Web Forms · public review walkthrough

Inspect one static route, then stop where its evidence stops.

This authored walkthrough demonstrates how a reviewer can read one checked-in synthetic Web Forms handler, a source-plus-compiled route, an illustrative evidence detail, an unresolved command category, and a coverage gap without treating static reachability as observed application behavior.

Public claim level: demo for the seven-step reading sequence. The reused source-plus-compiled projection remains concept: No independent extractor output is checked in for its illustrative hop IDs, tiers, spans, or supporting aliases. Nothing here proves runtime execution, page activation, browser reachability, source/build authenticity, deployed identity, complete coverage, migration parity, release approval, or safety.

Walkthrough boundary

This is a reading guide, not a public product workbench.

Displayed materialAllowlisted fields from tracemap.webforms-source-compiled-proof.v1, checked-in public synthetic paths, and authored reviewer guidance.
Evidence postureThe sequence is a demo. Its reused route projection remains concept-level, partial, and bounded static evidence with explicit candidates and gaps.
Private workflowThe shipped native workbench remains private/local. This page does not load an index, accept uploads, query retained evidence, display raw handoffs, or reproduce private output.
Broader trackerIssue #744 remains open. This one-handler walkthrough does not claim every requested full-application workbench feature shipped.
Branch boundaryPR #803 repairs are not-shipped at implementation base 5fd50ebec3bef40c7c0b3660a754ab08cab45982 and are not cited as main-backed proof.

Guided review

Seven steps keep identity, evidence, uncertainty, and ownership together.

The steps are ordinary HTML and remain readable without JavaScript. Labels—not color—distinguish source observations, compiled structure, review candidates, and gaps.

Step 1 · scope and provenance

Confirm the exact public projection before reading a route.

Repository joefeser/tracemap; selected projection commit 5ffd4a54176c002e4c6d41ce0133eab5963ad79b; schema tracemap.webforms-source-compiled-proof.v1; coverage bounded-static-evidence; result partial; no path/work truncation recorded for this projection.

Read the full public-safe provenance card. Stop if the selected commit, projection digests, versions, coverage, or limitation cannot be confirmed.

Step 2 · choose the handler

Choose the synthetic Profile_Click row.

The authored selection points to samples/messy-dotnet-workspace/vb-lazy-constructor/Overview.aspx.vb:13-15, rule vb.syntax.declarations.v1, tier Tier3SyntaxOrTextual. Selection is navigation state, not proof that a page loaded or an event fired.

Step 3 · read the route

Follow ordered observations without flattening their tiers.

Read the six rows below in order. Source syntax, compiled metadata, candidate bridges, and the terminal candidate retain separate labels; display names are never join keys.

Open the ordered route. Stop before calling a candidate bridge an exact compiled call or runtime dispatch.

Step 4 · open evidence detail

Keep the rule, tier, span, version, coverage, and limitation adjacent.

The getter detail carries dotnet.compiled.member.v1, Tier2Structural, its public relative span, extractor version, projection namespace, and concept limitation.

Inspect the detail. The public projection does not carry an independently verified supporting-evidence ID, so the missing reference stays visible as a gap.

Step 5 · inspect the unresolved command

Read categorical state without publishing a value.

The selected outcome records command type state method-local-constant and command text state unresolved-operand, with IlCommandOperandValueUnresolved and IlCommandVirtualDispatchUnproven.

Inspect the safe command panel. Reaching an ExecuteScalar API candidate is not execution, success, parameter binding, or a returned value.

Step 6 · inspect a coverage gap

Preserve the virtual-dispatch uncertainty.

IlCommandVirtualDispatchUnproven remains Tier4Unknown with reduced coverage. Encoded callvirt structure does not select an override, provider, or runtime target.

Inspect the gap. Stop before a display-name join, type-only member guess, or candidate bridge becomes an exact destination.

Step 7 · ask or stop

Route the smallest unanswered question to an owner.

Ask the application/runtime owner which input, branch, and provider need separate observation; ask the database owner only for independently authorized database evidence. Stop if no public-safe evidence or owner can answer without exposing protected material.

