Determinism & replay

State persistence scope

state-persistence-scope-2

Tests included

This contract defines the behavior of saved state: campaign progress, settings, or a cloud save.

This contract decides whether your campaign progress and settings are kept after events such as a crash or a move to a new device, and what happens when a save is damaged.

Use in your package

The first button opens the authoring tool with this contract added and its questions unanswered. You can also download the zip file and add the contract later.

What is in the zip file

The zip file holds the contract and its acceptance tests. In the authoring tool, choose Add contract and pick this zip file. If you edit your package outside the authoring tool, unpack the zip file in your package folder. The files of the zip file go into contracts/. Fill in the answers there.

Questions

Up to 3 questions. Some appear only after earlier answers.

  1. By default, what happens when saved state cannot be read?
  2. By default, what happens when an older game build wrote the copy?
  3. By default, what happens when a newer game build wrote the copy?

Try the answers

Pick answers to see which rules and tests apply. Nothing is saved here. In the zip file and in the authoring tool, the questions have no answers yet.

By default, what happens when saved state cannot be read?

Asked when
the copy kinds list has at least one row.
If not asked
No saved copy can be opened later, so unreadable saved state never reaches a load attempt.
Choices for By default, what happens when saved state cannot be read?
The unreadable copy stays closed. A city slot remains listed, but none of its progress becomes active.

Loading stops before any state from that copy becomes active. The copy is neither replaced nor repaired by this response.

Play starts from the normal starting state. A damaged puzzle slot opens with its first board instead of the old board.

The starting state becomes active instead of state from the unreadable copy. The response does not by itself delete or overwrite that copy.

An earlier copy can replace the unreadable copy through a route that the game supports. Restoring a file by hand is one such route. A factory game continues after the player chooses the backup that was made before the damaged autosave.

A declared manual, in-game, or automatic recovery route can activate an earlier copy. The newest usable earlier copy under the matching backup rule becomes active.

Readable progress returns and damaged parts reset. A dungeon keeps cleared floors but rebuilds one broken room record.

Readable state becomes active as one repaired result. Every unreadable part takes the starting value named by the cited repair rule.

The player can cancel or try the unreadable copy. A colony save opens only after its damage warning is accepted.

No state from the copy becomes active before the explicit choice. Accepting the warning permits an attempt but does not promise success.

Why this is asked

Lost progress is the most visible failure of a save system. This answer is the default answer. A save kind can choose another answer in its own row.

By default, what happens when an older game build wrote the copy?

Asked when
the copy kinds list has at least one row.
If not asked
No loadable copy exists, so an older build has no saved state to open.
Choices for By default, what happens when an older game build wrote the copy?
The older copy stays closed. A world from last year's rules cannot open in the current build.

Loading stops before state written by the older build becomes active.

The game updates the old state and opens it. A factory save gains the current recipe records before play resumes.

A declared conversion produces current-build state before activation.

The old copy is tried only after a warning. A racing career from an earlier patch opens after the player accepts the risk.

The player accepts a compatibility warning before old-build state becomes active. Acceptance permits an attempt but does not promise success.

Why this is asked

An update can make a player's progress impossible to load, or change it permanently. Choose how the current build protects that progress.

By default, what happens when a newer game build wrote the copy?

Asked when
the copy kinds list has at least one row.
If not asked
No loadable copy exists, so a newer build has no saved state to open.
Choices for By default, what happens when a newer game build wrote the copy?
The newer copy stays closed. A world from a later patch remains unavailable in this build.

Loading stops before state written by the newer build becomes active.

The newer copy is tried only after a warning. A sandbox world opens after the player accepts that newer content may be lost.

The player accepts a compatibility warning before newer-build state becomes active. Acceptance permits an attempt but does not promise success.

Why this is asked

Going back to an older build can erase newer content. Choose whether the player may take that risk.

Lists5 lists

Some settings are lists of rows.

A reference points to a number or a rule in your design. For a number, use the address of a decided number in your tuning, not an open one. For a rule, use its file and heading, such as 02-mechanics.md#recovery. The reference must match exactly one heading in that file. No > DELEGATED: or > PERSONALIZATION: tag may cover any part of the section under that heading. Each field's description says what it needs.

State families

state-families

List each state family. A state family is a group of state that can change later play. For each state family, give how long it lasts and what happens to it at a quit, a crash, death, a deletion, and a move to another device.

An empty list means: No changing game state is covered, so this adoption makes no persistence promise.

Each row is: id, state-declared-in, lifetime, scope-starts-in, scope-ends-in, lifetime-event-declared-in, saved-in, after-normal-quit, after-crash, after-death, after-slot-delete, after-local-profile-delete, on-another-device.

Every field
FieldKindWhen it appearsMeaning
id string Required A short name for the state family in your game's words, such as campaign-progress, run-inventory, unlocks, or settings.
state-declared-in reference Required Where your game's rules say which fields belong to this family and at which points the family can affect later play. For a family that does not return after a quit, after a crash, or on another device, the rules also name the value that the family starts from.
lifetime choice: run, session, slot, profile, device, account, until-event, not-kept Required How long this state lasts. Run: the state belongs to one attempt; a roguelike's carried items are lost when that attempt ends. Session: the state belongs to one continuous visit; a co-op lobby choice is lost when the party leaves that lobby. Slot: the state belongs to one player-selected save; campaign progress is lost when that slot is deleted. Profile: the state belongs to one local player profile; unlocks are lost when that profile is deleted. Device: the state belongs to one installation; local settings are lost when that device data is erased. Account: the state belongs to one account; online settings are lost when that account is deleted or reset. Until event: the state lasts to one named game event; dropped currency is lost at the next death. Not kept: the state is lost at its first named interruption; an enemy's alert meter does not return after quitting.
scope-starts-in reference Present when row lifetime is Run or Session. Where your game's rules say when this attempt or continuous visit starts. The player can observe the start. A run may start when the character enters the dungeon; a session may start when the party joins a lobby.
scope-ends-in reference Present when row lifetime is Run or Session or Slot or Profile or Device or Account or Not kept. Where your game's rules say when this lifetime ends. The player can observe the ending. It may be an attempt result, leaving a lobby, deleting a player-selected slot, deleting a local profile, erasing device data, deleting an account, or the first interruption that discards the value.
lifetime-event-declared-in reference Present when row lifetime is Until event. Where your game's rules say which named game event destroys the value that the family had before the event. A recovery point may last until the next death after it appears.
saved-in string Optional The save kind that restores this family. When the field is absent, no copy restores the family.
after-normal-quit choice: returns-last-commit, does-not-return Required Whether this state returns after a normal quit. The answer returns-last-commit means that the state returns as it was at the last successful save. A campaign returns its last checkpoint; an unsaved match score does not.
after-crash choice: returns-last-commit, does-not-return Required Whether this state returns after a crash. The answer returns-last-commit means that the state returns as it was at the last successful save before the crash. A world that is saved on a timer may lose the changes made since its last save, and still return that save.
after-death choice: keeps-value, clears-value Required Whether death keeps this value. Roguelike unlocks may remain while the dead run's inventory clears.
after-slot-delete choice: keeps-value, clears-value, no-slot Required Whether this value is kept when the related player-selected slot is deleted. The storage rule of a save kind with several player-selected slots names that slot. For a save kind with one current copy, answer no-slot.
after-local-profile-delete choice: keeps-value, clears-value, no-profile Required Whether this value is kept when the related local player profile is deleted. The storage rule of the save kind that restores this family names that profile. For a family with no such profile, answer no-profile.
on-another-device choice: returns, does-not-return Required Whether the value returns when the same eligible player continues on another device. A server profile may return; local settings may not.

Copy kinds

copy-kinds

List each save kind. A save kind is one kind of saved copy that is written and loaded independently, such as campaign slots, profile data, cloud settings, or a server profile.

An empty list means: No saved copy can be opened later. Loading cannot restore state, compare builds, recover damage, or resolve a conflict.

Each row is: id, contains-declared-in, write-trigger, write-rule-declared-in, residence, layout, storage-rule-declared-in, unreadable-copy, older-build-copy, newer-build-copy, mode-gated, mode-rule-declared-in, removed-at, removal-rule-declared-in.

Every field
FieldKindWhen it appearsMeaning
id string Required A short name for this save kind in your game's words, such as campaign-slots, unlock-profile, or account-settings.
contains-declared-in reference Required Where your game's rules say which state families this save kind writes and restores together. The rules list the state-family ids.
write-trigger choice: player-save, checkpoint, continuous, timer, service-owned Required What starts a save: a save action, a named checkpoint, each accepted change, a timer, or the service's own rule.
write-rule-declared-in reference Required Where your game's rules say exactly when a save begins, what makes it successful, and which later changes a quit or a crash can lose.
residence choice: local-device, cloud-synced, server-authoritative Required Where the copy that decides the restored state is kept: on this device, in copies that are synced between devices, or on a game service. Synced copies can disagree. A profile that the service controls uses the state that the service accepted.
layout choice: one-current, manual-slots Required How the save is presented: one current copy or several player-selected slots. A slot is one named load choice in the storage rule; retained earlier copies belong in the backup list.
storage-rule-declared-in reference Required Where your game's rules say where the copy is kept, which sync or service has authority over it, and how the player selects it. For a save kind with several player-selected slots, the rules also name the identity of each slot, and that identity does not change. For a save kind with one current copy, the rules name no player-selected slot.
unreadable-copy choice: use-game-default, refuse-load, start-fresh, restore-earlier-copy, repair-readable-state, warn-and-try Required What happens when a copy of this save kind cannot be read. Use the default answer, or choose another answer for this row.
older-build-copy choice: use-game-default, refuse-load, convert-and-load, warn-and-load Required What happens when an older game build wrote a copy of this save kind. Use the default answer, or choose another answer for this row.
newer-build-copy choice: use-game-default, refuse-load, warn-and-load Required What happens when a newer game build wrote a copy of this save kind. Use the default answer, or choose another answer for this row.
mode-gated choice: only-in-named-modes Optional This save kind exists only in named player modes. A restore point may exist in a practice mode and a standard mode but not in a challenge mode.
mode-rule-declared-in reference Present when row mode gated is Only in named modes. Where your game's rules say in which player modes this save kind exists. The rules name every such mode and confirm that the save kind is absent in every other mode.
removed-at choice: normal-quit, crash, death, slot-delete, local-profile-delete, device-data-delete, account-delete Optional The event that removes this copy from later load choices. A permadeath save may be removed when the character dies. For a save kind with several player-selected slots, this event removes the copy of the deleted slot, not the whole save kind.
removal-rule-declared-in reference Present when row removed at is Normal quit or Crash or Death or Slot delete or Local profile delete or Device data delete or Account delete. Where your game's rules say exactly which event removes the copy and what the player sees afterward.

