Browse docs

Start here

examplesGetting started with Flowdocumentation

Design

FoundationsLanguage architecturePhilosophy

Language specification

Program checkingConcurrencyDataEffectsResults, Tool problems, and faultsGrammarHistoryModules and importsLanguage specificationEvaluationStandard libraryToolsTypes

Runtime

Runtime architectureThe host boundaryDiagnosticsRunning a programThe history format

Guides

Writing programs that reach checkpointsImplementing Tools with a toolkitLoops that never returnRecursive delegationSharing types between Tool modulesHarnesses over tool registries

Runtime architecture

This document maps the language contract onto a conforming runtime. It owns three things: the layers a runtime is built from, the boundary between a Flow run and the application that embeds it, and the corpus's one ledger of what is not yet implemented.

The contract itself is owned above. language/architecture.md chooses the language mechanisms, and language/spec/ fixes the exact rules. A rule there is normative whether or not the current code satisfies it. Where an implementation disagrees, the rule stands and the gap is an implementation gap; Implementation gaps below is the only place in the corpus that records one.

What Flow owns

A Flow run owns the meaning of the orchestration written in Flow, and nothing else:

  • deterministic evaluation of a closed program;
  • the typed Tool call: its arguments, its one reply, and the check of that reply against the declared type;
  • scheduling and arbitration where they can change what a program observes, recorded as choices;
  • semantic history: the facts a program could not compute itself;
  • replay of a recorded run with no Tool bound;
  • pause and resume across process lifetimes, from history alone.

What the application owns

Everything around a run belongs to the application or the host that embeds it: the implementations behind each @tool declaration and their lifecycle, model loops, sessions, tool registries, credentials, approvals, budgets, filesystem, network and process policy, sandboxing, retries inside one call, retention and redaction of stored history, recovery beyond the run, and system-wide telemetry. Serves foundations: Applications remain applications.

None of these is a Flow language mechanism, and none may be inferred from a Tool's name, its signature, or anything an implementation claims about itself. A host may enforce any of them around the one dispatch seam and link its own records to Flow's run and call ids.

An application with its own goals, queues, transcript and durable product state therefore sits above or beside Flow. It may start a Flow run for a typed, replayable piece of work and correlate the run with its own records, or offer running Flow programs as a Tool to another run (execution.md). Flow does not become the surrounding application, and the application does not adopt Flow's semantics for the work it does outside a run.

application or host
  owns sessions, product state, credentials, approvals, isolation
  binds an implementation to every @tool declaration the run can reach
      |
      v
Flow runtime -> checked program -> evaluation -> semantic history
      |
      v
bound implementations, reached only through the dispatch seam

The runtime contract

A conforming runtime provides a small kernel. Each step names the specification that owns its rule.

  1. Form a closed program: resolve its modules and versions, check it, and compute its program identity (modules.md, checking.md, history.md).
  2. Bind an implementation to every @tool declaration the program can reach before the run starts, and refuse the run if one is missing; bind nothing for replay (tools.md, abi.md).
  3. Evaluate deterministically until the program makes a Tool call, waits, makes a choice, faults, or ends (semantics.md, concurrency.md).
  4. Write each fact before its consequence (history.md).
  5. Write checkpoints where the language allows them and when the runtime chooses, and resume from the latest one (history.md, execution.md).
  6. After a crash with a call out, leave the outcome to the host (history.md, execution.md).
  7. Fork a new run from a checkpoint of another, recording its parent (history.md).
  8. Store history so that a later process, with no network, can replay or resume it (trace.md).

An implementation is bound when the runtime can send it a call. Binding does not mean Flow started a process, opened a connection, or checked anything behind the implementation. An implementation may run in process, in another process, on another machine, or behind infrastructure Flow does not know; the reference host's process protocol is one choice among these (abi.md). Flow prescribes no provider, process, container or transport topology.

Runtime layers

A runtime is built from four layers plus its embedding surfaces. The layering is the durable part; the module decomposition is an implementation choice.

  • Program formation turns source into a checked program: source positions and names, parsing, module resolution, static checking, and lowering to an executable form.
  • Evaluation runs that program and yields at the boundary. It reaches no clock, filesystem, network or process of its own; every outside value arrives as a reply to a recorded call.
  • History writes the facts, checks them during replay, and serves them back through a storage port.
  • The host boundary owns binding and the one dispatch seam.
  • Embedding surfaces — an embeddable library, a command-line rim, an MCP server, and developer tooling such as the formatter and test runner — drive runs through those layers and add no semantics.

