanning WS_045, WS_027, and WS_012 writes.

6.4 Familiars

§5I.3 (L555) names "familiar bond" as a developable capability on the §3 roster carrying its

own minor and major pools, so familiars carry pick assignments per set by the universal pool

rule, keyed on WS_043 like every other owner. Their set-side state extends WS_012 per

§8.11.7's own sentence. Gear is the open edge — canon gives familiars a bond ladder (§8.11.5) and

a stat spread (§8.11.7) but no equipment slots. See F-4; the WS_012 touch is PENDING that

ruling.

---

7. The vril-site quick-change — state machine and data model

7.1 Registry and harness touches

TargetTouchGrounds
T0_Bonus_Pool_Registry.respec_classPENDING F-2: populate deferredset_local on all 7 rows§5 above; closes the named deferral. Flagged pending because §5 recommends rather than applies, and §11 F-2 is Josh's
T0_Bonus_Pool_Registry.grade_index + gate_indexPENDING F-7 (column NAME only): re-key to a single level_index (1-12), lane already discriminatesThe (d) ruling retires the two-index reading (§5I.1 L539: "The split follows the §2 single level index"); DESIGN_GAP_REGISTER L1141-1142 carries this as an open schema flag, recorded pre-ruling. The twentieth-sitting rider governs PROSE — "Gate" reads LEVEL GATE corpus-wide, no rename pass — and this row is registry scope, which the rider does not cover
T0_Bonus_Pool_Registry.spec_purpose_refspopulate on all 7 pool rows (or declare option-level refs the sole source and pool-level reserved)BLANK on all 7 rows today, so §2.3's derived spec purpose resolves empty for every set. Without this the derivation is a contract with no input; §9 declares it not-armed until the populate lands
harness/check_build_space.py tooth T-A2retire, replaced by T-LS-ENTITLEMENTAs written (L290-324) the tooth clamps grade_index to 1-10, so a legal minor pool at level 11 or 12 FAILs, and it FAILs any pool carrying a grade index at gate 6 or 10 while (d) rules that every level pays a pair. Calibration (critic finding 5): this is a LATENT defect, not a live red. Gate 26 runs PASS today (0 FAIL, fixtures 70/70) because no live pool carries both indices and every grade_index value is 1. It FAILs the first correct post-(d) row authored — a minor pool at level 11 or 12, or any row carrying the single level key at a former ceremony gate
harness/check_build_space.py T-A9 scopeextend PLAYER_SURFACE_COLUMNS (L132) with display_name_text and add ((sets,'set_id')) to the iterated table set (L575)Critic finding 2, recommended option applied. T-A9 is the no-mode-taxonomy firewall and is hard-scoped to the option and pool tables; the new set label below would be a player surface outside it, i.e. unarmed by construction. Ship the must-fire fixture: a set label containing bonus_picks. Fallback if the signature change is unwanted: the ninth tooth T-LS-VOICE at §9
harness/check_build_space.py T-A12 inputthe sweep/gate supplies selection keyed on (capability_ref, level_index, lane, loadout_set_id); the held-set sum groups on that key§3, corrected. budget_scope stays documentation of intent — the arithmetic never reads it outside the global branch (L630-636)
T0_Realm_Ruleset_Registryadd and populate suppresses_capability (bool) beside ability_availability_delta§8.2, corrected. T-LS-VENUE's clause has no input without it: only 3 of 11 rows carry a delta and two of those are not suppressions, so delta non-emptiness is the wrong predicate
T0_Loadout_Set_Definitionadd display_name_text + string_statusThe table has neither, while every populated Family-B sibling carries string_status and T0_Rarity_Grade uses display_name_text exactly. The build UI needs a player-facing label and the natural-voice pass needs its worklist hook. Words are not authored here (F-9), and the firewall obligation above lands in the same commit
T0_Loadout_Set_Definitionpopulate unlock_gate_chapter_min, unlock_gate_ref, unlock_cost_material_refs on LS_02/LS_03Blank at mint; "later-game purchasable" (§14 L567) needs a real gate. Materials denominate per the no-universal-coin ruling, per the fk_spec note
T0_Vril_Site_Registryno schema change; switch venues resolve by site_class / vril_function42 live rows; switch_venue_ref blank on all LS rows = "any site of the switch_venue_class," per the fk_spec L748 note
WS_027author the loadout columns: loadout_sets[] of {set_id, gear_instance_refs[], ability_selection_refs[], is_active} beside the loyalty fieldsRatified §8.11.6 L581 names this pass as the author and embargoes reads until it lands. Director-ruled home for companion loadout state
WS_012PENDING F-4: extend with the familiar-side set columns (same vocabulary, gear reserved and blank under F-4(a)) alongside the ratified spread extension§8.11.7's persistence sentence; §8.11.5 keeps the familiar axis separate
WS_045no field change; domain note amended — the owner_kind discriminator declares the shared SHAPE, and persistence for companions rides WS_027 and for familiars WS_012 per §8.11.6 L581 / §8.11.7T1 outranks T0; the amendment records the correction in place rather than leaving two homes
WS_043, WS_046no schema changeThe mint is correct as landed
WS_044no schema change; respec_kind=bonus declared inert (PENDING F-2)§5