Backup copies

backup-copies

List save kinds that retain an earlier copy for supported recovery.

An empty list means: No save kind promises an earlier usable copy, so damage cannot be answered by restoring one.

Each row is: id, copy-kind, backup-rule-declared-in, restore-rule-declared-in.

Every field
FieldKindWhen it appearsMeaning
id string Required A short name for this earlier copy in your game's words, such as previous-campaign-checkpoint.
copy-kind string Required The save kind protected by this earlier copy.
backup-rule-declared-in reference Required Where your game's rules say when an earlier copy is kept, how many earlier copies remain, and which later progress a recovery loses.
restore-rule-declared-in reference Required Where your game's rules say which supported route opens an earlier copy. The rules say whether recovery is automatic, happens in the game, or is a file step outside the game.

Copy conflicts

copy-conflicts

List shared save kinds that can present two complete but disagreeing copies. One adoption has at most one row per conflict scope: one for each named save kind and one for all synced kinds.

An empty list means: No shared save kind can present two disagreeing copies, so no conflict response runs.

Each row is: id, scope, copy-kind, response, resolution-declared-in.

Every field
FieldKindWhen it appearsMeaning
id string Required A short name for the conflict in your game's words, such as campaign-slot-sync.
scope choice: this-copy-kind, all-synced-kinds Required Whether the response settles one save kind or every synced save kind together. One cloud dialog may settle campaign slots and quicksaves as a set.
copy-kind string Present when row scope is This copy kind. The one cloud-synced or service save kind whose copies can disagree.
response choice: select-by-rule, player-chooses-copy, refuse-until-resolved Required What happens before any disagreeing state becomes active. A fixed rule may always prefer the copy the game service holds; the player may choose between dated copies; or neither copy may open until sync is repaired.
resolution-declared-in reference Required Where your game's rules say how this conflict is handled. The rules say how disagreement is detected. They say how the identities of the copies are compared. They say which copies are selected or kept. They name the event that clears the conflict.

Earlier point returns

earlier-point-returns

List save kinds that can return to an earlier point of the same continuous play, whether or not the game names a run. One adoption has at most one row per save kind.

An empty list means: No save kind can return to an earlier point of the same continuous play, so the player cannot load a save to try again.

Each row is: id, copy-kind, after-load, return-rule-declared-in, mode-gated, mode-rule-declared-in.

Every field
FieldKindWhen it appearsMeaning
id string Required A short name for the earlier return point in your game's words, such as dungeon-retry or quicksave.
copy-kind string Required The save kind that can return play to the earlier point.
after-load choice: resume-stays, resume-is-used-once, player-mode-decides Required Whether the same earlier point remains available after a successful load. A practice mode may keep a boss checkpoint while an iron mode allows one return.
return-rule-declared-in reference Required Where your game's rules say what the earlier point is, when activation is successful, and whether another load remains possible.
mode-gated choice: only-in-named-modes Optional This earlier return point exists only in named player modes. A quicksave may be available in a practice mode but absent in a challenge mode.
mode-rule-declared-in reference Present when row mode gated is Only in named modes. Where your game's rules say in which player modes this earlier return point exists. The rules name every such mode and confirm that the point is absent in every other mode.

For builders

Exact wording for builders and 85 pack tests

Exact wording for builders

This text decides the order of the steps for state-family identity, scope starts and endings, commits, loads, damage, build mismatch, copy conflicts, deletion, and device change. The questions and rows supply choices and cited game rules. They do not change the order.

A run begins at the player-observable attempt start named by scope-starts-in and ends at the result or exit named by scope-ends-in. Victory, death, and abandonment are common endings, but only the cited game rules decide. A save or load does not start or end a run. A session begins when play enters the world, match, lobby, or profile context named by scope-starts-in and ends at the exit, switch, or reset named by scope-ends-in. It continues through a pause, background interval, closure, or relaunch that returns to that same context; a missing commit may still prevent its earlier value from returning.

A save kind is one row of copy-kinds. A commit is one coherent accepted write of a save kind. A copy is a load candidate with its save-kind id, copy identity, any slot identity, build identity, commit identity, and complete state-family set. A conflict exists when the cited rule finds two accepted shared copies in one declared conflict scope that disagree and neither has already replaced the other. An earlier copy is a retained older commit named by a backup row.

### Change and commit

1. When state changes, keep each state-families row as one family under its cited game rule. The row's lifetime is the longest time for which a value of the family is kept. An until-event value ends at its cited game event. A boundary result may clear a value before its lifetime ends only when the row says so.

2. Evaluate run and session starts and endings from their separate cited player-observable events. A save action, automatic write, timer tick, process launch, process close, or load does not create a new run or session by itself.

3. Start a commit of a save kind only at its selected write trigger. A player save follows the cited save action. A checkpoint follows its named game event. Continuous writing follows each accepted change named by its rule. A timer follows the cited interval. A service-owned copy follows its authority's cited acceptance event.

4. A commit becomes loadable only when write-rule-declared-in reports success for the complete contains-declared-in set. A failed or partial write never replaces the last successful commit. Earlier copies are retained and ordered only by their backup and storage rules.

### Quit, crash, and return

5. On a normal quit, perform a final commit only when the cited write rule of the save kind requires one. For each state row, returns-last-commit restores its latest successful commit on return; does-not-return starts from the cited post-quit value. Uncommitted changes do not return. A copy removed at normal quit is no longer a later load choice.

6. On a crash, no unfinished commit succeeds. For each state row, returns-last-commit restores the last commit that succeeded before the crash; does-not-return starts from the cited post-crash value. With a timer or a checkpoint, a crash can therefore lose the changes made since the last successful commit. These changes are the possible loss window, and the cited write rule states it. A copy removed at crash is no longer a later load choice.

7. Select the requested slot or profile before activating state. A one-current save kind selects its current copy. manual-slots selects the player's named slot. A retained earlier copy is not another layout; the damage response and matching backup rule may select it later, and a backup row's cited restore route is also available to the player directly, independent of any damage response.

8. A local-device copy is available only on that device unless another cited transfer exists outside this adoption. A cloud-synced save kind obtains every accepted device and cloud candidate before conflict handling. A server-authoritative save kind obtains the service's accepted copy and does not treat an unaccepted local cache as equal authority. Read each candidate's save-kind, slot, build, and commit identity now. A candidate whose identity cannot be read is not a conflict candidate. If no candidate remains, run the damage response of the requested save kind immediately, without conflict or build comparison. A readable header with an unreadable gameplay body remains a candidate for steps 9 and 10, then reaches the damage response in step 11.

### Conflict, compatibility, and damage

9. If readable shared candidates conflict, apply the matching row's response before reading their gameplay state. A one-kind row settles only that save kind; a whole-set row settles every synced save kind together. select-by-rule chooses one complete copy. player-chooses-copy waits for one complete-copy choice. refuse-until-resolved activates neither. No response merges fields.

10. Compare the selected copy's writing build with the running build. Apply the save-kind override when present; otherwise apply the matching default answer for an older or a newer build. Refusal activates no state. Conversion produces one current-build copy before activation. A warning precedes the attempt and does not promise that it succeeds. If conversion fails, refuse the load and leave the source copy unchanged unless its cited rule says otherwise.

11. Read the selected copy as one coherent unit. If it is unreadable, apply the save-kind override or unreadable-copy-default. Refusal activates nothing. start-fresh activates the cited starting state without silently deleting the unreadable copy. Earlier-copy recovery follows the matching backup row, selects the newest usable earlier copy, and reports the lost interval. Repair activates one coherent repaired result and resets every unreadable part under the cited rule; failure to produce a coherent result refuses the load. Warning waits for the player's choice before any attempted activation.

12. Activate all state families in the accepted copy together. State families saved in another save kind keep the already active value from that kind; a state family without saved-in is never restored by this load.

13. If the accepted copy has an earlier-point-returns row, return continuous play to its cited earlier point. If that point is inside a run, continue the same run identity. Apply after-load only after successful activation: keeping the resume leaves it available, using it once makes it unavailable, and a player-mode answer follows the mode that was set before the load.

### Death, deletion, and another device

14. On death, apply every state's after-death result. clears-value removes the earlier value before later play. keeps-value retains it. If death is also the cited run end, every run-lifetime value clears even if no save action occurs. If it is the cited event for an until-event value, that value clears as well. Longer-lived unlocks, settings, and profile state follow their own rows. A copy with removed-at: death disappears from the load choices after these state results are settled.

15. On slot deletion, clear each clears-value row tied to that slot and keep each keeps-value row. no-slot records that the state has no related player-selected slot. Deleting a local profile applies after-local-profile-delete the same way and includes any slots whose cited rule makes them children of that profile. Device-data deletion ends device-lifetime state under its cited rule. Account deletion or reset ends account-lifetime state through scope-ends-in. At each event, remove every copy whose removed-at value names it.

16. On another eligible device, returns obtains the family from its cloud-synced or server-authoritative copy before activation and still runs conflict handling. does-not-return starts from the cited new-device value. A device change does not by itself delete the source device's copy.

17. After every event, no earlier value affects later play once its lifetime has ended or its selected boundary result cleared it. A later game rule may derive a new value, but that is new state rather than restoration of the cleared value. A mode-gated copy or earlier return point exists only while the cited player mode permits it.

Every settlement report identifies the state-family id, save-kind id or its absence, event, scope before and after, last successful commit when read, selected copy and build when loaded, override or default answer used, state result, and any lost interval. Conflict reports also identify both candidate commits and the selected response. Damage reports identify refusal, starting state, earlier-copy recovery, repaired parts, or warning choice without claiming an unattempted load succeeded.