Two dependency rules survive every reorganization:

  • Evaluation calls a host port and never reaches around it into an operating-system interface. That is what makes the closed evaluation model checkable by reading the code rather than by trusting it.
  • Replay holds no dispatcher. The evaluator that replays a run has no dispatcher to call, not merely a rule against calling one.

A different evaluator conforms if it preserves what a program and its history can observe: the same call ids, the same facts in the same causal order, and the same replay verdicts.

The dispatch seam

Every Tool call passes through one runtime-owned path, and that path is neutral. It carries:

  • the declaration's identity and the fingerprint of its signature;
  • the history call id;
  • the canonical arguments, and for a generic Tool the schema of the type the caller expects;
  • exactly one reply: a value checked against the declared type, or a Tool problem;
  • cancellation, as a request and never as proof that nothing happened.

It carries no effect, no channel or class of operation, no authority, no policy verdict, and no statement about where an implementation runs. Effects stay in the checker and never reach the host protocol. A call to a clock, a file store, a person or a remote service is the same kind of call, and the runtime reads nothing into which is which.

A live run sends a call only after its Call fact is written. A replaying run has no dispatcher at all: it checks each call the program makes against the recorded one and reads the recorded reply. Missing history makes the replay incomplete and contradictory history makes it diverge; neither is permission to contact the world.

Host policy may wrap this seam. A host can consult an allowlist, ask a person, attach credentials, choose an isolation boundary, or refuse a call before forwarding it. Those decisions are host records. They reach a program only as the reply to a call, and a refused call is NotRun (errors.md).

spec/abi.md fixes the value encoding and the protocol across this seam; spec/execution.md owns how a runtime drives live, replayed and resumed runs across it.

History and durability

Durability has three separate duties, and none proves the others:

  • Replay re-runs a recorded program with nothing bound and reports whether the record matched. It is re-execution, not a reading of a log.
  • Resume starts a new process at the latest checkpoint, re-runs from there with recorded replies, and continues live where the record ends.
  • An interrupted call is one whose Call was written and whose reply was never accepted; what becomes of it is history.md's. Serves foundations: Honest uncertainty.

A runtime's own snapshot of evaluation state is a private cache (history.md). Serves foundations: Replay and resume read one history.

Reconciliation, compensation and restarting an implementation belong to the application and produce no Flow fact except through a new recorded call.

Versions

There are two versions. The language version is the standard library's major version, std@v1, which fixes the source language and std together (modules.md). The data version covers the value encoding, the Tool protocol and the history format, which share one encoding; it is recorded in every history's Start and exchanged when a Tool process describes itself (abi.md, trace.md). Within a major version, minors only add. Serves foundations: Stable meaning.

Flow is pre-release. No artifact carries a compatibility promise, no encoding is stable, and nothing in the repository is a published contract a later change must preserve. The first public release fixes the initial language version and data version, and versioned stability begins there.

Implementation gaps

This is the corpus's only implementation-status ledger.

The toolchain is rebuilt for the specifications. Every crate under crates/ belongs to the current target: flow-index and flow-span are the foundation the others stand on, flow-diagnostic holds the current diagnostic shape, flow-lexer tokenizes the current lexical grammar, flow-syntax parses the current grammar and reports its syntax-layer refusals, flow-fmt lays source out in its canonical form, flow-resolve forms a program from its imports and resolves its names, flow-check types it and checks its effects and discard rules, flow-ir lowers it to the core form an evaluator runs and computes its program identity, flow-value holds the values a run computes with, flow-abi encodes and decodes them at their types and describes those types, flow-eval evaluates the core with one machine per task and hands each Tool call and each timing choice to its driver, flow-history records a run's semantic history and replays, resumes and forks from it, flow-host keeps that history in a run directory on disk, settles the calls a crashed run left open, binds a run's Tools and dispatches its calls to Tool processes and implementations in process, flow-driver composes them into one embeddable façade that forms a program and starts, resumes, forks, replays and shows its runs, flow-cli is the flow binary over it, and flow-testing is test support. The CLI runs a program written in the language the specifications describe from start to end: the 22 corpus programs whose Tool modules are listed run to their end through flow run against Tool processes and replay to Matched. What the code does not yet do is the gaps below.