T0_Loadout_Set_Definition stays the sole owner of set canon: the ceiling is this table's

row count, never a number restated elsewhere (fk_spec L748).

7.2 The state machine

States per owner: exactly one set is is_active at any time.

Reading a build is not changing one, and blocking it would make the book screens useless in

the field.

switch venue. §14 (L571): the vril site is "save point, vril recharge source, and loadout home

together."

Guards on EDIT and ACTIVATE, each resolvable from data:

the purchase plus unlock_gate_chapter_min / unlock_gate_ref);

switch_venue_ref meaning any site of that class;

(§8.1);

guard failure, not a fallback.

7.3 Atomicity

§14 rules the switch is "as a unit rather than piece by piece." The engine contract is

transactional: gear equip, ability rebinding to GAS, the WS_043 filter flip to the new

loadout_set_id, the derived spec-purpose recompute, and the presentation-tier key re-read

(addendum §5, which "reads this doc's tier key … and carries no power of its own") either all

commit or none do — across all owners touched by one sanctum decision, spanning WS_045,

WS_027, and WS_012. A partially-activated set — new gear with old picks, or a player switched

while a companion's write failed — is a defect class, not a transient.

Save coupling: the vril site is also the save point (§14 L571). The switch commits before the

save write, so no save ever captures a half-switched state.

---

8. Edge cases

8.1 Mid-combat

Banned: switch_in_encounter_allowed = FALSE on all three LS rows, derived from the siting rule

(§14, and the LS_03 note states the derivation as data). Engine requirement: a real

encounter-scoped out-of-combat detector with settle hysteresis — the primitive already specced as

UHumanityCombatStateSubsystem in docs/pipeline_review/FORKB_RESURRECTION_BRIEF_2026-07-27.md

(A4). Without hysteresis a fleeing enemy holds the sanctum hostage and the player is locked out

of their own build screen with nothing on screen to explain why.

The defeat/revival sub-case, resolved. The vril site is the ruled respawn anchor for the

Fork-B defeat model. A player who wipes and revives at a site is, by construction, standing at a

switch venue — so a wipe legitimately permits a re-build before the retry. That is the intended

loop, not an exploit: it is the same "learn the fight, change the answer" beat the puzzle-boss

chain-meter design already builds toward. The invariant that must hold alongside it: the boss

encounter's own state resets, and the player's picks do not.

8.2 Suppressing crossings — realms and committed-run interiors

Two live realm rows state a related problem in their own data

(T0_Realm_Ruleset_Registry.ability_availability_delta), and reading them precisely is what

keeps the tooth honest:

confiscated**, one usual answer is closed and the lived record opens another." This is a real

capability suppression.

the intensity instrument and not a build confiscation**." By its own words this is intensity,

not suppression.

medium"). Not a suppression at all.

Only 3 of 11 rows carry any delta, and two of those three are not suppressions — which is why the

obligation below keys on a declared suppression, never on delta non-emptiness (critic finding 3).

Rules:

gates what the active set can *do*; it never mutates the set, strips a pick, or unequips gear.

The Duat row already says the build is never confiscated — this generalizes it as the law.

A build the player did not choose is a build the player cannot learn from.

against the active set's core loop and the space beyond contains no switch venue, the crossing

must supply an entry-side sanctum before the threshold. Enforced by tooth T-LS-VENUE,

positive-controlled per the standing law that a search which cannot match must never report a

clean zero.