Verification pack

sha256:4ec64b865a0ade721bc27b72550f9d1d57e3e93d9a060e72b6eba5890aea75fd

The format calls an adoption that has its matching pack Checked. The tests are included, but this does not mean that a game has passed them. An adoption without the pack is Promised. The builder must still build the chosen behavior.

85 pack tests

Placeholders are filled from the adoption's answers, numbers, rows, and test inputs.

Row.id begins and ends its run only at the cited events

run-scope-uses-cited-events

scenarioper state-families row

Applies when row lifetime is Run.

The run for Row.id begins at Row.scope starts in and ends at Row.scope ends in. Each save, automatic write, timer tick, load, close, or relaunch the adoption can construct does not create either boundary. For an event that the adoption cannot construct, this test checks nothing. The test names the addresses and restates nothing from them.

Given

a distinguishable Row.id value before, during, and after its run

When
  • play crosses the attempt start at Row.scope starts in, the run ending at Row.scope ends in, and each save, automatic write, timer tick, load, process close, and relaunch to the same context that the adoption can construct
Then
  • the run identity begins only at Row.scope starts in and ends only at Row.scope ends in
  • each constructed save, automatic write, timer tick, load, close, and relaunch does not by itself begin or end the run; for an event that the adoption cannot construct, this test checks nothing
Diagnostics
  • Instance-state-boundary-trace
  • Instance-run-identity
Row.id keeps one session through returns to the same context

session-scope-uses-cited-events

scenarioper state-families row

Applies when row lifetime is Session.

The session for Row.id begins at Row.scope starts in, continues through each constructible save, automatic write, timer tick, load, pause, background interval, closure, relaunch to the same context, and another family's run boundary, and ends at Row.scope ends in. For an event or a run boundary that the adoption cannot construct, this test checks nothing. The family's value still needs the declared commit and boundary result to return. The test names the addresses and restates nothing from them.

Given

a distinguishable Row.id value in the session that starts at Row.scope starts in

When
  • play pauses, enters the background, crosses each constructed save, automatic write, timer tick, and load, closes, relaunches to the same context, and finally crosses Row.scope ends in
  • where the adoption declares a state family with the lifetime run, play also crosses the run boundary of that family
Then
  • pause, background, closure, and relaunch to the same context retain one session identity
  • each constructed save, automatic write, timer tick, load, close, and relaunch does not by itself begin or end the session; for an event that the adoption cannot construct, this test checks nothing
  • crossing a run boundary declared by another family does not by itself end this session; where the adoption declares no state family with the lifetime run, this test checks nothing about a run boundary
  • the session ends only at Row.scope ends in; whether its earlier value returns still follows its commit and boundary results
Diagnostics
  • Instance-state-boundary-trace
  • Instance-session-identity
Row.id copies carry their complete identity and their complete state-family set

copy-carries-complete-identity

scenarioper copy-kinds row

Applies for every adoption

A copy of save kind Row.id is one coherent accepted commit with save-kind, copy, slot when present, build, and commit identities and the complete family set at Row.contains declared in. The test names the address and restates nothing from it.

Given

one accepted commit of the save kind named Row.id

When
  • the copy is recorded and later considered as a candidate
Then
  • the copy record carries save-kind id, copy identity, any slot identity, build identity, commit identity, and the complete state-family set named at Row.contains declared in
  • the commit record identifies one coherent accepted write rather than a collection of separately accepted fields
Diagnostics
  • Instance-commit-log
  • Instance-candidate-set
Row.id is a conflict only for two accepted unreplaced copies

conflict-has-two-unreplaced-accepted-copies

scenarioper copy-conflicts row

Applies for every adoption

Row.id is a conflict only for two accepted shared copies in one declared scope that disagree and have not replaced one another. Row.resolution declared in decides the cited facts; this test names the address and restates nothing from it.

Given

candidate pairs inside and outside the conflict scope governed by Row.resolution declared in

When
  • the game classifies each pair before reading gameplay state
Then
  • a conflict is recorded only when two accepted shared copies in one declared scope disagree and neither has replaced the other
  • an unaccepted, agreeing, out-of-scope, or already replaced pair is not recorded as a conflict
Diagnostics
  • Instance-candidate-set
  • Instance-conflict-report
Row.id follows its declared maximum lifetime

state-family-follows-maximum-lifetime

scenarioper state-families row

Applies when row lifetime is Run or Session or Slot or Profile or Device or Account or Until event or Not kept.

Row.id has a maximum lifetime of Bind maximum scope. Each boundary before the end of that lifetime follows the row's result, and the trace distinguishes a restored value from an equal value derived later. The family definition is at Row.state declared in; the test names the address and restates nothing from it.

Given

Row.id changes from an earlier value to a distinguishable value

When
  • the value is read immediately before and after every declared persistence boundary that Instance can construct
Then
  • the earlier value affects play for no longer than Bind maximum scope
  • a boundary before the end of that lifetime clears it exactly when Row.id's selected boundary result says so
  • the trace identifies restoration of the earlier value separately from a later derivation of an equal value
Diagnostics
  • Instance-state-boundary-trace
  • Instance-active-state-source
Row.id ends at its cited event

until-event-value-ends-at-cited-event

scenarioper state-families row

Applies when row lifetime is Until event.

Row.id follows its quit, crash, death, slot-deletion, local-profile-deletion, and device-change results at each boundary the adoption can construct and ends at Row.lifetime event declared in. This test checks nothing about a run or session boundary, because a value that lasts until an event declares no run or session scope. It names the address and restates nothing from it.

Given

a distinguishable Row.id value before the event at Row.lifetime event declared in

When
  • play crosses each of quit, crash, death, slot deletion, local-profile deletion, and device change that the adoption can construct, then the cited event; this test includes no run or session boundary, because a value that lasts until an event declares no run or session scope
Then
  • each constructed boundary follows Row.id's own row result; for a boundary that the adoption cannot construct, this test checks nothing
  • the earlier value ends at Row.lifetime event declared in and does not affect later play
Diagnostics
  • Instance-state-boundary-trace
  • Instance-active-state-source
Row.id never returns after its named interruption

not-kept-value-never-returns

scenarioper state-families row

Applies when row lifetime is Not kept.

The earlier Row.id value never returns after Row.scope ends in. An equal value derived later is recorded as new state. The test names the address and restates nothing from it.

Given

a distinguishable Row.id value before Row.scope ends in

When
  • play crosses Row.scope ends in and later reaches a point where an equal value can be derived
Then
  • the earlier value never returns after the boundary
  • the source record distinguishes a later derived equal value as new state
Diagnostics
  • Instance-state-boundary-trace
  • Instance-active-state-source
Row.id ends at its cited Row.lifetime boundary

slot-and-profile-end-at-cited-event

scenarioper state-families row

Applies when row lifetime is Slot or Profile.

The maximum lifetime of Row.id ends at Row.scope ends in. An equal value derived later is new state. The test names the address and restates nothing from it.

Given

a distinguishable Row.id value before Row.scope ends in

When
  • play crosses the cited lifetime ending
Then
  • the earlier value reaches the end of its maximum lifetime at Row.scope ends in and cannot affect later play
  • the source record distinguishes an equal value derived later as new state
Diagnostics
  • Instance-state-boundary-trace
  • Instance-active-state-source
Row.id starts a commit only at its selected trigger

commit-starts-only-at-selected-trigger

scenarioper copy-kinds row

Applies when row write trigger is Player save or Checkpoint or Continuous or Timer or Service owned.

A commit for Row.id begins only at Bind trigger under Row.write rule declared in. The test names the address and restates nothing from it.

Given

events around the write rule at Row.write rule declared in

When
  • the events occur before, at, and after Bind trigger
Then
  • one Row.id commit starts at Bind trigger and Bind negative
  • the commit log records which cited event started it
Diagnostics
  • Instance-commit-log
Row.id replaces its last commit only after complete success

commit-loadable-only-after-complete-success

scenarioper copy-kinds row

Applies for every adoption

Row.id becomes loadable only when Row.write rule declared in reports success for the complete family set at Row.contains declared in. A failed or partial write leaves the last successful commit in place. The test names both addresses and restates nothing from them.

Given

a last successful Row.id commit and later complete-success, failed, and partial write attempts under Row.write rule declared in

When
  • each attempt is followed by a return that requests Row.id
Then
  • only the attempt reported successful for the complete set at Row.contains declared in becomes loadable
  • a failed or partial attempt never replaces the last successful commit
  • the commit and load records distinguish the retained last commit from the attempts that did not succeed
Diagnostics
  • Instance-commit-log
  • Instance-load-result
  • Instance-active-state-source
Row.id makes a final quit commit only when its rule requires one

normal-quit-final-commit-follows-write-rule

scenarioper copy-kinds row

Applies for every adoption

On a normal quit, Row.id makes a final commit only when Row.write rule declared in requires one. Otherwise the earlier successful commit remains the last commit. The test names the address and restates nothing from it.

Given

each normal-quit case the adoption can construct for changed Row.id state under Row.write rule declared in

When
  • each normal quit completes
Then
  • where Row.write rule declared in requires a final commit, exactly one starts
  • where the rule does not require one, no final commit starts and the previous last successful commit remains; for a case that the adoption cannot construct, this test checks nothing
Diagnostics
  • Instance-commit-log
Row.id returns its last commit after a normal quit

normal-quit-returns-last-commit

scenarioper state-families row

Applies when row after normal quit is Returns last commit.

After a normal quit, Row.id returns from the latest successful commit of the save kind named by saved-in; its uncommitted change does not return. If the row has no saved-in, this test checks nothing about restoration.

Given

a committed Row.id value followed by a distinguishable uncommitted change

When
  • the game quits normally and returns through the same context
Then
  • where this family names a save kind at saved-in, the latest successful commit of that kind restores Row.id and the uncommitted change does not return
  • where this family has no saved-in, this test checks nothing about restoration
Diagnostics
  • Instance-commit-log
  • Instance-load-result
  • Instance-active-state-source
Row.id does not return after a normal quit

normal-quit-does-not-return

scenarioper state-families row

Applies when row after normal quit is Does not return.

After a normal quit, the earlier Row.id value does not return. Its post-quit value follows Row.state declared in, and the record distinguishes that result from restoration. The test names the address and restates nothing from it.

