Web Forms · source + compiled evidence

Follow the path without pretending the page ran.

One checked-in synthetic Web Forms corpus frames how a page handler, VB.NET property getter, constructor work, separate provider DLL, and static database API terminal can be reviewed together. The concept keeps illustrative rule, tier, span, coverage, and limit fields visible without calling them observed extractor evidence.

Public claim level: concept. This projection is bound to exact main revision 5ffd4a54176c002e4c6d41ce0133eab5963ad79b and checked-in public synthetic fixtures. No independent extractor output is checked in for the illustrated hops, so their IDs, tiers, and spans are not published as verified evidence. It is not runtime reachability, execution, build authenticity, deployment identity, compatibility, complete tracing, release approval, or safety.

Proof boundary

The asset is a privacy projection, not a copied scan.

Exact revision5ffd4a54176c002e4c6d41ce0133eab5963ad79b on main; later dev repairs are not silently included.
Public fixtureslazy-constructor, vb-lazy-constructor, and vb-lazy-logging-provider only.
ProjectionAllowlisted labels, categorical states, illustrative rule/tier/span fields, versions, and limits. Unverified supporting IDs are omitted.
Result statuspartial; explicit gaps and bounded traversal prevent a complete-coverage claim.
OmittedNo source snippets, command bodies, SQL text, literal hashes, parameter values, configuration, connection material, raw indexes, analyzer output, local paths, or private identities.

Evidence layers

One rule family can emit three different tiers.

combined.paths.compiled-il-bridge.v1 is not a tier. The emitted tier belongs to the individual edge, so the proof never flattens a mixed path to its strongest observation.

Tier1Semantic

Bound source + metadata identity

An exact admitted source/metadata identity can enter the compiled graph. Identity does not prove execution, reachability, freshness, or deployment.

Tier2Structural

Uniquely resolved encoded call

An admitted nonvirtual IL target can be joined structurally. Encoded call evidence does not prove that a branch or call executes.

Tier3SyntaxOrTextual

Review-only candidate

Virtual, unbound, source-to-publish, and database-terminal bridges stay candidates—not proven IL destinations or runtime provider selections.

Tier4Unknown

Explicit gap

Missing, ambiguous, unresolved, changed, or bounded evidence remains visible. A gap means reduced observation coverage, never absence.

Three bounded concept outcomes

The paths share context, but their value states do not.

The ordered chains illustrate the focused regression contract. Until independent extractor output is projected, they are not evidence identities and must not be used as proof that a hop was observed.

Outcome 1 · unresolved value

Dynamic email lookup → ExecuteScalar

The concept orders the getter and constructor across the provider boundary while keeping a runtime-composed command value unresolved-operand.

Coveragebounded-static-evidence-with-explicit-gaps
Value stateunresolved-operand; no command text or literal hash is published.
GapsIlCommandOperandValueUnresolved and IlCommandVirtualDispatchUnproven.
  1. Profile_Click handlervb.syntax.declarations.v1 · Tier3SyntaxOrTextual · Overview.aspx.vb:13-15
  2. EmployeeInfo getterdotnet.compiled.member.v1 · Tier2Structural · Overview.aspx.vb:20-25
  3. ProfileEmployee constructorcombined.paths.compiled-il-bridge.v1 · Tier3SyntaxOrTextual · Overview.aspx.vb:31-35
  4. GetProfilecombined.paths.compiled-il-bridge.v1 · Tier3SyntaxOrTextual · Overview.aspx.vb:39-47
  5. GetEmail · provider DLL boundarycombined.paths.compiled-il-bridge.v1 · Tier3SyntaxOrTextual · PublicLog.vb:6-11
  6. ExecuteScalar · database API candidatecombined.paths.compiled-il-bridge.v1 · Tier3SyntaxOrTextual · PublicLog.vb:13-17

Owner question: Which runtime input, branch, provider, and database context must be validated separately?

Outcome 2 · categorical state

Literal audit call → ExecuteScalar

The concept illustrates a static exception-branch call with a literal command category and command type without publishing the command body.

Coveragebounded-static-evidence-with-review-tier-value
Value statemethod-local-constant at Tier3SyntaxOrTextual.
StopStatic branch presence is not branch feasibility, execution, success, or database identity.
  1. GetProfile exception branchvb.syntax.callgraph.v1 · Tier3SyntaxOrTextual · Overview.aspx.vb:39-47
  2. WriteAudit · provider DLL boundarydotnet.compiled.member.v1 · Tier2Structural · PublicLog.vb:19-24
  3. Retained categorical command statecombined.paths.compiled-command-value.v1 · Tier3SyntaxOrTextual · PublicLog.vb:19-24
  4. ExecuteScalar · database API candidatecombined.paths.compiled-il-bridge.v1 · Tier3SyntaxOrTextual · PublicLog.vb:19-24

Owner question: Does runtime evidence show this branch was feasible and an approved operation actually ran?