What exists

Present What it provides today
flow-index typed indices, index-keyed vectors, fixed-domain bit sets, a deduplicating worklist
flow-span byte extents carrying their file, the source map and line index, the identifier interner
flow-diagnostic diagnostics as data: an error's stable hyphenated code with an explanation, a message, its place, notes, and exact fixes marked safe or not and applied all or nothing; JSON and bounded text rendered from the value, with lines and code-point columns counted from 1
flow-lexer a total, lossless lexer for the lexical rules of grammar.md
flow-syntax a total, recovering parser for the whole of grammar.md, reporting the lexer's flags and the grammar's refusals as diagnostics
flow-value the run-time value model: unbounded Int with flooring div and divisor-signed %; exact normalized Decimal with division rounded to 34 significant digits; code-point Text with no implicit normalization; Bytes; List with constant-time indexing and parts; Dict and Set sorted by key over any data key; records, enum values and tuples by declaration; Duration and Instant as exact seconds; opaque function, task and host-token values; structural equality and total order over data, refusing what is not data; the text form interpolation inserts
flow-abi the value encoding at a type: every row of the encoding table, the Option-field shortcut and raw json.Value, the canonical form and its SHA-256 hash; type-directed decoding by the decoding table in reply and run-input modes, with a path and problem for every refusal, exact numbers, lone-surrogate and duplicate-key refusal, nothing decoded into an opaque type or, in input, a host type, and the depth, Int, Text and Bytes minimums; draft 2020-12 JSON Schemas with named types in $defs keyed by identity; @tool identity, canonical signature and fingerprint; a checkpoint's arguments written and rebuilt with each task as the id of the call it is parked on; the data version; its own JSON reader and canonical writer
flow-resolve forming a program: the closure of its imports through a source port, one version per repository and one std, cross-repository cycles, submitted bundles, the prelude, and every name resolved except a bare constructor's choice and method syntax, which need types; @test and @fake marks with the @tool function each fake names; a @tool type called as a function; and a root file the tree does not hold, reported as such
flow-check typing a resolved program: written types formed with aliases expanded, every expression typed by inference over its whole body, bare constructors and method syntax resolved by type, records and visibility, the data category with each type parameter's inferred requirements, @tool declarations and generic Tool calls, exhaustive matching and reachable arms, effects (!tool, !pure, pass-through, inferred local effects, pure top-level constants with no task operation), the discard rules, which functions can start a run, a test's signature and a fake's against the Tool it stands in for, and a fake's test values of a host type, refused anywhere else
flow-ir lowering a checked program to a closed core form: one call form for every callee (Flow functions, std's @lang intrinsics including the task operations, @tool functions, constructors and closures), a fake's test value of a host type as a primitive operation on its token, builds by declaration index, if, match and return for every surface convenience, decoded literals, closures with explicit captures, and every tail call marked; a structural verifier and a text rendering; program identity over every module's parsed program with its layout removed, the resolved commits and the std version
flow-eval a deterministic, sans-io step machine over the core form for each task: an explicit stack, so tail calls of every kind run in constant stack and non-tail calls nest only to a configurable depth; calls through every kind of function value, closures, local function groups, patterns, builds, return, and constants computed on their first read and kept for the run; std's @lang functions over flow-value; a Tool call handed out as a request naming the task, the task's call count, the declaration, the concrete type arguments and the arguments, and resumed with its reply; tasks: one machine per task under a scheduler whose order is fixed by the order of the driver's replies and answers, several calls out at once with replies in any order, spawn, await, stop, first, map and map_limit, ownership by the spawning call with tail calls continuing it, hand-off through returned values and closures, teardown in a fixed order with each stopped task reported with the calls it closed, first's pick and stop's finding asked of the driver as choices that hold until they can be met, the checkpoint opportunities with their parked tasks reported on request, each with the constructor its reply is built into and what that carries beside it, a checkpoint the driver takes restarting the root's ids under it, and a run restored from a checkpoint's function, arguments and parked tasks that goes on exactly as the run that took it; faults for division by zero, waiting on a stopped task, task.first([]) and the call depth, value nesting and Decimal scale limits, with their location, a fault in any task stopping the rest and ending the run