Given

a distinguishable Row.id value before a normal quit

When
  • the game quits normally and returns through its normal flow
Then
  • the earlier value does not become active
  • Row.id starts from the post-quit value governed at Row.state declared in
  • the source record distinguishes that value from restoration of the earlier value
Diagnostics
  • Instance-state-boundary-trace
  • Instance-active-state-source
Row.id returns its last completed commit after a crash

crash-returns-last-commit

scenarioper state-families row

Applies when row after crash is Returns last commit.

After a crash, no unfinished commit succeeds. Row.id returns from the last successful commit of the save kind named by saved-in, without later changes. If the row has no saved-in, this test checks nothing about restoration.

Given

a committed Row.id value, then a distinguishable change and an unfinished commit

When
  • the game crashes and returns through the same context
Then
  • the unfinished commit does not succeed
  • where this family names a save kind at saved-in, the last commit completed before the crash restores Row.id and the later change does not return
  • where this family has no saved-in, this test checks nothing about restoration
Diagnostics
  • Instance-commit-log
  • Instance-load-result
  • Instance-active-state-source
Row.id does not return after a crash

crash-does-not-return

scenarioper state-families row

Applies when row after crash is Does not return.

After a crash, the earlier Row.id value does not return. Any unfinished commit fails; if none can exist, this test checks nothing about an unfinished commit. Its post-crash value follows Row.state declared in. The test names the address and restates nothing from it.

Given

a distinguishable Row.id value and, where the adoption can construct one, an unfinished commit before a crash

When
  • the game crashes and returns through its normal flow
Then
  • the earlier value does not become active; where an unfinished commit exists, it does not succeed, and where none can exist, this test checks nothing about an unfinished commit
  • Row.id starts from the post-crash value governed at Row.state declared in
  • the source record distinguishes that value from restoration
Diagnostics
  • Instance-state-boundary-trace
  • Instance-active-state-source
Row.id reports its possible crash loss window

timer-and-checkpoint-have-crash-loss-window

scenarioper copy-kinds row

Applies when row write trigger is Timer or Checkpoint.

Row.write rule declared in states which later changes of Row.id a crash can lose. These changes are the possible loss window. The interrupted commit fails, and the report identifies the last successful commit and the lost interval. The test names the address and restates nothing from it.

Given

a successful Row.id commit, later changes inside the possible loss window at Row.write rule declared in, and a commit interrupted by a crash

When
  • the game returns after the crash
Then
  • the interrupted commit does not succeed
  • the settlement report identifies the last successful commit and the changes in the cited possible loss window that did not return
Diagnostics
  • Instance-commit-log
  • Instance-settlement-report
Row.id selects its requested copy before activation

layout-selects-requested-copy

scenarioper copy-kinds row

Applies when row layout is One current or Manual slots.

Before activation, Row.id Bind selection under Row.storage rule declared in. Where an earlier commit is retained, it is not another layout. Where none is retained, this test checks nothing about earlier commits. The test names the address and restates nothing from it.

Given

the player requests Row.id through the selection route at Row.storage rule declared in and, where the adoption retains one, an earlier commit is also available

When
  • selection completes before any state activation
Then
  • Row.id Bind selection
  • where an earlier commit is retained, it is not treated as another layout choice and remains available only through its matching backup and damage routes; where none is retained, this test checks nothing about earlier commits
Diagnostics
  • Instance-candidate-set
  • Instance-active-state-source
Row.id obtains candidates from its declared residence

residence-controls-authoritative-candidates

scenarioper copy-kinds row

Applies when row residence is Local device or Cloud synced or Server authoritative.

Row.id Bind candidates under Row.storage rule declared in. The test names the address and restates nothing from it.

Given

the candidate sources the adoption can construct for Row.id as governed at Row.storage rule declared in

When
  • the game builds the candidate set before conflict handling
Then
  • Row.id Bind candidates
Diagnostics
  • Instance-candidate-set
  • Instance-authority-trace
Row.id reads candidate identity before settlement

candidate-identity-precedes-settlement

scenarioper copy-kinds row

Applies for every adoption

Row.id reads candidate identity first. A candidate with an unreadable identity cannot enter conflict handling. When no candidate remains, the effective damage response runs immediately. A readable header with an unreadable body reaches the damage response only after conflict and build comparison.

Given

Row.id candidates with readable identity, unreadable identity, and a readable header with an unreadable gameplay body

When
  • the game reads candidate identity before conflict, build, or damage settlement
Then
  • save-kind, slot when present, build, and commit identity are read before gameplay state
  • an unreadable identity is not a conflict candidate; if no candidate remains, the effective damage response runs immediately without conflict or build comparison
  • a readable header with an unreadable body remains a candidate through conflict and build comparison before reaching damage settlement
Diagnostics
  • Instance-candidate-set
  • Instance-settlement-trace
  • Instance-damage-report
Row.id has no conflict response without a matching row

missing-conflict-row-runs-no-conflict-response

scenarioper copy-kinds row

Applies for every adoption

If Row.id has no matching conflict row, this contract performs no conflict response for it. If it has one, this test checks nothing.

Given

a candidate set for Row.id

When
  • the game looks for a matching copy-conflicts row before build comparison
Then
  • where no matching conflict row exists, no candidate is selected, refused, or replaced by a conflict response from this contract
  • where a matching row exists, this test checks nothing
Diagnostics
  • Instance-candidate-set
  • Instance-settlement-trace
Row.id settles only Row.copy kind

one-kind-conflict-settles-only-named-kind

scenarioper copy-conflicts row

Applies when row scope is This copy kind.

Row.id settles only Row.copy kind before gameplay state is read. It never merges fields, and state from other save kinds remains active. Row.resolution declared in governs the conflict; the test names the address and restates nothing from it.

Given

a conflict under Row.id plus non-conflicting active state from another save kind

When
  • the response at Row.resolution declared in runs before gameplay state is read
Then
  • only Row.copy kind candidates enter this conflict settlement
  • the response chooses or refuses complete copies and never merges fields
  • the other save kind keeps its active value
Diagnostics
  • Instance-candidate-set
  • Instance-conflict-report
  • Instance-active-state-source
Row.id settles every synced save kind together

all-synced-conflict-settles-whole-set

scenarioper copy-conflicts row

Applies when row scope is All synced kinds.

Row.id settles every synced save kind in its declared scope together, before gameplay state is read, and never merges fields. Row.resolution declared in governs the conflict; the test names the address and restates nothing from it.

Given

accepted disagreeing candidates across the synced save kinds in Row.id's scope

When
  • the response at Row.resolution declared in runs before gameplay state is read
Then
  • every synced save kind in the declared scope enters one settlement
  • the response chooses or refuses complete copies and never merges fields
Diagnostics
  • Instance-candidate-set
  • Instance-conflict-report
Row.id applies select-by-rule

conflict-select-by-rule

scenarioper copy-conflicts row

Applies when row response is Select by rule.

For Row.id, select-by-rule runs before gameplay state is read. The rule at Row.resolution declared in selects one complete copy before activation; only that copy proceeds, and fields are never merged. The test names the address and restates nothing from it.

Given

two accepted complete shared copies that conflict under Row.resolution declared in

When
  • the cited selection rule resolves the conflict
Then
  • the rule at Row.resolution declared in selects one complete copy before activation
  • only the selected copy's complete state can proceed; fields from candidates are never merged
Diagnostics
  • Instance-candidate-set
  • Instance-conflict-report
  • Instance-active-state-source
Row.id applies player-chooses-copy

conflict-player-chooses-copy

scenarioper copy-conflicts row

Applies when row response is Player chooses copy.

For Row.id, player-chooses-copy runs before gameplay state is read. No candidate state activates before the player chooses one complete copy; the chosen copy proceeds, and fields are never merged. The test names the address and restates nothing from it.

Given

two accepted complete shared copies that conflict under Row.resolution declared in

When
  • the player first waits without choosing and then chooses one candidate
Then
  • no candidate state activates before the player chooses one complete copy
  • the chosen complete copy proceeds and fields from candidates are never merged
Diagnostics
  • Instance-candidate-set
  • Instance-conflict-report
  • Instance-active-state-source
Row.id applies refuse-until-resolved

conflict-refuse-until-resolved

scenarioper copy-conflicts row

Applies when row response is Refuse until resolved.

For Row.id, refuse-until-resolved runs before gameplay state is read. No candidate activates while the conflict remains. After the cited clearing event at Row.resolution declared in, a load of the resulting accepted copy is no longer refused by this conflict. Fields are never merged. The test names the address and restates nothing from it.

Given

two accepted complete shared copies that conflict under Row.resolution declared in

When
  • a load is attempted before and after the cited conflict-clearing event
Then
  • no candidate activates while the conflict remains
  • after the cited clearing event at Row.resolution declared in, a load of the resulting accepted copy is no longer refused by this conflict
  • fields are never merged
Diagnostics
  • Instance-candidate-set
  • Instance-conflict-report
  • Instance-active-state-source
Row.id applies its older-build refuse-load override

older-build-override-refuse-load

scenarioper copy-kinds row

Applies when row older build copy is Refuse load.

Row.id overrides the default answer for an older build and refuses the load before any mismatched-build state activates. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected readable copy of save kind Row.id written by an older build, with no unresolved conflict

When
  • the player requests the copy
Then
  • loading stops before any state from the mismatched-build copy activates
  • the refusal record distinguishes refusal by build mismatch from an absent or unreadable copy
Diagnostics
  • Instance-writer-and-reader-builds
  • Instance-load-result
  • Instance-active-state-source
Row.id applies the default answer refuse-load for an older build

older-build-default-refuse-load

scenarioper copy-kinds row

Applies when Older build default is Refuse load and row older build copy is Use game default.

Row.id uses the default answer for an older build and refuses the load before any mismatched-build state activates. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected readable copy of save kind Row.id written by an older build, with no unresolved conflict

When
  • the player requests the copy
Then
  • loading stops before any state from the mismatched-build copy activates
  • the refusal record distinguishes refusal by build mismatch from an absent or unreadable copy
Diagnostics
  • Instance-writer-and-reader-builds
  • Instance-load-result
  • Instance-active-state-source
Row.id applies its older-build convert-and-load override

older-build-override-convert-and-load

scenarioper copy-kinds row

Applies when row older build copy is Convert and load.