Record the owner question and stop condition. The walkthrough never substitutes for source, database, runtime, migration, release, or application-owner review.

Ordered route

The weakest hop stays visible.

These rows reproduce the allowlisted dynamic-email ordering from the concept projection. They illustrate how to review the route; they are not independently projected extractor facts.

One synthetic handler to a static database API terminal candidate.
OrderLabelEvidence classRule and tierPublic spanLimitation
1Profile_Click handlersource syntaxvb.syntax.declarations.v1 · Tier3SyntaxOrTextualOverview.aspx.vb:13-15Declared handler syntax does not prove event binding, page activation, or firing.
2EmployeeInfo gettercompiled metadata observationdotnet.compiled.member.v1 · Tier2StructuralOverview.aspx.vb:20-25Metadata identity does not prove the getter executed or that this source built the binary.
3ProfileEmployee constructorsource-to-compiled review candidatecombined.paths.compiled-il-bridge.v1 · Tier3SyntaxOrTextualOverview.aspx.vb:31-35The projectless bridge is not an exact compiled call.
4GetProfilecompiled-route review candidatecombined.paths.compiled-il-bridge.v1 · Tier3SyntaxOrTextualOverview.aspx.vb:39-47Static ordering does not prove branch feasibility.
5GetEmail in provider DLLprovider-boundary candidatecombined.paths.compiled-il-bridge.v1 · Tier3SyntaxOrTextualPublicLog.vb:6-11The candidate does not select a provider implementation or runtime dispatch.
6ExecuteScalar API terminaldatabase-terminal candidatecombined.paths.compiled-il-bridge.v1 · Tier3SyntaxOrTextualPublicLog.vb:13-17A terminal API shape does not prove command execution, success, or returned data.

Evidence detail

One structural observation, with its missing support left open.

Illustrative subjectEmployeeInfo getter in the selected synthetic route.
Rule and tierdotnet.compiled.member.v1 · Tier2Structural.
Relative locationsamples/messy-dotnet-workspace/vb-lazy-constructor/Overview.aspx.vb:20-25.
Selected commit5ffd4a54176c002e4c6d41ce0133eab5963ad79b.
Extractor versionmanaged-metadata/0.1.2+cecil-0.11.6.
Coveragebounded-static-evidence; overall result partial.
NamespaceAuthored projection namespace public-projection:tracemap.webforms-source-compiled-proof.v1. An independent source/index namespace is unavailable in the public asset.
Supporting referenceunavailable-in-concept-projection. The asset intentionally omits unverified supporting evidence IDs; this is a visible provenance gap, not a value to reconstruct.
LimitationThis is an illustrative projection row, not an extractor-verified fact, runtime observation, build-authenticity claim, or deployed-binary identity.

Unresolved command

Keep the terminal shape; withhold the command value.

Terminal categoryExecuteScalar API candidate.
Command type statemethod-local-constant.
Command text stateunresolved-operand.
Outcome coveragebounded-static-evidence-with-explicit-gaps.
Retained gapsIlCommandOperandValueUnresolved and IlCommandVirtualDispatchUnproven.
Withheld materialNo command text, procedure name, parameter, connection material, configuration value, source snippet, or executable body is published.
Stop conditionStop before guessing the value, provider, database identity, execution, success, or returned value.

Coverage gap

A virtual-call shape is not a selected implementation.

ClassificationIlCommandVirtualDispatchUnproven.
Rule and tiercombined.paths.compiled-command-value.v1 · Tier4Unknown.
Relative locationsamples/messy-dotnet-workspace/vb-lazy-logging-provider/PublicLog.vb:13-17.
Coveragereduced.
MeaningEncoded callvirt evidence leaves runtime override and provider selection unresolved.
Next bounded questionCan the application/runtime owner provide separate authorized evidence for the selected provider and dispatch target?
Stop conditionStop before using a display name, type-only member guess, or candidate edge as an exact compiled destination or runtime target.

Reviewer decisions

Partial and missing evidence change the next question—not the observed facts.

