pixellint

Pixellint 0.32.0 deepens destination rules and adds 13 error findings in corpus replay.

Pixellint 0.32.0 expands destination validation after a source review of all 137 vendor packs across 79 vendors. The manifests now contain 4,205 field contracts and 469 cross-field assertions, compared with 1,419 contracts and 213 assertions in the review baseline. The release also records what each pack still cannot validate from the available specification and request artifact.

Before release, we replayed every sample in a complete snapshot of the production D1 sample table against the released 0.31.12 engine and the new engine. Across 8,133 stored artifacts, error findings increased from 231 to 244, a net gain of 13, or 5.6%. Samples carrying at least one error decreased from 177 to 176.

Both numbers matter. One artifact can produce several findings, and a deeper validator can add checks while also removing an unsupported constraint. Four added findings concern redacted IP values. The comparison therefore describes a change in diagnostics on stored artifacts, with no claim that every added finding proves a defect in the original request.

Destination rules now cover more of the published field contracts.

A pack that checks a host and a few required keys can identify a destination while missing the contract that makes an event acceptable. This review worked through field types, permitted values, conditional requirements, numerical boundaries, and relationships between fields. The resulting checks cover more of the documented request surfaces in analytics, conversion APIs, mobile attribution, identity, and browser measurement.

JSON validation now distinguishes native types before checking scalar formats. A string containing a number is not automatically interchangeable with a JSON number. Manifests can express documented type unions, array and object bounds, decoded character or byte limits, and exact monetary constraints. Those details let a pack preserve a vendor's stated rule instead of substituting a broad regular expression.

The source review is available in the repository as RULEPACK_DEPTH_AUDIT.json. Each pack carries review evidence and explicit coverage limits. Reviewing every pack does not establish complete coverage of every vendor's specification. Account settings, authentication, undocumented behavior, and acceptance decisions at a remote service remain outside the evidence a pasted URL or payload can provide.

Conditional checks follow the event and its destination.

Conversion payloads often share an envelope but disagree on the meaning of their fields. The expanded packs can require a complete identifier alternative, apply a rule only for a selected event type, or check a timestamp against the destination's published window. The engine supports a fixed reference clock so boundary tests do not depend on the day the test suite runs.

The release adds stronger consent structure and destination-specific checks where published evidence supports them. These include TCF variable sections and policy checks, the reviewed US GPP layouts, and Google Additional Consent validation. An encoded consent string needs structural validation before a destination rule can make a useful statement about a field inside it.

A successful local validation still answers only the checks represented in the pack. It does not demonstrate that a vendor authenticated the sender, matched an account, attributed a conversion, or accepted an event. The audit separates those limits from rules that can be evaluated directly against the request. That separation keeps a green result useful without implying remote acceptance.

Batch and slot rules stay within their own records.

A batched request cannot borrow a required identifier from a neighboring event. Scoped contracts now support more of the relationships inside individual events, nested bodies, query slots, and repeated path items. The review also corrected alias leakage across batches and collisions between literal JSON member names and member paths.

Destination routing received separate attention. Adobe Audience Manager DCS ID and event requests have separate packs alongside the Experience Cloud ID surface. Nielsen's static SDK configuration loader also has its own pack. These distinctions prevent a contract written for one endpoint from being imposed on another request that happens to use a related vendor host.

Encoded bodies are another source of missed checks. Some measurement requests carry JSON in a URL parameter or a string inside a body. The expanded manifest machinery can inspect those documented representations and apply scoped field rules after decoding them. Source and fixture evidence remains attached to the destination rules rather than treating all encoded payloads as the same format.

The complete stored corpus produced a small net increase in errors.

The snapshot was read on October 8, 2026, and contains artifacts stored from August 27 through October 7 in UTC. It includes 7,980 VAST trackers, 108 URLs, and 45 JSON payloads. Both engines received the same stored bytes and automatic built-in pack selection. Previously recorded browser counters were excluded because they mix engine versions and may describe inputs before storage redaction.

The new engine added 19 error findings and removed six. Two samples newly carry an error, three no longer carry one, and 174 remain error-bearing. Finding sets changed on 32 samples; the other 8,101 were unchanged. Warnings increased from 678 to 694, while informational findings remained at 2,681. All rows were accounted for, with no engine exceptions or crashes.