Row.id overrides the default answer for an older build and converts the copy to one coherent current-build copy before successful activation; a failed conversion refuses the load and leaves the source copy unchanged unless its cited rule records another result for the source copy. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected readable copy of save kind Row.id written by an older build, with no unresolved conflict

When
  • one conversion succeeds and a second constructed conversion fails
Then
  • the successful conversion produces one coherent current-build copy before all of its carried families activate together
  • the failed conversion refuses activation and leaves the source copy unchanged unless its cited rule records another result for the source copy
  • the conversion record distinguishes success, refusal, and what happened to the source copy
Diagnostics
  • Instance-writer-and-reader-builds
  • Instance-conversion-result
  • Instance-load-result
  • Instance-active-state-source
Row.id applies the default answer convert-and-load for an older build

older-build-default-convert-and-load

scenarioper copy-kinds row

Applies when Older build default is Convert and load and row older build copy is Use game default.

Row.id uses the default answer for an older build and converts the copy to one coherent current-build copy before successful activation; a failed conversion refuses the load and leaves the source copy unchanged unless its cited rule records another result for the source copy. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected readable copy of save kind Row.id written by an older build, with no unresolved conflict

When
  • one conversion succeeds and a second constructed conversion fails
Then
  • the successful conversion produces one coherent current-build copy before all of its carried families activate together
  • the failed conversion refuses activation and leaves the source copy unchanged unless its cited rule records another result for the source copy
  • the conversion record distinguishes success, refusal, and what happened to the source copy
Diagnostics
  • Instance-writer-and-reader-builds
  • Instance-conversion-result
  • Instance-load-result
  • Instance-active-state-source
Row.id applies its older-build warn-and-load override

older-build-override-warn-and-load

scenarioper copy-kinds row

Applies when row older build copy is Warn and load.

Row.id overrides the default answer for an older build and warns before the attempt; cancellation activates nothing, and acceptance is recorded separately from success. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected readable copy of save kind Row.id written by an older build, with no unresolved conflict

When
  • the player first cancels the warning, then accepts a successful attempt, and finally accepts a constructed failed attempt
Then
  • canceling activates no state
  • the warning precedes both accepted attempts; the successful attempt activates every carried family together and the failed attempt activates none
  • warning acceptance is recorded separately from load success
Diagnostics
  • Instance-writer-and-reader-builds
  • Instance-warning-choice
  • Instance-load-result
  • Instance-active-state-source
Row.id applies the default answer warn-and-load for an older build

older-build-default-warn-and-load

scenarioper copy-kinds row

Applies when Older build default is Warn and load and row older build copy is Use game default.

Row.id uses the default answer for an older build and warns before the attempt; cancellation activates nothing, and acceptance is recorded separately from success. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected readable copy of save kind Row.id written by an older build, with no unresolved conflict

When
  • the player first cancels the warning, then accepts a successful attempt, and finally accepts a constructed failed attempt
Then
  • canceling activates no state
  • the warning precedes both accepted attempts; the successful attempt activates every carried family together and the failed attempt activates none
  • warning acceptance is recorded separately from load success
Diagnostics
  • Instance-writer-and-reader-builds
  • Instance-warning-choice
  • Instance-load-result
  • Instance-active-state-source
Row.id applies its newer-build refuse-load override

newer-build-override-refuse-load

scenarioper copy-kinds row

Applies when row newer build copy is Refuse load.

Row.id overrides the default answer for a newer build and refuses the load before any mismatched-build state activates. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected readable copy of save kind Row.id written by a newer build, with no unresolved conflict

When
  • the player requests the copy
Then
  • loading stops before any state from the mismatched-build copy activates
  • the refusal record distinguishes refusal from an absent or unreadable copy
Diagnostics
  • Instance-writer-and-reader-builds
  • Instance-load-result
  • Instance-active-state-source
Row.id applies the default answer refuse-load for a newer build

newer-build-default-refuse-load

scenarioper copy-kinds row

Applies when Newer build default is Refuse load and row newer build copy is Use game default.

Row.id uses the default answer for a newer build and refuses the load before any mismatched-build state activates. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected readable copy of save kind Row.id written by a newer build, with no unresolved conflict

When
  • the player requests the copy
Then
  • loading stops before any state from the mismatched-build copy activates
  • the refusal record distinguishes refusal from an absent or unreadable copy
Diagnostics
  • Instance-writer-and-reader-builds
  • Instance-load-result
  • Instance-active-state-source
Row.id applies its newer-build warn-and-load override

newer-build-override-warn-and-load

scenarioper copy-kinds row

Applies when row newer build copy is Warn and load.

Row.id overrides the default answer for a newer build and warns before the attempt; cancellation activates nothing, and acceptance is recorded separately from success. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected readable copy of save kind Row.id written by a newer build, with no unresolved conflict

When
  • the player first cancels the warning, then accepts a successful attempt, and finally accepts a constructed failed attempt
Then
  • canceling activates no state
  • the warning precedes both accepted attempts; the successful attempt activates every carried family together and the failed attempt activates none
  • warning acceptance is recorded separately from load success, and the failed attempt is distinguished from an absent or unreadable copy
Diagnostics
  • Instance-writer-and-reader-builds
  • Instance-warning-choice
  • Instance-load-result
  • Instance-active-state-source
Row.id applies the default answer warn-and-load for a newer build

newer-build-default-warn-and-load

scenarioper copy-kinds row

Applies when Newer build default is Warn and load and row newer build copy is Use game default.

Row.id uses the default answer for a newer build and warns before the attempt; cancellation activates nothing, and acceptance is recorded separately from success. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected readable copy of save kind Row.id written by a newer build, with no unresolved conflict

When
  • the player first cancels the warning, then accepts a successful attempt, and finally accepts a constructed failed attempt
Then
  • canceling activates no state
  • the warning precedes both accepted attempts; the successful attempt activates every carried family together and the failed attempt activates none
  • warning acceptance is recorded separately from load success, and the failed attempt is distinguished from an absent or unreadable copy
Diagnostics
  • Instance-writer-and-reader-builds
  • Instance-warning-choice
  • Instance-load-result
  • Instance-active-state-source
Row.id applies its unreadable-copy refuse-load override

unreadable-copy-override-refuse-load

scenarioper copy-kinds row

Applies when row unreadable copy is Refuse load.

Row.id overrides the default answer for an unreadable copy and refuses the load without activating, replacing, or repairing unreadable state. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected copy of save kind Row.id whose gameplay body is unreadable after conflict and build settlement

When
  • the player requests the unreadable copy
Then
  • no state from the unreadable copy becomes active
  • the unreadable copy is neither replaced nor repaired by this response
  • the load result distinguishes refusal from an absent copy
Diagnostics
  • Instance-damage-report
  • Instance-load-result
  • Instance-active-state-source
  • Instance-removal-log
Row.id applies the default answer refuse-load for an unreadable copy

unreadable-copy-default-refuse-load

scenarioper copy-kinds row

Applies when Unreadable copy default is Refuse load and row unreadable copy is Use game default.

Row.id uses the default answer for an unreadable copy and refuses the load without activating, replacing, or repairing unreadable state. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected copy of save kind Row.id whose gameplay body is unreadable after conflict and build settlement

When
  • the player requests the unreadable copy
Then
  • no state from the unreadable copy becomes active
  • the unreadable copy is neither replaced nor repaired by this response
  • the load result distinguishes refusal from an absent copy
Diagnostics
  • Instance-damage-report
  • Instance-load-result
  • Instance-active-state-source
  • Instance-removal-log
Row.id applies its unreadable-copy start-fresh override

unreadable-copy-override-start-fresh

scenarioper copy-kinds row

Applies when row unreadable copy is Start fresh.

Row.id overrides the default answer for an unreadable copy and activates the adoption's starting state without silently deleting or overwriting the unreadable copy. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected copy of save kind Row.id whose gameplay body is unreadable after conflict and build settlement

When
  • the player requests the unreadable copy
Then
  • the starting state named by the adoption becomes active instead of state from the unreadable copy
  • the unreadable copy is not silently deleted or overwritten
  • the source and removal records distinguish a new start from a deletion
Diagnostics
  • Instance-damage-report
  • Instance-load-result
  • Instance-active-state-source
  • Instance-removal-log
Row.id applies the default answer start-fresh for an unreadable copy

unreadable-copy-default-start-fresh

scenarioper copy-kinds row

Applies when Unreadable copy default is Start fresh and row unreadable copy is Use game default.

Row.id uses the default answer for an unreadable copy and activates the adoption's starting state without silently deleting or overwriting the unreadable copy. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected copy of save kind Row.id whose gameplay body is unreadable after conflict and build settlement

When
  • the player requests the unreadable copy
Then
  • the starting state named by the adoption becomes active instead of state from the unreadable copy
  • the unreadable copy is not silently deleted or overwritten
  • the source and removal records distinguish a new start from a deletion
Diagnostics
  • Instance-damage-report
  • Instance-load-result
  • Instance-active-state-source
  • Instance-removal-log
Row.id applies its unreadable-copy restore-earlier-copy override

unreadable-copy-override-restore-earlier-copy

scenarioper copy-kinds row

Applies when row unreadable copy is Restore earlier copy.

Row.id overrides the default answer for an unreadable copy and uses the matching backup row to activate the newest usable earlier copy and report the lost interval. Where none can be produced, the result follows the cited recovery rule and activates no state from the unreadable copy. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected copy of save kind Row.id whose gameplay body is unreadable after conflict and build settlement

When
  • the supported recovery route selects the newest usable earlier copy under the matching backup row
Then
  • the selected earlier copy becomes active as one complete copy
  • the damage report identifies the selected earlier commit and the lost interval
  • where no usable earlier copy can be produced, the result follows the cited recovery rule and activates no state from the unreadable copy
Diagnostics
  • Instance-damage-report
  • Instance-load-result
  • Instance-active-state-source
  • Instance-removal-log
Row.id applies the default answer restore-earlier-copy for an unreadable copy

unreadable-copy-default-restore-earlier-copy

scenarioper copy-kinds row

Applies when Unreadable copy default is Restore earlier copy and row unreadable copy is Use game default.