The obligation is not realm-shaped, it is threshold-shaped: it binds **any committed-run

interior that suppresses or gates the active set**. The sibling RIFT_DUNGEON_SCAFFOLDING_SPEC

rules (L464-468, restated at L634-637) that "Vril sites are the ruled save, recharge and

loadout sanctum. A pocket interior is a committed run and should NOT inherit that

automatically," with the sanctum affordance a MOUTH-row property and the POCKET row declaring

it FALSE by default. Composed with this spec: **a committed-run pocket inherits no sanctum, and

therefore the mouth carries the entry-side switch venue.** That is what keeps the composition

inside the rift spec's own no-lockout law (L93-96) — a player who commits into a pocket with a

mismatched build must have had an edit venue at the mouth, since EDIT is banned outside a

switch venue by §7.2 and the interior offers none. Neither spec owned this state before; this

clause and the rift spec's edge case 13 are the two halves of one rule, cross-referenced in

both.

declare no suppression — that is the intensity instrument working, and the tooth must not fire

on them.

8.3 The MMO bridge

§12 and T1_Tier_C_MMO_Spec (L349, and the reciprocal at Integrity L721) make single-player party

building "the training ground for Tier-C raid building — one architecture, designed once."

a solo build tops out at 22 assigned picks and a Tier-C character's set can carry 24.

content keeps its level-12 assignments in WS_043 and simply does not express them. Stripping

them would be confiscation, which §8.11.6's investment-protection doctrine forbids and which

would make crossing arenas destructive.

composition encounter across four operational teams. Role composition is exactly what §8.11.7

(L591) puts at the sanctum. See F-6.

8.4 Cross-set gear sharing — one instance, many pointers

gear_instance_refs[] are references into a single owned inventory (WS_046.instance_id). A set

is a pointer list, never a container. Consequences:

switch is an item-dupe class defect, the most damaging failure this system can ship.

drops the reference and that slot reads empty. A dangling ref that still confers stats is a

phantom-item defect. Tooth T-LS-REFINTEGRITY.

simultaneously live in the player's set 2. WS_046.owner_kind/owner_ref is the arbiter.

8.5 Level-up while non-active sets exist

Entitlement is global and immediate; assignment starts unassigned in every set (§3). No

auto-fill. The UI obligation is a per-set pending-pick indicator so a player does not walk into a

region with an unspent pair in the set they are actually wearing.

8.6 Purchasing set 3 while set 2 is active

A newly unlocked set initializes as a copy of the currently active set (gear refs shared, not

duplicated; pick assignments copied). See F-3 — the alternative leaves the player naked the

instant they activate it.

8.7 Retired and superseded options held in a saved set

T0_Bonus_Option_Registry.lifecycle supports retired / superseded_by, and tooth T-A8 already

forbids deleting ids. A saved set holding a retired option degrades that key to unassigned

and surfaces it as a pending choice. It never silently substitutes the successor — a silent

substitution authors a build change the player never made — and it never hard-fails the load.

8.8 Imprints and the sigma constraint

Imprints ride items (§2.2), so switching sets cannot re-roll anything. Roll state and the

±1 sigma bound (HL_0061, per-drop-table counters, reset on drop) live entirely on the item

instance (WS_046.slot_rolls[], sigma_seq, reroll_count). Stated explicitly because the

obvious naive implementation — imprints as set-scoped state — would open a free re-roll loop at

every waterfall and silently defeat the ruled sigma discipline.

8.9 Companion departure with gear in an inactive set

Covered at §6.2 and armed by tooth T-LS-RETURN. Called out separately here because it is the one

edge case where a correct-looking implementation (sweep the active set) still violates a ruled

invariant.

---

9. Verification teeth

Nine teeth, each FAIL-only or WARN-scored as noted, each shipping a **must-fire and a

must-not-fire fixture** per the convention already established in harness/check_build_space.py

(L769-771: fixtures are in-code canned rows, deliberately outside the scanned registries tree).

Ids are namespaced T-LS-* to avoid collision with the live T-A* and T-RLM-* sets.

in that owner's ruled home, and every set_id resolves to a T0_Loadout_Set_Definition row.

*Must fire:* two actives for one owner. *Must not fire:* one active, two dormant.