flow-history the seven facts in canonical JSON lines with value slots inline, as blobs or as holes, each fact hashed over its digest form into a mandatory chain, module sources as blobs, the data version, and a reader that refuses an unknown version, a member a fact does not define, a non-canonical line or a broken chain and reports a torn last line as truncation; a sans-io recorder that writes each fact before its consequence through a host's sink, admits delivered replies when every task waits, decodes them into BadReply when they do not fit, records first's picks, stops with what they found and the replies that closed their calls, checkpoints when a policy says and the end; replay with no dispatcher from Start or the latest checkpoint to Matched, Incomplete or Diverged at fact N, with holes and missing blobs incomplete and corruption reported as such; resume as replay that goes on live; forks from a checkpoint with replaced arguments or onto a newer program; holes that keep every hash, and archiving before the latest checkpoint
flow-host a run directory per run: the facts as canonical lines, content-addressed blobs and module sources, and the host's own records of pauses, halts and decisions about open calls, beside them and never read as facts; one writer at a time under an exclusive lock on the run's lock file, refusing a second in any process; a fact accepted when its blobs and then its lines are written, under one of two stated durabilities — written to the operating system, or with each new blob, the blob directory and the history synchronized to storage first; a failed write reported before its consequence and the writer refusing everything after it; a reader that reads without the lock and reports a torn last line as truncation, and a writer that cuts it before appending; corruption, including bytes that are not UTF-8, reported as a storage failure; archiving before the latest checkpoint and holes that delete a blob no source or schema names, each by replacing a whole file, with the archive read back in front of the history and its chain checked; on resume, each open call told apart as left pending at a recorded pause or interrupted by a crash or a halt, and settled as the host decides — a reply of Unknown by default, or the same call sent again under its id with its recorded arguments and schema; the run's state — completed, completed with an Err, faulted, paused, halted or interrupted — and its CLI exit code, read from history and the host's records; binding before a run starts: every @tool declaration the entry can reach, through calls, function values, closures and constants, bound by the host's override keyed by identity or else by the command its repository's flow-tool.toml names, each repository found through a port: a local directory the host names, or a remote repository's files checked out from the cache at the commit its version pins to, each command started once, after the host's approval hook says so, asked to describe itself and held to each declaration's fingerprint, and every unbound, unfitting, unapproved, unstartable or undescribed one refusing the run with nothing recorded, what was approved and bound kept among the host's records; a JSON-RPC 2.0 client over a process's standard input and output, one canonical line per message, with describe, call (and a generic Tool's schema), reply and cancel; implementations in process given the same fields as values, replying now, later from any thread, or parking a call; a dispatcher that sends each call the run hands out, delivers replies in the order they arrive on one channel, cancels each call a stop or a fault leaves out, admits a reply line longer than the host's limit, not UTF-8, not JSON or carrying no outcome as BadReply when it still names its call, drops and notes a reply for another run, a call not out to that implementation or a second reply, settles a call whose line never reached its process as NotRun and one whose process ended after it was written as Unknown, settles a call past the host's timeout, when it sets one, as Unknown and cancels it, pauses and records it when every task waits on calls nothing in the process holds, halts on request, and sends again the calls a resume settled to resend; the source port of a machine: a program's own directory, std from a directory, and remote repositories fetched by the system git into a per-machine cache under a lock per repository, each tag pinned to the commit it first named and refused as moved when it names another until an update accepts the new commit, a gone tag keeping its pin, a commit pinned to itself in full and fetched by name when no ref reaches it, files read at a pinned commit, version tags listed, a repository fetched once per cache value, and offline only what the cache holds