Row.id uses the default answer for an unreadable copy and uses the matching backup row to activate the newest usable earlier copy and report the lost interval. Where none can be produced, the result follows the cited recovery rule and activates no state from the unreadable copy. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected copy of save kind Row.id whose gameplay body is unreadable after conflict and build settlement

When
  • the supported recovery route selects the newest usable earlier copy under the matching backup row
Then
  • the selected earlier copy becomes active as one complete copy
  • the damage report identifies the selected earlier commit and the lost interval
  • where no usable earlier copy can be produced, the result follows the cited recovery rule and activates no state from the unreadable copy
Diagnostics
  • Instance-damage-report
  • Instance-load-result
  • Instance-active-state-source
  • Instance-removal-log
Row.id applies its unreadable-copy repair-readable-state override

unreadable-copy-override-repair-readable-state

scenarioper copy-kinds row

Applies when row unreadable copy is Repair readable state.

Row.id overrides the default answer for an unreadable copy and activates one coherent repaired result with every unreadable part reset under the cited rule; a failed repair refuses the load. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected copy of save kind Row.id whose gameplay body is unreadable after conflict and build settlement

When
  • one repair produces a coherent result and a second constructed repair cannot do so
Then
  • the successful repair activates one coherent result containing every readable part and the starting value for every unreadable part under the cited repair rule
  • the failed repair refuses the load and activates no state
  • the repair record distinguishes retained readable parts, reset parts, and failure
Diagnostics
  • Instance-damage-report
  • Instance-load-result
  • Instance-active-state-source
  • Instance-removal-log
Row.id applies the default answer repair-readable-state for an unreadable copy

unreadable-copy-default-repair-readable-state

scenarioper copy-kinds row

Applies when Unreadable copy default is Repair readable state and row unreadable copy is Use game default.

Row.id uses the default answer for an unreadable copy and activates one coherent repaired result with every unreadable part reset under the cited rule; a failed repair refuses the load. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected copy of save kind Row.id whose gameplay body is unreadable after conflict and build settlement

When
  • one repair produces a coherent result and a second constructed repair cannot do so
Then
  • the successful repair activates one coherent result containing every readable part and the starting value for every unreadable part under the cited repair rule
  • the failed repair refuses the load and activates no state
  • the repair record distinguishes retained readable parts, reset parts, and failure
Diagnostics
  • Instance-damage-report
  • Instance-load-result
  • Instance-active-state-source
  • Instance-removal-log
Row.id applies its unreadable-copy warn-and-try override

unreadable-copy-override-warn-and-try

scenarioper copy-kinds row

Applies when row unreadable copy is Warn and try.

Row.id overrides the default answer for an unreadable copy and waits for an explicit choice; cancellation activates nothing, and acceptance is recorded separately from success. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected copy of save kind Row.id whose gameplay body is unreadable after conflict and build settlement

When
  • the player first cancels the warning, then accepts a successful attempt, and finally accepts a constructed failed attempt
Then
  • no copy state activates before the explicit choice and cancellation activates nothing
  • the successful accepted attempt activates one coherent copy and the failed accepted attempt activates none
  • warning acceptance is recorded separately from load success
Diagnostics
  • Instance-damage-report
  • Instance-load-result
  • Instance-active-state-source
  • Instance-removal-log
Row.id applies the default answer warn-and-try for an unreadable copy

unreadable-copy-default-warn-and-try

scenarioper copy-kinds row

Applies when Unreadable copy default is Warn and try and row unreadable copy is Use game default.

Row.id uses the default answer for an unreadable copy and waits for an explicit choice; cancellation activates nothing, and acceptance is recorded separately from success. The observable consequence is stated here; the test restates nothing from the adoption's cited rule.

Given

a selected copy of save kind Row.id whose gameplay body is unreadable after conflict and build settlement

When
  • the player first cancels the warning, then accepts a successful attempt, and finally accepts a constructed failed attempt
Then
  • no copy state activates before the explicit choice and cancellation activates nothing
  • the successful accepted attempt activates one coherent copy and the failed accepted attempt activates none
  • warning acceptance is recorded separately from load success
Diagnostics
  • Instance-damage-report
  • Instance-load-result
  • Instance-active-state-source
  • Instance-removal-log
Row.id retains and restores earlier copies

backup-retains-orders-and-restores-earlier-copies

scenarioper backup-copies row

Applies for every adoption

Row.id retains and orders earlier copies under Row.backup rule declared in. Its direct player route at Row.restore rule declared in opens the newest usable one and reports the lost interval, independently of damage settlement. The test names both addresses and restates nothing from them.

Given

several earlier commits for the save kind named by Row.copy kind, including usable and unusable candidates

When
  • the game applies Row.backup rule declared in and the player directly uses Row.restore rule declared in
Then
  • earlier commits are retained and ordered only as Row.backup rule declared in and the storage rule of the save kind named at copy-kind provide
  • the newest usable earlier copy becomes active as one complete copy and the lost interval is reported
  • the direct route at Row.restore rule declared in remains available independently of any damage response
Diagnostics
  • Instance-backup-inventory
  • Instance-load-result
  • Instance-damage-report
Row.id loads a readable compatible conflict-free copy

readable-compatible-copy-activates-together

scenarioper copy-kinds row

Applies for every adoption

A readable, same-build, conflict-free copy of save kind Row.id loads successfully and activates every family at Row.contains declared in together from one commit. The test names the address and restates nothing from it.

Given

a selected readable copy of save kind Row.id from the running build with no conflict, carrying distinguishable values for every family at Row.contains declared in

When
  • the game loads the copy
Then
  • the load is accepted rather than refused
  • every carried state family activates together from one commit
  • no partial copy is visible at any point
Diagnostics
  • Instance-load-result
  • Instance-active-state-source
  • Instance-activation-trace
loading Row.id preserves state from other save kinds

load-preserves-families-from-other-kinds

scenarioper copy-kinds row

Applies for every adoption

Loading Row.id activates its carried families together and preserves the active value of every family saved in another save kind. If no other save kind exists, this test checks nothing about other save kinds.

Given

active distinguishable state from Row.id and, where the adoption declares one, another save kind

When
  • a readable compatible conflict-free copy of save kind Row.id loads successfully
Then
  • families carried by Row.id activate together from its selected commit
  • families saved in another save kind keep that kind's already active value
  • where no other save kind exists, this test checks nothing about other save kinds
Diagnostics
  • Instance-activation-trace
  • Instance-active-state-source
Row.id is never restored when it names no save kind

family-without-saved-in-is-never-restored

scenarioper state-families row

Applies for every adoption

For Row.id, when it has no saved-in, no return path restores its earlier value. For Row.id, when it names saved-in, only an accepted load of that save kind restores its earlier value; no other return path does.

Given

a distinguishable earlier Row.id value and every return path the adoption can construct

When
  • the return paths complete
Then
  • where Row.id has no saved-in, none of the return paths restores its earlier value
  • where Row.id names saved-in, its earlier value is restored only by an accepted load of that save kind and by no other return path
Diagnostics
  • Instance-state-boundary-trace
  • Instance-active-state-source
Row.id follows its after-load result

earlier-point-follows-after-load

scenarioper earlier-point-returns row

Applies when row after load is Resume stays or Resume is used once or Player mode decides.

After successful activation, Row.id returns play to Row.return rule declared in and keeps the run identity when the point is inside a run. Then Bind reuse. The test names the address and restates nothing from it.

Given

an accepted copy of the save kind Row.copy kind and an earlier point at Row.return rule declared in

When
  • activation succeeds and the player attempts the return twice
Then
  • continuous play returns to the cited earlier point only after successful activation
  • each return the row's after-load result permits retains the same run identity when the point is inside a run
  • Bind reuse
Diagnostics
  • Instance-load-result
  • Instance-return-point
  • Instance-run-identity
  • Instance-save-availability-after-load
Row.id returns to no earlier point without an earlier-point row

missing-earlier-point-row-returns-nowhere

scenarioper copy-kinds row

Applies for every adoption

A successful Row.id load returns continuous play to no earlier point under this contract when no earlier-point row names it. When a row names it, this test checks nothing.

Given

a successful Row.id load

When
  • the game checks for an earlier-point-returns row after activation
Then
  • where no row names Row.id, this contract returns continuous play to no earlier point
  • where a row names Row.id, this test checks nothing
Diagnostics
  • Instance-load-result
  • Instance-return-point
Row.id exists only in its named modes

earlier-point-mode-gate-controls-existence

scenarioper earlier-point-returns row

Applies when row mode gated is Only in named modes.

Row.id exists only while Row.mode rule declared in permits it. This test checks nothing about a mode change during an existing profile. It names the address and restates nothing from it.

Given

modes allowed and excluded by Row.mode rule declared in

When
  • the player looks for Row.id in each mode before loading
Then
  • Row.id exists in every allowed mode and is absent in every excluded mode
  • a mode change during an existing profile is outside this declaration and this test checks nothing about that change
Diagnostics
  • Instance-mode-trace
  • Instance-return-point
Row.id follows its death result

death-follows-family-result

scenarioper state-families row

Applies when row after death is Keeps value or Clears value.

On death, Row.id follows its selected result: Bind result.

Given

a distinguishable Row.id value immediately before death

When
  • death settles before any death-triggered copy removal the adoption declares
Then
  • Bind result
Diagnostics
  • Instance-state-boundary-trace
  • Instance-active-state-source
Row.id clears when death is its run end

death-at-run-end-clears-run-family

scenarioper state-families row

Applies when row lifetime is Run.

If death is the run end at Row.scope ends in, Row.id clears even without a save action. The test names the address and restates nothing from it.

Given

a distinguishable Row.id value before a death, where the run ending at Row.scope ends in is death

When
  • death occurs without another save action
Then
  • if the cited end at Row.scope ends in is death, the earlier run-lifetime value clears before later play even without a save action; if the cited end is not death, this test checks nothing
Diagnostics
  • Instance-state-boundary-trace
  • Instance-run-identity
Row.id clears when death is its cited event

death-at-until-event-clears-family

scenarioper state-families row

Applies when row lifetime is Until event.

If death is the event at Row.lifetime event declared in, Row.id clears before later play. The test names the address and restates nothing from it.