WS_012; player at WS_045. No loadout field is written on a WS_045 row at

owner_kind=companion or familiar, and no consumer reads a loadout field on WS_027 before

the §7.1 column authoring lands. *Must fire:* a WS_045 row at owner_kind=companion carrying

gear_instance_refs. *Must not fire:* a companion's sets held on WS_027 with the same field

vocabulary. (New this revision — critic finding 1 under the director's ruling.)

table's row count and never as a literal in code or in another registry. *Must fire:* a

reference to LS_04 while three rows are live.

level; every pool carries exactly one level_index in 1-12 alongside its lane. **This tooth

replaces T-A2's retired two-index logic**; landing it without retiring T-A2 ships two teeth

that contradict each other. *Must fire:* a minor pool keyed at level 13, and (regression) a

legal minor pool at level 11 that the old T-A2 rejected. *Must not fire:* the seven live rows

after the re-key.

allocation, a device bonding, a numerical-experience value, or a familiar bond level; and

composition_kinds is a subset of {gear, abilities, bonus_picks}. A spec_purpose token

appearing in composition_kinds is a FAIL, because purpose is derived (§2.3). *Must fire:*

composition_kinds containing spec_purpose. *Must not fire:* the three live LS rows.

(docs/factory_contract.json) resolves at least one switch venue in T0_Vril_Site_Registry.

(2) Every crossing row declaring suppresses_capability=TRUE — realm rows in

T0_Realm_Ruleset_Registry and committed-run interior rows per §8.2 — resolves either an

in-space venue or a declared entry-side sanctum. **The predicate is the declared suppression

token, never a non-empty ability_availability_delta** (critic finding 3): RLM_0006 and

RLM_0010 are the named must-not-fire fixtures, since RLM_0006's delta says in its own words

it is "the intensity instrument and not a build confiscation" and RLM_0010's is an atmospheric

reference; RLM_0004 (weapons unresponsive) is the must-fire candidate once the column

populates with no venue and no declared entry sanctum. The resolver **positive-controls

itself** — it proves it can match a known-good chapter before reporting any zero.

event resolves a return transaction covering gear held across all entries of that

companion's WS_027.loadout_sets[], not only the active one. Pairs with

harness/check_no_dead_end.py on the same event, per §8.11.2's one-contract-two-clauses rule.

*Must fire:* a DEPARTED event whose return covers the active set only while an inactive set

still holds gear.

instance ref; a retired option_id held in WS_043 degrades to unassigned rather than

resolving to a live effect. *Must fire:* one instance id under both the player and a companion.

least one active option; and no pool marked set_local writes a WS_044 entry with

respec_kind=bonus. FAIL-only. **Arming is gated on the F-2 ruling landing, not on the column

populating** (critic finding 7): arming it earlier punishes the pre-ruling state, which is

legally deferred until Josh rules. *Must fire:* a set_local pool with a bonus ledger

entry.

The player-surface firewall (critic finding 2). display_name_text on

T0_Loadout_Set_Definition is a new player surface, and T-A9 — the ruled no-mode-taxonomy

firewall — cannot see it: PLAYER_SURFACE_COLUMNS is `("option_name", "player_text",

"pool_display_name")` (L132) and the iteration is hard-scoped to the option and pool tables

(L575). The obligation lands in the same commit as the column: extend both, with the must-fire

fixture being a set label carrying bonus_picks, and a must-not-fire fixture being a natural

label with no routing vocabulary in it. If the T-A9 signature change is refused, the equivalent

is a ninth tooth T-LS-VOICE with the identical predicate over the set table. Either way the

surface is armed before any word is authored (F-9).

Arming honesty — declared, never a silent green, per harness/check_build_space.py L10-15:

armed while unlock_gate_ref blanks persist.

rows, so §2.3's derivation resolves empty and T-LS-SWAPLINE's purpose clause is a shape check

only until the §7.1 populate lands.

---

10. Engine contract summary (what lands on the 5090)

guarantee across all owners in the decision, gated by the §7.2 guards including the home guard.

hysteresis, consumed by the switch_in_encounter_allowed=FALSE guard.

save, recharge, and loadout in one interaction, exposing every fielded owner's sets in one

screen (§6.3) by reading across WS_045 / WS_027 / WS_012.

WS_027.loadout_sets[].

(§8.2), built with the rift spec's mouth/pocket row pair rather than as a second mechanism.

---

11. Open forks for Josh — options, recommendation, strongest objection

Each of these touches a number, a name, or a ruled boundary, so each is presented rather than

applied.

F-1 The set ceiling (numerical). (a) Hold at three — the ruled ceiling, derived in T1_Combat

§14 (L567) from Josh's naming of a second and a third set, and expressed as the row count of

T0_Loadout_Set_Definition. (b) Raise it later as a purchasable ladder. RECOMMEND (a) hold.

Objection: the AAAAA doctrine wants many viable builds, and three profiles may feel tight at

endgame with 24 picks per capability across many capabilities. Counter: sets multiply *carrying*

capacity, not build space; build space is what the sweeps measure, and raising the ceiling is a

one-row change if playtest asks for it.