Outcome 3 · independent Fill terminal

Constructor and property work → Fill

The independent concept chain orders the property getter, nested constructor work, provider boundary, and final Fill candidate.

Coveragebounded-static-evidence-with-terminal-candidate
Filter boundaryA Fill-only result does not resolve the other outcome’s command values.
GapsWarm/cold property state and provider dispatch remain unproven.
  1. Load_Click handlervb.syntax.declarations.v1 · Tier3SyntaxOrTextual · Overview.aspx.vb:9-11
  2. SyntheticChoices constructorcombined.paths.compiled-il-bridge.v1 · Tier3SyntaxOrTextual · Overview.aspx.vb:51-54
  3. EmployeeInfo gettercombined.paths.compiled-il-bridge.v1 · Tier3SyntaxOrTextual · Overview.aspx.vb:60-67
  4. SyntheticEmployee constructor + field initializationcombined.paths.compiled-il-bridge.v1 · Tier3SyntaxOrTextual · Overview.aspx.vb:70-88
  5. Lookup · provider DLL boundarydotnet.compiled.member.v1 · Tier2Structural · PublicLog.vb:92-98
  6. Fill · database API candidatecombined.paths.compiled-il-bridge.v1 · Tier3SyntaxOrTextual · PublicLog.vb:92-98

Owner question: Which property state, runtime provider, database target, and returned rows require separate validation?

Gaps and stop conditions

Stop where the evidence stops.

Projectless bridgecombined.paths.projectless-publish-candidate.v1 stays Tier3SyntaxOrTextual without exact source-method mapping.
Virtual callcallvirt does not select an override, provider, or runtime dispatch target.
Unresolved operandRuntime-composed material remains Tier4Unknown rather than guessed from a method name or nearby literal.
BoundsDepth 20, 256 paths, and 100,000 traversal-work units bound this fixture proof. A clean cap result is not complete application coverage.
PlatformThe public regression is cross-platform; real ASP.NET mapped and mapless publication validation remains Windows-only.

Provenance and versions

The projection can be reproduced and compared byte-for-byte.

Public-safe provenance for the checked-in projection.
FieldRecorded valueMeaning
Generator SHA-256a9aae27d806b21bb1d8c48f861d0b82533e0862f1c8b12e1683ad58027f4946cDigest of the exact site-owned generator bytes.
Bounded input SHA-25623000bf21810695f70f3b5e9f96f460037c1611534b8a5ab7d63a8d63effcd54Digest of the canonical allowlisted privacy projection—not a private scan, source tree, or binary.
Source extractorsvb-semantic/0.8.7
vb-syntax/0.3.23
Compiler-backed and projectless fallback evidence remain separate.
Compiled extractorsmanaged-metadata/0.1.2+cecil-0.11.6
il-body-evidence/0.1.11+srm-10.0.0+cecil-0.11.6
Metadata and dual-reader IL evidence versions on the selected revision.
Path reporteralgorithm 1.3Bounded deterministic traversal and explicit gaps.

Reproduce on public fixtures

No customer repository or database is required.

Focused regressionFrom the repository root, run dotnet test src/dotnet/tests/TraceMap.Tests/TraceMap.Tests.csproj --filter FullyQualifiedName~LazyConstructorLoggingTests.
Retained operator corpusWith PowerShell 7 and the documented toolchain, run pwsh -File scripts/wlocal.ps1. The fixture methods and database APIs are not executed.
Projection refreshRun node site/scripts/generate-webforms-source-compiled-proof.mjs, then review the generator and bounded-input digests before publishing.
Windows boundaryThe optional real ASP.NET publication check is Windows-only and is not evidence that a deployment or customer application works.

Orient the retained run before opening the projected chain.

The reproducible local demo and artifact map explains the five operator layouts, four query views, exact-tree Windows receipt, failure preservation, and which retained artifacts remain local. This page keeps the selected path illustration at concept; the local-demo receipt does not upgrade these hop IDs, tiers, or spans to observed extractor proof.

Review one route without upgrading its evidence.

The Web Forms review-workbench walkthrough demonstrates a seven-step reading sequence over this exact projection. The walkthrough is demo-level, while these illustrative hop IDs, tiers, spans, and supporting aliases remain concept-level.

Non-claims

This proof does not approve a modernization decision.

Move from the path to the owner question.

Use the manager proof-path guide to frame the review, the modernization evidence map to separate observed and missing evidence, and the review handoff to assign runtime, build, database, and migration questions. Keep the static/runtime boundary, gap register, reduced-coverage playbook, and claim ledger attached.