Given

a distinguishable Row.id value before death

When
  • death occurs, where death is the event cited at Row.lifetime event declared in
Then
  • if the cited event at Row.lifetime event declared in is death, the earlier value clears before later play; if the cited event is not death, this test checks nothing
Diagnostics
  • Instance-state-boundary-trace
  • Instance-active-state-source
Row.id follows its slot-deletion result

slot-deletion-follows-family-result

scenarioper state-families row

Applies when row after slot delete is Keeps value or Clears value or No slot.

On slot deletion, Row.id follows its selected result: Bind result.

Given

Bind case

When
  • Bind action
Then
  • Bind result
Diagnostics
  • Instance-state-boundary-trace
  • Instance-settlement-report
Row.id follows its local-profile-deletion result

local-profile-deletion-follows-family-result

scenarioper state-families row

Applies when row after local profile delete is Keeps value or Clears value or No profile.

On local-profile deletion, Row.id follows its selected result: Bind result. Where a related profile exists, child slots are included only as the adoption's cited rule provides. Where no related profile exists, this test checks nothing about child slots. The test restates nothing from the cited rule.

Given

Bind case

When
  • Bind action
Then
  • Bind result
Diagnostics
  • Instance-state-boundary-trace
  • Instance-settlement-report
  • Instance-removal-log
Row.id ends when device data is deleted

device-lifetime-ends-at-device-data-deletion

scenarioper state-families row

Applies when row lifetime is Device.

Device-data deletion ends Row.id through Row.scope ends in. The test names the address and restates nothing from it.

Given

a distinguishable Row.id value before device-data deletion

When
  • the event at Row.scope ends in deletes device data
Then
  • the earlier device-lifetime value ends and cannot affect later play
Diagnostics
  • Instance-state-boundary-trace
  • Instance-active-state-source
Row.id ends when its account is deleted or reset

account-lifetime-ends-at-account-deletion

scenarioper state-families row

Applies when row lifetime is Account.

Account deletion or reset ends Row.id through Row.scope ends in. The test names the address and restates nothing from it.

Given

a distinguishable Row.id value before account deletion or reset

When
  • the event at Row.scope ends in deletes or resets the account
Then
  • the earlier account-lifetime value ends and cannot affect later play
Diagnostics
  • Instance-state-boundary-trace
  • Instance-active-state-source
Row.id returns on another eligible device

another-device-returns-family

scenarioper state-families row

Applies when row on another device is Returns.

On another eligible device, Row.id is obtained from its synced or authoritative copy before activation. Conflict handling still runs and applies the response of the conflict row that matches that save kind; where no row matches, this test checks nothing about a conflict response. The device change does not delete any source-device copy; if none exists, this test checks nothing about a source-device copy.

Given

a distinguishable Row.id value on one device before the same eligible player continues on another

When
  • the new device settles available state
Then
  • the family is obtained from its synced or authoritative copy before activation and conflict handling still runs, applying the response of the conflict row that matches that save kind; where no conflict row matches it, this test checks nothing about a conflict response
  • any source-device copy is not deleted by the device change; where none exists, this test checks nothing about a source-device copy
Diagnostics
  • Instance-candidate-set
  • Instance-conflict-report
  • Instance-active-state-source
  • Instance-removal-log
Row.id does not return on another device

another-device-does-not-return-family

scenarioper state-families row

Applies when row on another device is Does not return.

On another eligible device, the earlier Row.id value does not return. Its new-device value follows Row.state declared in. The device change does not delete any source-device copy; if none exists, this test checks nothing about a source-device copy. The test names the address and restates nothing from it.

Given

a distinguishable Row.id value on one device before the same eligible player continues on another

When
  • the new device settles available state
Then
  • the earlier value does not activate and the family starts from the new-device value governed at Row.state declared in
  • any source-device copy is not deleted by the device change; where none exists, this test checks nothing about a source-device copy
Diagnostics
  • Instance-state-boundary-trace
  • Instance-active-state-source
  • Instance-removal-log
Row.id disappears at its removal event

removed-copy-disappears-at-selected-event

scenarioper copy-kinds row

Applies when row removed at is Normal quit or Crash or Death or Slot delete or Local profile delete or Device data delete or Account delete.

At Bind event, Row.id disappears from later load choices Bind order under Row.removal rule declared in. The record distinguishes removal from refusal or failure. The test names the address and restates nothing from it.

Given

a visible Row.id load choice before Bind event

When
  • Bind event occurs under Row.removal rule declared in
Then
  • the affected copy disappears from later load choices Bind order
  • the removal log records the event and distinguishes removal from a refused or failed load
Diagnostics
  • Instance-removal-log
  • Instance-load-result
Row.id exists only in its named modes

copy-kind-mode-gate-controls-existence

scenarioper copy-kinds row

Applies when row mode gated is Only in named modes.

Row.id exists only while Row.mode rule declared in permits it. This test checks nothing about a mode change during an existing profile. It names the address and restates nothing from it.

Given

modes allowed and excluded by Row.mode rule declared in

When
  • the player looks for Row.id in each mode
Then
  • Row.id exists in every allowed mode and is absent in every excluded mode
  • a mode change during an existing profile is outside this declaration and this test checks nothing about that change
Diagnostics
  • Instance-mode-trace
  • Instance-candidate-set
ended and cleared values stay absent

cleared-or-ended-value-never-affects-later-play

scenarioonce

Applies for every adoption

After a lifetime ends or a boundary result clears a value, that earlier value never affects later play. An equal value derived later is new state. If no such case can be constructed, this test checks nothing.

Given

every event the Instance adoption can construct where a lifetime ends or a boundary result clears an earlier value

When
  • later play reaches points where an equal value can be derived
Then
  • the earlier value never affects later play after the end or clearing event
  • any equal value derived later is recorded as new state rather than restoration
  • where the adoption can construct no such event, this test checks nothing
Diagnostics
  • Instance-state-boundary-trace
  • Instance-active-state-source
every settlement report records its complete result

settlement-report-is-complete

scenarioonce

Applies for every adoption

Every settlement report carries the mechanism's full identity, boundary, commit, selection, response, result, and loss fields. Conflict and damage reports add their required facts and never claim an unattempted success. For a case that the adoption cannot construct, this test checks nothing.

Given

each persistence settlement the Instance adoption can construct

When
  • the settlement completes or refuses
Then
  • the report identifies state-family id, save-kind id or its absence, event, scope before and after, last successful commit when read, selected copy and build when loaded, override or default answer used, state result, and any lost interval
  • a conflict report also identifies both candidate commits and the selected response
  • a damage report identifies refusal, starting state, earlier-copy recovery, repaired parts, or warning choice and never claims an unattempted load succeeded
  • where a conflict, damage case, load, or answered question does not arise, this test checks nothing about it
Diagnostics
  • Instance-settlement-report
  • Instance-conflict-report
  • Instance-damage-report
declaration check: Row.id's state citation states its duty

state-family-citation-states-its-duty

scenarioper state-families row

Applies for every adoption

This declaration check reads the adoption and cited prose, not the running game. Row.state declared in must name every field in Row.id and every point where it can affect later play. For a family that answers does-not-return after a quit, a crash, or on another device, it must also name the value the family starts from; otherwise this test checks nothing about a starting value. When the cited prose has another meaning, the adoption is invalid, and this test fails. The test names the address and restates nothing from it.

Given

the Instance adoption and the prose at Row.state declared in, not the running game

When
  • a reviewer checks the citation's meaning
Then
  • Row.state declared in names every field in this state family and every point where it can affect later play
  • where the row answers does-not-return after a quit, a crash, or on another device, Row.state declared in also names the value the family starts from; where it never gives that answer for those cases, this test checks nothing about a starting value
  • when the cited prose has another meaning, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
declaration check: Row.id names an existing save kind when saved

saved-in-joins-a-copy-kind

scenarioper state-families row

Applies for every adoption

This declaration check reads the adoption, not the running game. When Row.id has saved-in, it must name exactly one save kind in this adoption. When it names anything else, the adoption is invalid, and this test fails. With no saved-in, this test checks nothing. It says nothing about a family held in two places at once; one family names one restoring save kind.

Given

the Instance adoption document, not the running game

When
  • a reviewer reads Row.id's saved-in field
Then
  • where saved-in is present, it names exactly one copy-kinds row in this adoption; when it names anything else, the adoption is invalid, and this test fails
  • where saved-in is absent, this test checks nothing
Diagnostics
  • Instance-declaration-record
declaration check: Row.id names an existing save kind

backup-copy-kind-joins

scenarioper backup-copies row

Applies for every adoption

This declaration check reads the adoption, not the running game. Row.copy kind must name exactly one save kind in this adoption. When it names anything else, the adoption is invalid, and this test fails.

Given

the Instance adoption document, not the running game

When
  • a reviewer compares Row.copy kind with copy-kinds ids
Then
  • Row.copy kind names exactly one copy-kinds row in this adoption; when it names anything else, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
declaration check: Row.id names an existing shared save kind

conflict-copy-kind-joins

scenarioper copy-conflicts row

Applies when row scope is This copy kind.

This declaration check reads the adoption, not the running game. Row.copy kind must name exactly one shared save kind in this adoption. When it names anything else, the adoption is invalid, and this test fails.

Given

the Instance adoption document, not the running game

When
  • a reviewer compares Row.copy kind with copy-kinds ids and residences
Then
  • Row.copy kind names exactly one cloud-synced or server-authoritative copy-kinds row in this adoption; when it names anything else, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
declaration check: Row.id names an existing save kind

earlier-point-copy-kind-joins

scenarioper earlier-point-returns row

Applies for every adoption

This declaration check reads the adoption, not the running game. Row.copy kind must name exactly one save kind in this adoption. When it names anything else, the adoption is invalid, and this test fails.

Given

the Instance adoption document, not the running game

When
  • a reviewer compares Row.copy kind with copy-kinds ids
Then
  • Row.copy kind names exactly one copy-kinds row in this adoption; when it names anything else, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
declaration check: Row.id names account deletion or reset as its end

account-family-names-account-ending

scenarioper state-families row

Applies when row lifetime is Account.

This declaration check reads the adoption and cited prose, not the running game. Row.scope ends in must name account deletion or reset. When it has another meaning, the adoption is invalid, and this test fails. The test names the address and restates nothing from it.