F-2 respec_class default (system boundary). (a) set_local on both lanes — recommended,

argued in full at §5. (b) minors set_local, majors ritual_costed. (c) both ritual_costed.

RECOMMEND (a). Objection and counter at §5. The §7.1 touch row and T-LS-RESPEC's arming both

wait on this ruling.

F-3 New-set initialization. (a) Copy the active set on unlock (gear refs shared, picks

copied). (b) Initialize empty. RECOMMEND (a). A player who buys set 3 and activates it under

(b) is instantly unarmed and unpicked at whatever point in the world they are standing, which

reads as a bug rather than a purchase. Objection: (a) briefly makes the new set redundant, so

the purchase does not immediately feel like anything — mitigated entirely by the UI opening the

new set in edit mode at the sanctum where it was bought.

F-4 Familiar set composition. (a) Familiar sets carry bond-ability selection and pick

assignments, no gear — grounded in §5I.3 (L555) naming "familiar bond" as a pooled capability,

while no canon gives familiars equipment slots. (b) Full gear parity with companions.

RECOMMEND (a), with the gear column reserved and blank so (b) is a populate rather than a

migration. Objection: §8.11.7 (L591) says "Gear and imprint runes shift an ally's profile per

§8.11.6 parity," and "ally" arguably covers familiars — but §8.11.5 (L561) explicitly separates

the familiar axis, and minting familiar equipment slots would be inventing a system rather than

expanding one. The WS_012 touch at §7.1 waits on this ruling.

F-4b Does the active set select the fielded familiar? Addendum §11 (L208-231) rules that "a

familiar is a spec decision, not a pet cosmetic," and names "EAM pairing (ability enhancement

gated on the bonded familiar)" in the same bullet. (Anchor corrected this pass: revision 1 cited

a §10.6 that does not exist in the addendum; the sentence is §11's.) RECOMMEND yes — the

fielded familiar is part of the set, which makes swapping sets a genuine spec change rather than

a gear change. Objection: it couples the 22-slot roster to the set system, and the path-variable

22nd slot has story constraints that a free swap could bruise.

F-5 REBONDED preservation. On DEPARTED, (a) keep the ally's set shapes — ability selection

and pick assignments — dormant on WS_027, and empty only the gear refs; or (b) clear

everything. RECOMMEND (a). §8.11.6 (L579) rules that a companion who returns under REBONDED

"returns as who they were — their spread, specialties, and combat style persist across the

absence, and re-equipping is the player's choice to make again." That sentence names re-equipping

as the only thing the player redoes. Objection: pick assignments were the *player's* choices, not

the ally's identity, so arguably they should not persist — but discarding them means a returning

ally comes back mechanically blank, which contradicts "returns as who they were."

F-6 Tier-C raid staging as a switch venue. (a) Register guild-hall and raid-entry staging

areas as switch venues of a Tier-C venue class. (b) Sanctums only, so raid role changes require

leaving the staging area. RECOMMEND (a). A 100-player World Boss with a four-team operational

architecture cannot compose roles if changing role means leaving. Objection: it dilutes the

diegetic siting rule that makes the vril site special — mitigated by making the staging venue a

*named* Tier-C venue class rather than by loosening vril_recharge_zone itself, so the

single-player fiction is untouched.

F-7 The level_index re-key (schema naming). Deterministic under the ruled (d) shape — the

two-index reading is retired and the level index is the single key (§5I.1 L539: "The split

follows the §2 single level index"). The only genuinely open piece is the column name:

level_index (recommended) versus reusing grade_index re-scoped. RECOMMEND level_index,

with grade_index and gate_index retired rather than deleted per the id-permanence convention.

Scope note carried from the twentieth-sitting record (L26): the rider "'Gate' reads LEVEL GATE

corpus-wide — no rename pass" governs PROSE, and this fork is a registry column re-key, which the

rider neither authorizes nor forbids. Objection: a rename touches every consumer at once — which

is exactly why it should happen now, while seven rows and one tooth are the entire consumer set.

F-8 The mid-encounter ban. (a) Hold — recommended; it is derived from the siting rule and

holding it costs nothing. (b) Relax for out-of-combat-but-in-encounter lulls. **RECOMMEND (a)

hold.** Objection: long multi-phase boss fights with a hard counter-check may feel punishing

without a between-phase adjustment — but that is what the §8.1 defeat-and-retry loop already

answers, diegetically and at the sanctum.