The headline increase includes different kinds of change. Thirteen added errors were classified as rule behavior changes, four as redaction-sensitive findings, one as a severity promotion, and one as an equivalent FreeWheel rule rename. The rename also removes the previous code. These categories explain why a count of added codes is not a count of newly discovered request defects.

The sample mix limits what this replay can establish.

VAST trackers make up 98.1% of the snapshot. With only 45 JSON artifacts, this corpus exercises a small portion of the deeper conversion and analytics payload contracts. The per-pack fixtures remain essential evidence for those behaviors. A modest production-corpus delta can coexist with a substantial increase in tested field coverage when most stored requests never reach the added checks.

The ingestion worker removes identifiers and consent values before storage and deduplicates artifacts by hash. A literal REDACTED value is not an IP address, so a format rule can correctly reject the stored string while telling us nothing about the original address. The four added IP findings fall into that category. Stored sample rates also cannot be treated as traffic-weighted failure rates.

The samples have no independent labels establishing vendor acceptance. Three records losing their last error does not prove all three requests were valid. Some constraints were relaxed because the reviewed source did not support the previous hard bound, and a severity change can leave a warning behind. More findings alone would not establish improved precision; the useful result is the inspectable change backed by regression tests.

Replay exposed a brace placeholder that needed template handling.

During comparison, a OneLink impression template carrying af_ip={SA_IP_ADDRESS} acquired a literal IP format error. The named token represented a value to be supplied later. Treating the braces as an ordinary string made the expanded IP check too eager for a template. This release recognizes named single-brace macros and defers that literal value check.

Single-brace tracking placeholders are documented in the ecosystem. Affise's tracking URL macro reference includes named tokens for click identifiers and IP addresses. AppsFlyer's attribution-link examples also contain brace placeholders. That evidence supports recognizing the syntax; it does not establish that every placeholder name is supported by every destination.

The regression tests keep named tokens distinct from JSON objects, empty braces, and numeric brace content. Existing nested macro delimiters retain their handling. A raw named placeholder in an artifact explicitly marked as fired still receives the unresolved-macro diagnostic. Two malformed-JSON controls were made unambiguously malformed so their original expected error codes continued to test JSON syntax.

Release checks tie the source, fixtures, and WASM engine together.

The workspace passed 388 Rust tests, formatting, and clippy with warnings denied. All 137 pack source reviews passed the freshness check, and the generated reference matched the reviewed manifests. The npm smoke tests ran against a freshly built 0.32.0 WASM bundle and checked that the package version agrees with the bundled engine.

Native and WASM output was compared on 240 representative samples for each version, giving 480 engine comparisons. That selection includes every changed sample and every JSON payload in the snapshot. The comparisons passed. This establishes parity on the selected cases while the full 8,133-row comparison was run through the native engines.

For time-sensitive replay, the new engine used each sample's storage timestamp as the reference clock. Ingestion time is a proxy, because the original event execution time and template state were not recorded. A second complete candidate run used a shared analysis-time clock. The two candidate runs produced no finding differences in this snapshot. The public aggregate report records the method and denominators without publishing sample artifacts.

Upgrade to 0.32.0 and review changed diagnostics in your fixtures.

The minor release is available through the Rust packages, the pixellint npm package, and the CLI archives attached to the GitHub release. The pixellint.org playground uses the refreshed browser engine. Pin 0.32.0 in reproducible checks, then compare the findings on your own destination-specific fixtures before changing a launch gate.

Rust callers that construct BodySpecs::One directly need to wrap the BodySpec in Box::new. The JSON manifest representation is unchanged. Teams using the CLI or npm entry points should still review diagnostic changes, including severity changes and the scoped FreeWheel rule codes, when their checks assert an exact finding list.

The release's pack audit provides the next work list: documented checks with source evidence, fixtures that exercise them, and the remaining gaps for each destination. Add examples from your actual event families when extending a pack. The production replay gives a measured regression comparison for this release, while the source-target fixtures supply evidence for rules the stored corpus rarely exercises.

Pin the released version in your tooling.

Choose the installation command for your Rust CLI or Node project. Release downloads also include native CLI archives.

cargo install pixellint --version 0.32.0 --locked
npm install pixellint@0.32.0

Sources

Contract pages

The dated argument is above. These pages are the field lists.

Validate a tracking URL or payload Docs