flow-driver the embeddable façade over formation, the host and history: a root file read, resolved, checked and lowered, every diagnostic refusing it at once; a stored run's program re-formed from the sources its history keeps and held to the identity its Start records; an entry chosen from the root module and judged able to start a run; a run started on a JSON object of input, refused with nothing recorded when the input does not decode or a Tool it can reach is unbound, unfit, unapproved, unstartable or undescribed; resumed from its history alone, replaying from its latest checkpoint, admitting each supplied reply for the open call it names and refusing one for a call that is not open or that is not an outcome, rebinding, and settling each call a dead process left out as Unknown or by sending it again under its id, a call left pending at a pause staying open; forked from a numbered or the latest checkpoint, with replaced arguments or onto a newer program, its parked calls settled as after a crash; replayed with nothing bound to its verdict; shown fact by fact with each value decoded, withheld or missing, beside the host's records; pins updated; the host's overrides keyed by a declaration or a whole module — a Tool process, an implementation in process, or a pause that answers nothing in the process — over std's clock, which it binds to the host's own: now the system's time and sleep a wait a stop cancels, each an ordinary recorded call; a halt hook for the host; a program's @test functions run against its @fakes, each bound by the identity of the declaration it stands in for and handed the call's number when it takes one, each fake evaluated beside the test from its call on a virtual clock that answers std's clock where no fake does, the reply due earliest handed over whenever every task waits, ties in call order, a closed call stopping the fake answering it, a test that can reach a declaration no fake stands in for not run, and two fakes for one declaration refusing every test; a saved history replayed from Start against the current version of its program, found beside the history or above it; every module of the program's own tree documented from its /// comments, with each declaration as written, a function's effect, each type parameter's inferred requirements and each @tool declaration's identity and fingerprint; the Tools an entry reaches and the places a checkpoint can be taken in a run of it; refusals, storage failures and runs that stop short of an outcome reported as diagnostics with published codes, located at the declaration or file they are about
flow-fmt the one canonical formatter, with no options: the layout of grammar.md's Canonical form over the token sequence, moving only whitespace and line ends and adding or dropping only trailing commas, so every comment stays on its line; idempotent; every result parsed again and compared with its source by the structural projection, and refused as a formatter defect rather than returned if they differ
flow-cli the flow binary: check, run, resume, fork, replay, history, update, test, fmt, doc, tools (every @tool declaration, for a toolkit) and mcp, each reporting human text or one JSON document whose diagnostics have the published shape; check listing the Tools main or --entry reaches and the places a checkpoint can be taken; test running the tests of each root file and replaying each saved history it is given or finds in a directory, exiting 0, 1 or 2; fmt formatting files in place, the .flow files under a directory, or standard input to standard output, and with --check writing nothing and exiting 1 for a file not in canonical form; doc printing Markdown or JSON, or writing one Markdown file per module under --out; an MCP server over standard input and output, one JSON-RPC message per line, answering initialize, ping, tools/list and tools/call with check, run, resume and replay, its bindings and approval its own command line's, never asking and refusing an implementation it was not approved for; an interrupt halting the run being driven, which exits 130 with the halt among the host's records; main or --entry, --input, --runs, --checkpoint-every; --tool DECL=COMMAND and --pause DECL binding a declaration or a module; resume --call ID --reply OUTCOME, and --resend to send again the calls a dead process left out; the exit codes 0, 1, 2, 3 and 4, a paused run printing its id and pending calls; a repository's implementation approved at the terminal the first time for a repository and commit and remembered in the cache, --allow for non-interactive use, and refused with a note saying how when there is no terminal; local imports read from the root file's directory, std from a directory on disk and remote repositories through the per-machine cache FLOW_CACHE names, fetching nothing under FLOW_OFFLINE
flow-testing test support: discovery, isolation, subprocess capture, blessing, diffs
tools/xtask the repository-arrangement checks the gate runs