Bounded next questions for common evidence states.
Evidence stateWhat remains knownNext bounded question and ownerStop condition
Reduced or partial source analysisRetained lower-tier evidence and named gaps.Ask the source/build owner which project, toolchain, or input evidence is missing.Stop before semantic, clean, absent, or complete wording.
Packet truncatedA deterministic retained prefix and an exact truncation reason.Ask the packet owner which configured inventory or graph bound was reached.Stop before absence or complete-inventory claims.
Query slice omittedReturned children and an explicit omission marker.Ask the evidence owner for the exact child pointer or a smaller authorized slice.Stop before treating an omitted child as absent.
Path or work limitedRetained paths and the named limit gap.Ask the application owner for a narrower question or a separately justified bound change.Stop before complete reachability claims.
Candidate bridge onlyA static review candidate and its bounded support.Ask the build/source owner whether exact PDB/source identity or unambiguous compiled evidence exists.Stop before calling the candidate an IL call or runtime target.
Required input missingExisting independent evidence plus the input gap.Ask the evidence owner for the exact authorized bounded input.Stop; never substitute a nearby or newer artifact or infer absence.
Command value unresolvedTerminal call shape and categorical value-origin gap.Ask the source/database owner whether separate authorized evidence can answer the value question.Stop before publishing or guessing command material.

Modernization packet bounds

Client and server behavior inventories have independent limits.

Client inventoryRetains at most the first 10,000 client behavior rows in deterministic order. Overflow marks the packet truncated and may retain WebFormsModernizationClientBehaviorLimitReached.
Server inventorySeparately retains at most the first 10,000 server behavior rows in deterministic order. Overflow marks the packet truncated and may retain WebFormsModernizationServerBehaviorLimitReached.
Gap-budget fallbackIf the configured packet gap budget is already saturated, a later inventory-specific gap may instead appear as WebFormsModernizationGapLimitReached. The specific client/server label is not guaranteed to survive saturation.
ScopeThese are packet behavior-inventory bounds—not handler, page, compiled-path, graph-node, total-fact, query, or general workbench limits. This selected projection does not claim it observed an inventory overflow.

Public-safe provenance

The walkthrough reuses the #806 projection; it creates no second evidence asset.

Projection identity and bounded-input commitments.
FieldRecorded valueBoundary
Repository and commitjoefeser/tracemap · 5ffd4a54176c002e4c6d41ce0133eab5963ad79bExact selected public projection revision, not current deployment identity.
Generator SHA-256a9aae27d806b21bb1d8c48f861d0b82533e0862f1c8b12e1683ad58027f4946cExact generator bytes for the reused projection.
Bounded input SHA-25623000bf21810695f70f3b5e9f96f460037c1611534b8a5ab7d63a8d63effcd54Canonical allowlisted privacy-projected input only; never a private source or binary hash.
Extractor/reporter versionsvb-semantic/0.8.7 · vb-syntax/0.3.23 · managed-metadata/0.1.2+cecil-0.11.6 · il-body-evidence/0.1.11+srm-10.0.0+cecil-0.11.6 · path-reporter/1.3Version labels do not upgrade illustrative fields to observed extractor output.
BoundsmaxDepth=20 · maxPaths=256 · maxTraversalWork=100000Absence beyond any bound is not proven.
Coveragebounded-static-evidence · partial · truncatedByPathOrWorkLimit=falseNot truncated by these path/work bounds does not mean complete application coverage.

Ask or stop

The next question stays smaller than the evidence gap.

Application/runtime ownerWhich input, branch, property state, provider, and runtime dispatch would need separate observation?
Build/source ownerCan exact source/PDB/compiled identity be established for the candidate bridge without substituting another artifact?
Database ownerIs separately authorized evidence available for database identity, effective command, parameters, execution, success, and returned data?
StopStop when the next answer would require private material, an unavailable input, a guessed join, a stronger tier, or an unsupported runtime, migration, release, completeness, or safety conclusion.

Non-claims

Static review does not observe the application.