Unreasonably robust programming is the standard Hraness holds agent-written code to before it runs unattended: five written rules that make wrong values hard to construct and quick to find when they get through. The rules are ordinary. What makes the standard work is that the repositories apply all five everywhere, with no exception for a small script.
The standard exists because of how agent-written code usually breaks. It compiles, the happy path works, and the first unfamiliar input does something nobody planned for. It handles the case it was told about and nothing else. Most Hraness code is drafted by agents, reviewed by agents and a person, and shipped through checks that run without anyone watching, so “looks right” is not enough. The name admits that the bar is higher than a fair-minded reviewer would set for a person.
why agent code fails thin
The typical failure starts with a function written against a description (“the response contains a list of sessions”) instead of a type. In the third week the description turns out to be wrong: sessions can be empty, or null, or a string on the error path. The function doesn’t crash. It returns something slightly wrong, and the wrong value travels downstream until it becomes someone else’s bug.
The usual advice is to handle the error. This standard asks for a model in which the error can’t be expressed: instead of adding a case, change the types so the case cannot exist.
the five rules
Model invalid states out of existence. Prefer a type whose values are exactly the valid states over a loose type plus checks scattered where it is used. A Pending handshake that cannot express “finished twice” needs no check for it. Where the type system can’t exclude a state, exclude it at construction and make the constructor the only way in.
Parse every foreign value from unknown. Anything that crosses into the program (a file, a response, a user record, a provider payload) is unknown until a parser proves its shape. The parser rejects unknown keys, so a renamed field fails at the edge of the program instead of turning into undefined three layers deep.
Put a limit on every count, byte size, depth, and list. If a list can grow, say how large it may get and what happens past the limit. An unlimited input invites denial of service or silent truncation. Every new field in a shared data format carries a limit and a test for it.
Fail closed. When the evidence is ambiguous, the answer is no. A deployment check that cannot list every CI job does not assume the missing ones passed. A session whose clock ran backwards ends instead of carrying on as “probably fine.” When the code is in doubt, it takes the safe answer.
Keep wall-clock fields out of run records. A record of when something happened is evidence about the clock, not about the run. Deterministic replay needs two runs of the same input to produce the same record, byte for byte. Time enters as a parameter where a decision needs it.
what the rules buy
Review gets cheaper. Someone checking a parser, person or agent, doesn’t have to imagine what a hostile provider might send. The tests already list the malformed cases, and the closed types list what the function can do with them. Review shifts from “is this safe?” to “is the model right?”, and the second question has an answer.
Agents write better code against it. A model that sees parseForeign at every boundary writes the same shape without being told to. Agents copy conventions that are uniform; they only approximate one-off defensive code.
Failures say where they happened. Code that fails closed names the check that rejected the input. “The session closed because the clock regressed” tells you what to fix. “Something went wrong downstream” sends you digging.
what they cost
The first cost is writing parsers for shapes you already know. Parsing a three-field payload feels like ceremony until a fourth field appears upstream. The rule holds anyway, because parsing only where it “matters” means deciding at each boundary whether the input is hostile, and that decision is where the mistakes happen.
The second cost is more review. Because unknown keys are rejected, a provider that adds a field breaks a check, and a person or an agent has to read the change and decide the field is harmless before the parser accepts it. The friction is deliberate, and it is a real weekly cost.
The third is that the rules only work together. A codebase that parses 95% of its boundaries pays the debugging cost of the strict 95% and still has the failure modes of the loose 5%.
the rules in practice
The same rules run through the portfolio’s languages.
In TypeScript, unknown parsing happens at every external edge. GhostGet’s URL admission parses provider payloads and rejects unknown keys. Jungle’s merge queue parses its state from disk every time it opens instead of trusting what is in memory. The ALGAL manifest loader rejects an organism with fields it does not know.
In Rust, the equivalent is closed enums and #[serde(deny_unknown_fields)]. Once decoded, vhalla’s wire types cannot express a malformed envelope, and the session crate takes its clock and entropy as parameters so its code cannot reach outside the model.
In the release machinery, failing closed is literal. The site-promotion check accepts a CI run only when the complete list of jobs is present and every job reports success. A job it cannot find counts as failed.
limits
The rules don’t make a program correct. A closed type can encode the wrong rule, and a limit can cap the wrong thing. What they buy is that a wrong result stays contained and fails loudly instead of spreading quietly. The rest of this series covers the tools that catch what is left.
They don’t replace judgment. When a provider adds a key, someone still has to decide whether it is hostile or a legitimate schema change. The rule turns that decision into a visible event; it does not make the decision.
They don’t pay everywhere. A one-off analysis that runs once and is deleted doesn’t need a claims ledger. The portfolio applies the standard to code that runs unattended, holds other people’s data, or will be read by the next agent as if it were true.