The two dependency rules hold in the code that exists: flow-eval reaches no host interface and holds no dispatcher — a Tool call stops evaluation and hands out a request — and replay in flow-history is built without a dispatcher: it has none to hold. flow-host is the one crate that touches the filesystem and starts processes, and it keeps no snapshot of evaluation: a run resumes from its history alone.

Gaps

Gap The specification The code today
Data types types.md, data.md the checker types every built-in data type, records, enums, tuples, per-field pub and opaque, and judges the data category, and the value model holds every value with its equality, order, text and operators, which the evaluator computes with; equality, order, text and dropping walk a value on the heap, the captures of function values included; growing or joining a list that another value still holds copies it, in time linear in its length; a part of a list, or a dictionary an entry was removed from, keeps the depth bound of the larger value, so a nesting check that bound cannot settle walks that value's elements
Value encoding and the Tool protocol abi.md the value encoding, its canonical form and hash, decoding, schemas, and @tool identity and fingerprints exist, and json.encode and json.decode use them; flow-history decodes a run's input and a delivered reply and records encoded values; flow-host speaks describe, call, reply and cancel to a process, runs an MCP server through the MCP adapter, starts an ended process again, and binds by override or flow-tool.toml; toolkits for Python, TypeScript and Rust under toolkits/ generate from flow tools and pass the conformance program, whose sets and dictionaries are keyed by values Flow orders otherwise than their encodings, UTF-16 or insertion order; a generic Tool's type-parameter values are raw JSON, so a set of, or dictionary keyed by, a type parameter has no order in Rust and is ordered as json.Value is in Python and TypeScript, not as the type argument is; a TypeScript Set's has and Map's get find an object element or key by reference, not by Flow equality; the host's clock answers now from the system's time and sleep with a wait in process, and another implementation of it is bound only by an override; the CLI binds a file's own declarations and overrides only through --tool and --pause on the command line, with no configuration file of the host's; a decoded number's significant digits are held to the Int size limit and its plain notation to the Text limit, and the numbers of one JSON text, written out, may lengthen it by no more than the Text limit, and JSON nested more than twice the depth limit plus one is refused before it is decoded
Task ownership concurrency.md the evaluator runs tasks with their ownership, hand-off, stopping, the two task faults and immediate fault surfacing, and asks its driver for first's pick and for stop's finding where the stopping task does not already know it, which history records as Choice and Stop facts; the run's count of reachable tasks still visits every slot and frame of each running task, and a task learning what another knew copies its set of known finished tasks when another task shares it, in time linear in the finished tasks the run holds
History facts and checkpoints history.md, trace.md flow-history records, reads, replays, resumes and forks as the specifications say, as a library, and flow-host stores a history and settles its open calls after a crash, and flow-driver re-forms a program from the sources a history stores and runs it; a value-nesting fault building a restored parked task's constructor is located at the checkpointed function rather than at the constructor; a reply lost between a written Stop and the replies that follow it is recorded Unknown on resume; a replay host whose limits are smaller than the recording host's reports a recorded reply too deep for it as corruption
Storage and durability trace.md, execution.md flow-host keeps a run on a local filesystem only; synchronizing to storage relies on the filesystem honoring it, and on Windows, where it does not synchronize a directory, the directory entries of new blobs and replaced files are not synchronized, so the power-loss durability holds only for the file contents there; replacing a whole file while another process holds it open can fail on Windows; the second writer it refuses is found by an advisory lock, which a process that ignores the lock file does not see
Modules and versions modules.md resolution is complete behind a source port, and flow-host's port fetches remote repositories with the system git and keeps the per-machine pin cache, and flow update accepts a moved tag; a tag is compared with its remote once per resolution, and a repository that cannot be fetched is resolved from the cache, without that comparison, when the cache holds it; a repository is fetched from https:// and its name, so a host that serves git elsewhere is reached only through git's own URL rewriting; an abbreviated commit is found only among the commits a fetch of every branch and tag brings
Running, exit codes and the CLI execution.md the CLI checks, runs, resumes, forks, replays, shows histories, updates pins, tests, formats, documents and serves MCP with the exit codes the specification gives; flow check lists a tail call through a function value once for each top-level function of that many parameters the run names as a value, and judges a generic function called that way by its type parameters' requirements rather than by the value's type, and an enum that holds a function only through itself (A(T), B(fn)) as marked rather than unlisted; the CLI pauses a run only on a declaration --pause names, since a call out to a Tool process is waited on until it answers or the process ends; on a terminal, an interrupt also reaches the Tool processes the run started, and a call settled by one's exit before the halt is admitted is recorded like any other reply; the evaluator enforces the call-depth, value-nesting, Int, Decimal and Text size limits on a program's own values, defaulting to the minimums, as json.decode does

Tool implementations, editor support, packaging, security policy and release work are separate product milestones, not ledger gaps in the language and runtime target.

Runtime specifications

  • spec/abi.md — value encoding, the Tool process protocol, schemas, identity and fingerprints, binding, flow-tool.toml, toolkits and adapters;
  • spec/execution.md — running: entry selection, input and output, run states and CLI exit codes, pause and resume, crashes, limits, nested runs, forks, and the CLI and MCP surface;
  • spec/trace.md — the history format: fact encoding, hash chain, content-hashed values and sources, checkpoints, holes, data version;
  • spec/diagnostics.md — the diagnostic data shape, codes and fixes.

A runtime specification may refine how the language contract is realized. It never redefines what the contract means; that disagreement is a defect in the runtime document.