F-9 Player-facing set names (naming canon). T0_Loadout_Set_Definition carries no

display_name_text. The column is recommended at §7.1; **the words themselves are not authored

here** and route to the natural-voice pass, per the standing doctrine that every player-facing

word sounds like a person and is culturally registered. Landing condition: the T-A9 firewall

extension at §9 ships with or before the column, so the surface is armed before it carries a word.

F-10 CONFIRM-ONLY — what a loadout set means to the player (no alternatives offered). §2.4

reads "equipment-and-ability set" as the *prepared* selection over Mastery-Point unlocks, never

the Mastery Point allocation itself. This is not a fork with live options — the canon forces it

(§5A L197 separates the two economies, §5I.1 L545 reserves reallocation to §5B.1, and the other

reading makes §5B.1's cost architecture dead text) — but it is the single reading that defines

what a set *is* to the player, so it is surfaced for confirmation rather than left inferred

(critic finding 9, applied as recommended).

---

12. Paste-ready amendment text (CVD §17.14 style)

The following prose is written to §17.14 — plain prose, single-level dashed bullets, no code

blocks, no emphasis asterisks, affirmative framing — for the owning T1 docs, and lands only

after the F-2 through F-6 rulings. The §8.11.6 persistence clause below is the exception: it

carries no pending fork and may land with the schema-pass commit.

For T1_Combat_System_Spec Section 14, appended under Second and Third Loadout Sets

A set is an assignment over permanent entitlement rather than a second character. What the

protagonist has become stays outside the set and what the protagonist has chosen rides inside it.

Numerical experience, level standing, Mastery Point allocations, device bondings, questline

completions, and earned rarity-grade access are permanent and shared by every set. Gear, the

imprint runes carried on that gear, the prepared ability selection, and the bonus pick

assignments are what a set holds and what quick-change moves. Spec purpose is read from the

picks a set holds rather than stored on the set, so a build's role is always what its selections

actually support.

The ability selection a set carries is the prepared set drawn from what Mastery Points have

already unlocked, and never the Mastery Point allocation itself. Point reallocation remains the

sited and costed ritual owned by T1_Ability_Tree Section 5B.1, so the well is where a build is

carried and the trade compound is where a build is remade.

A crossing that suppresses what the active set can do carries its own answer. Where a realm or a

committed-run interior gates the capabilities a build depends on and holds no switch venue of its

own, the threshold before it carries the sanctum, so a player who commits into that space has

always had the chance to prepare for it. Suppression shapes what a build can do inside the space

and never alters the build itself.

For T1_Ability_Tree Section 5I.1, replacing the schema-pass deferral sentence

Selection state is per capability, per ability, per level, per lane, and per loadout set. A

capability carried to a given level holds that level's minor and major pick entitlements

permanently, and each unlocked loadout set holds its own independent assignment of those

entitlements. A set never holds a pick above the capability's earned level, exclusion groups

resolve within a set rather than across sets, and a newly granted pick arrives unassigned in

every set so that no build is authored on the player's behalf. Re-selection within a set is a

loadout edit performed at the sanctum, and Section 5B.1 remains the authority on point

reallocation.

For T1_Integrity_Paths_Worldstates_Master Section 8.11.6, replacing the interim-split paragraph's closing sentence

The transferable-versus-intrinsic split is ratified as written at the schema pass. Gear and the

imprint runes carried on it return to the player on departure; the ally's levels, attribute

spread, and proficiency picks are intrinsic and leave with them; the purchasable second and third

loadout-set slots are player-level unlocks that persist across whoever is on the bench. The

return transaction sweeps every set the departing ally holds rather than only the active one, so

that equipment parked in a set the ally was not currently wearing comes home with the rest.

For T1_Integrity_Paths_Worldstates_Master Section 8.11.6, replacing the persistence sentence at the sub-section close

Persistence rides the per-companion roster object at WS_027 per T0_Worldstate_Variables, which

now carries loadout state alongside the loyalty fields: each unlocked set the companion holds

records its set identifier, its gear instances, its prepared ability selection, and whether it is

the active one. The familiar side rides WS_012 beside the bond state per Section 8.11.7, and the

protagonist's sets ride WS_045. The three homes carry one field vocabulary and one writer each,

so a companion's loadout is read from the companion's own roster entry and from nowhere else.

The return transaction rides the DEPARTED event at WS_028 beside rerouted paths.

Generated by harness/site/structure_site.py — the URL path is the repo path. review root