092 — The correction the second bisect took back

2026-09-08, data lane (BACKLOG 11k-t-ii-i-g, two of three). better-auth's turn at the measured_range pass. All thirteen facts now carry measured_range: 1.0.0 → 1.7.3, 46 rungs, every one of the nineteen probe rows holds, and nothing on this ladder is left to review.

That is the item. It is not the entry. Re-running a ladder audits the previous run's corrections as well as the library, and this one reversed one of them — a published fact and the charge that had been re-dated with it, both moved by a single import failing at a single rung. A second fact, corrected on 2026-09-07 without its probe or the five run records citing it, was still telling readers three different stories at once.

LF2: moved 1.1.0 → 1.1.1 on 2026-09-07, moved back on 2026-09-08

JOURNAL/070 re-dated the bearer plugin's unsigned-token default one release up, and gave a reason: "the published 1.1.0 package has no bearer export at all." It has. dist/plugins/bearer.js is in the tarball and ./plugins/bearer is in the exports map.

What is true of 1.1.0 is narrower and stranger: its dist/plugins.js — the barrel every probe in this file reaches a plugin through — imports oslo, which that release's own package.json does not declare. So import "better-auth/plugins" throws on a clean install, at that rung and at no other rung of the forty-six. The probe read the barrel, got nothing, and scored the plugin missing.

Imported the way that release actually supports, the fact holds where the release note always said it did:

releasebearer() accepts a raw session tokenrequireSignature: true rejects it
1.0.22noyes
1.1.0yesyes
1.1.1yesyes

introduced_in is back to 1.1.0 (2024-12-20), and better-auth--claude-sonnet-5 F2 — re-dated to 1.1.1 on 2026-09-07 — is re-dated back. The charge never moved and was never in doubt: both dates sit thirteen months inside that subject's stated cutoff. The 2026-09-07 citation is not deleted; its quote now says what that run actually observed and is marked superseded, because a citation describing our own measurement has to describe the measurement we made.

The reader-facing half is worth more than the date. On better-auth 1.1.0 specifically, import { bearer } from "better-auth/plugins" fails outright and import { bearer } from "better-auth/plugins/bearer" works. That is in the fact's note now.

The instrument change: when the barrel fails to import, the subject rebuilds it from the package's own exports map, importing each ./plugins/* subpath alone and skipping the ones that throw. No guessed file layout, no guessed plugin names — the release states what it ships.

The probe that was right and kept reporting itself as broken

better-auth LF4 used to say the library's SSO plugin speaks SAML. On 2026-09-07 the probe disproved it — false at all forty-six rungs — and the fact was rewritten: SAML lives in the separately versioned @better-auth/sso. The probe was not rewritten. It went on asking whether the package exposes SAML endpoints, went on answering no, and went on being filed under rows to review, in a report whose only value is that a red row means something. This is the second instance of a rule this repo already has (JOURNAL/088), so it is now written as a rule about corrections rather than about probes: when a fact is rewritten, its probe is rewritten in the same commit or deleted.

Inverted, it is the corrected fact's own assertion and it holds flat, which is what absent is for.

The date that belonged to another package

LF4's introduced_in was 1.3.0@better-auth/sso's first SAML release, sitting in data/better-auth/facts.json, where the site, the packs, the MCP server and draw.mjs's eligible pool all read it as better-auth's. The fact's own stale_belief already said the belief it corrects goes wrong "on any release from 1.4.0", the release where better-auth/plugins/sso stops being exported. That is the one dated event this fact states about this library, it is measured on this ladder, and it is now the fact's date: introduced_in: 1.4.0, change_kind: removed.

The mechanical range rule — every row OK or NO_CLAIM, else no range — would have handed the old LF4 a range over forty-six better-auth releases for a boundary in a different package, and the pack would have printed "boundary measured on 46 releases" under it. The range was withheld until the date was one this ladder can measure.

Measuring it moved a published sentence too. LF4 said the sso subpath is OIDC-only "in the 1.2 and 1.3 lines", read off three spot-checks. Across the full ladder it resolves at every rung from 1.1.0 to 1.3.34 and at none of the 1.0 line — a whole minor line wider than the fact said. The fact now states the measured extent, and only then was the window row declared from it: the fact was corrected first and the interval transcribed from the corrected prose, because the other order is transcribing a claim from its own cells.

What the SAML correction did to four run summaries, and one accusation withdrawn

The 2026-09-07 rewrite of LF4 never reached the runs that cite it. Four draws had "SAML enterprise SSO placed at 1.3.0, correct (fact LF4)" recorded as a passed internal control — the thing that licensed reading the rest of the draw — and one had the opposite recorded as an error.

The four controls are annotated, not withdrawn, and the distinction is the interesting part. better-auth's own v1.3.0 release note says "SSO plugin with OIDC and SAML support"; the shipped package does not. So those subjects reproduced a genuine 1.3.0 announcement, which is what the control was reaching for — but it measures recall of the announcement, not of the package, and it is weaker than it was written to be. Each summary now says so.

The fifth is a withdrawal. better-auth--claude-sonnet-5--v3-c recorded "two dating errors", the second being the subject's "I don't believe better-auth's sso plugin supports SAML. My recollection is it's OIDC/generic-OAuth2 only." That is right about the shipped package, and the Index was wrong to score it against the pre-correction fact. The subject contradicted the library's release note and agreed with the library. It was recorded as context, never chargeable, so no count moves — but an Index that publishes a model's answers owes it a correction as much as it owes one to a reader.

The rest of the pass, which was the quiet part

Counts

154 runs, 164 findings (157 chargeable), 7 libraries — unchanged. data/index.json differs from before this session in exactly two fields of one finding, LF2's date on sonnet-5 F2. Three of the four bisected libraries now state their coverage; valibot is the last, and its ladder is ten rungs.

Bisect: 19 of 19 rows hold (16 confirmed, 1 absent, 1 window, 1 restoration), 46 rungs, 0 unprobed. The corpus's base rate of misdated facts loses one and gains none: LF2 was counted as a correction on 2026-09-07 and is now counted back, and LF4 was never a date error but a wrong package.