Given

the Instance adoption and the prose at Row.scope ends in, not the running game

When
  • a reviewer checks the meaning of the cited ending
Then
  • Row.scope ends in names account deletion or reset; when it has another meaning, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
declaration check: Row.id's restore-earlier-copy override has a backup row

restore-earlier-override-has-backup

scenarioper copy-kinds row

Applies when row unreadable copy is Restore earlier copy.

This declaration check reads the adoption, not the running game. The Row.id override that restores an earlier copy requires a matching backup row. When that row is absent, the adoption is invalid, and this test fails.

Given

the Instance adoption document, not the running game

When
  • a reviewer compares Row.id with backup-copies copy-kind fields
Then
  • at least one backup-copies row names Row.id; when no row names it, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
declaration check: the default answer restore-earlier-copy for Row.id has a backup row

restore-earlier-default-has-backup

scenarioper copy-kinds row

Applies when Unreadable copy default is Restore earlier copy and row unreadable copy is Use game default.

This declaration check reads the adoption, not the running game. The default answer that restores an earlier copy applies to Row.id and requires a matching backup row. When that row is absent, the adoption is invalid, and this test fails.

Given

the Instance adoption document, not the running game

When
  • a reviewer compares Row.id with backup-copies copy-kind fields
Then
  • at least one backup-copies row names Row.id; when no row names it, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
declaration check: Row.id returns from a cloud-synced or server-authoritative save kind

returning-family-uses-shared-authority

scenarioper state-families row

Applies when row on another device is Returns.

This declaration check reads the adoption, not the running game. A returning Row.id family must name exactly one cloud-synced or server-authoritative save kind that restores it. When it does not, the adoption is invalid, and this test fails.

Given

the Instance adoption document, not the running game

When
  • a reviewer follows Row.id's saved-in name to a copy-kinds row
Then
  • saved-in is present and names exactly one cloud-synced or server-authoritative save kind; when it does not, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
declaration check: each conflict scope has at most one row

one-conflict-row-per-scope

scenarioonce

Applies for every adoption

This declaration check reads the adoption, not the running game. Each represented conflict scope has at most one row. When a scope has more than one row, the adoption is invalid, and this test fails. With no conflict rows, this test checks nothing.

Given

the Instance adoption document, not the running game

When
  • a reviewer groups copy-conflicts rows by a this-copy-kind name or the all-synced-kinds scope
Then
  • no declared scope has more than one conflict row; when a scope has more than one row, the adoption is invalid, and this test fails; with no conflict rows, this test checks nothing
Diagnostics
  • Instance-declaration-record
declaration check: each save kind has at most one earlier-point row

one-earlier-point-row-per-copy-kind

scenarioonce

Applies for every adoption

This declaration check reads the adoption, not the running game. Each save kind has at most one earlier-point row. When more than one row names a save kind, the adoption is invalid, and this test fails. With no such rows, this test checks nothing.

Given

the Instance adoption document, not the running game

When
  • a reviewer groups earlier-point-returns rows by copy-kind
Then
  • no save kind is named by more than one earlier-point-returns row; when more than one row names a save kind, the adoption is invalid, and this test fails; with no such rows, this test checks nothing
Diagnostics
  • Instance-declaration-record
declaration check: Row.id's required citations state their duties

copy-citations-state-their-duties

scenarioper copy-kinds row

Applies for every adoption

This declaration check reads the adoption and cited prose, not the running game. Row.contains declared in must state the state-family set. Row.write rule declared in must state when a write succeeds and what the loss window is. Row.storage rule declared in must state the residence, the authority, the identities, and the player selection that apply. When a duty is missing, the adoption is invalid, and this test fails. The test names the addresses and restates nothing from them.

Given

the Instance adoption and the prose at Row.contains declared in, Row.write rule declared in, and Row.storage rule declared in, not the running game

When
  • a reviewer checks each citation's meaning
Then
  • Row.contains declared in names the complete family set written and restored together
  • Row.write rule declared in names the trigger, success condition, final-write behavior, and quit or crash loss window
  • Row.storage rule declared in names residence, applicable sync or service acceptance and authority, layout, identities, and player selection
  • when a citation does not state its duty, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
declaration check: Row.id's backup citations state their duties

backup-citations-state-their-duties

scenarioper backup-copies row

Applies for every adoption

This declaration check reads the adoption and cited prose, not the running game. Row.backup rule declared in must state how earlier copies are retained, how they are ordered, how a usable earlier copy is selected, and what a recovery can lose. Row.restore rule declared in must state the direct restore route. When a duty is missing, the adoption is invalid, and this test fails. The test names both addresses and restates nothing from them.

Given

the Instance adoption and the prose at Row.backup rule declared in and Row.restore rule declared in, not the running game

When
  • a reviewer checks each citation's meaning
Then
  • Row.backup rule declared in names how earlier copies are retained, how they are ordered, how a usable earlier copy is selected, and the possible lost interval
  • Row.restore rule declared in names the supported direct restore route
  • when a citation does not state its duty, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
declaration check: Row.id's resolution citation states its duties

conflict-citation-states-its-duties

scenarioper copy-conflicts row

Applies for every adoption

This declaration check reads the adoption and cited prose, not the running game. Row.resolution declared in must state how disagreement is detected, how the identities of the copies are compared, how complete copies are selected or kept, and which event clears the conflict. When a duty is missing, the adoption is invalid, and this test fails. The test names the address and restates nothing from it.

Given

the Instance adoption and the prose at Row.resolution declared in, not the running game

When
  • a reviewer checks the citation's meaning
Then
  • Row.resolution declared in names disagreement detection, identity comparison, complete-copy selection or preservation, and the conflict-clearing event
  • when the citation does not state a duty, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
declaration check: Row.id's return citation states its duties

earlier-return-citation-states-its-duties

scenarioper earlier-point-returns row

Applies for every adoption

This declaration check reads the adoption and cited prose, not the running game. Row.return rule declared in must state the earlier point, when activation is successful, the run identity when the point is inside a run, and whether another load remains possible. When a duty is missing, the adoption is invalid, and this test fails. The test names the address and restates nothing from it.

Given

the Instance adoption and the prose at Row.return rule declared in, not the running game

When
  • a reviewer checks the citation's meaning
Then
  • Row.return rule declared in names the earlier point, successful activation, run identity when applicable, and whether another load remains possible
  • when the citation does not state a duty, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
declaration check: Row.id's removal citation states its duty

copy-removal-citation-states-its-duty

scenarioper copy-kinds row

Applies when row removed at is Normal quit or Crash or Death or Slot delete or Local profile delete or Device data delete or Account delete.

This declaration check reads the adoption and cited prose, not the running game. Row.removal rule declared in must state the exact removal event and visible result. When the cited prose has another meaning, the adoption is invalid, and this test fails. The test names the address and restates nothing from it.

Given

the Instance adoption and the prose at Row.removal rule declared in, not the running game

When
  • a reviewer checks the citation's meaning
Then
  • Row.removal rule declared in names the exact removal event and what the player sees afterward
  • when the cited prose has another meaning, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
declaration check: Row.id's mode citation states its duty

copy-mode-citation-states-its-duty

scenarioper copy-kinds row

Applies when row mode gated is Only in named modes.

This declaration check reads the adoption and cited prose, not the running game. Row.mode rule declared in must name all allowed modes and confirm absence elsewhere. When the cited prose has another meaning, the adoption is invalid, and this test fails. The test names the address and restates nothing from it.

Given

the Instance adoption and the prose at Row.mode rule declared in, not the running game

When
  • a reviewer checks the citation's meaning
Then
  • Row.mode rule declared in names every mode where the save kind exists and confirms absence elsewhere
  • when the cited prose has another meaning, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
declaration check: Row.id's player-mode return is mode-gated

player-mode-return-is-mode-gated

scenarioper earlier-point-returns row

Applies when row after load is Player mode decides.

This declaration check reads the adoption, not the running game. Row.id must be mode-gated: only-in-named-modes and cite its mode rule. When a player-mode-decides row has no mode gate, the adoption is invalid, and this test fails.

Given

the Instance adoption document, not the running game

When
  • a reviewer checks the player-mode return's mode gate and mode-rule citation
Then
  • Row.id is mode-gated: only-in-named-modes and cites its mode rule; when a player-mode-decides row has no mode gate, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
declaration check: Row.id's mode citation states its duty

earlier-point-mode-citation-states-its-duty

scenarioper earlier-point-returns row

Applies when row mode gated is Only in named modes.

This declaration check reads the adoption and cited prose, not the running game. Row.mode rule declared in must name all allowed modes and confirm absence elsewhere. When the cited prose has another meaning, the adoption is invalid, and this test fails. The test names the address and restates nothing from it.

Given

the Instance adoption and the prose at Row.mode rule declared in, not the running game

When
  • a reviewer checks the citation's meaning
Then
  • Row.mode rule declared in names every mode where the earlier point exists and confirms absence elsewhere
  • when the cited prose has another meaning, the adoption is invalid, and this test fails
Diagnostics
  • Instance-declaration-record
the persistence mechanism holds for the whole run

persistence-holds

generalonce

Applies for every adoption

Across Inputs scope, each family's value on both sides of every constructed boundary matches its row and the numbered settlement order holds. Every load the adoption can construct refuses partial state and activates all carried families together only when accepted. For a case that the adoption cannot construct, this test checks nothing. The pack's default audit seeds apply unless the adoption supplies its own.

Holds

every state family's distinguishable value on both sides of every constructed boundary matched its row; every commit, candidate, conflict, build comparison, damage response, activation, earlier return, deletion, device return, and settlement report that the adoption constructed followed the mechanism's numbered order; every constructed load that was partial or refused activated no state; every accepted load activated all carried families together; where the adoption can construct no load, conflict, damage, build mismatch, or earlier return, this test checks nothing about that case

Seeds

Inputs seeds

Scope

Inputs scope

Diagnostics
  • Instance-state-boundary-trace
  • Instance-commit-log
  • Instance-candidate-set
  • Instance-settlement-trace
  • Instance-load-result
  • Instance-active-state-source
  • Instance-settlement-report
  • Instance-first-ordering-violation

Use this contract in your package ↑