Pixellint 0.33.0 validates more destinations and links HTTP transport to event contracts.
Pixellint 0.33.0 adds 22 destination packs and expands validation of complete HTTP requests. It now ships 159 vendor packs across 85 vendors, with 5,147 field contracts and 526 cross-field assertions. The work combines a deeper review of existing destinations with a search for documented protocol surfaces present in stored samples that previously received only generic checks or vendor identification.
We replayed all 8,504 artifacts in a fresh, complete snapshot of the production sample table against released 0.32.0 and the new engine. The number selecting vendor protocol checks rose from 3,055 to 4,365. That is 1,310 additional artifacts reaching a destination pack, without any artifacts losing vendor selection. Each replay used the same stored bytes and the same reference clock.
Error findings rose from 259 to 284. Review of every added error supported 24 findings about empty IAS session identifiers. One additional Nielsen finding resulted from a value redacted during storage. Its original value is unavailable, so it contributes no supported customer-error gain. These counts describe observable local contract checks and preserve the limits of the stored evidence.
HTTP captures let the engine connect transport and payload requirements.
A destination can require the correct payload on a particular path with a particular method and media type. A bare JSON document does not expose those transport facts. The new request input carries the URL, method, headers and optional raw body together. Existing destination packs can evaluate that capture without guessing which service a generic event object belongs to.
The HTTP work deepened 39 existing packs and added 406 source-backed fixture cases before the destination expansion. It covers documented transport requirements, form fields, JSON and NDJSON entities, repeated header values, and decoded Basic authentication metadata. Captured method and header checks still run when a body representation cannot be inspected.
The raw body remains available for byte limits. A decoded object cannot stand in for the number of bytes sent on the wire: whitespace, escaping and Unicode can change that number. Header names are normalized for lookup, while repeated values remain visible. Findings retain their source and field names; transformed body offsets are not presented as offsets into the submitted capture.
Observed destinations guided22 additional protocol packs.
The sample table stores artifacts, rather than a catalog of rulepacks. We mapped their endpoints to the packs that actually selected them. A directory entry can identify a vendor without checking its measurement protocol, so directory identification was counted separately. This exposed missing surfaces even for vendors that already had a pack for another endpoint.
New packs cover Adnami, Amplified, AdCanvas, XPLN, TripleLift tracking and sync, IAS video and display pixels, and AppsFlyer impressions. Google additions separate IMA telemetry, interaction, PCS and Active View. Flashtalking impression and state collectors, Innovid legacy collectors, LiveRamp CTvid, Nielsen DAR, and three Trade Desk identity and conversion surfaces also receive dedicated checks.
The split follows endpoint contracts. A script loader does not establish the fields accepted by an event collector, and an identity match call does not establish a conversion schema. Trade Desk browser conversions were also deepened within their existing pack. Registration and source inventory checks ensure that the shipped manifests, fixture directories and published pack catalog agree.
Producer evidence has an explicit place in validation.
Some vendors publish an implementation or integration template without publishing a complete server rejection contract. Those sources still establish useful wire behavior: which fields the producer emits, how it encodes them, and which values it computes. They support scoped checks, provided the result does not turn an example into a universal backend mandate.
Amplified illustrates this distinction. The inspected SDK defines tuple columns for display, MRAID and OMID variants, including variable lists and conditional video extensions. The new pack checks every statically defined column in that source. Producer-only constraints are advisories. Unknown future labels, backend versions and session-dependent inputs remain documented limits.
Adnami decoding likewise uses an explicit warning severity for malformed producer payloads. IAS requirements supported by its integration guide retain error severity where a mandatory field is observably empty. The source audit records those choices per pack. A shared decoder can support both cases without reducing the severity of an unrelated destination contract.
Wire encodings now preserve the destination’s own units.
The new contracts required additional decoding behavior. Browser Base 64 JSON can use Latin-1 bytes through btoa, which differs from UTF-8 JSON encoded as Base 64. Both representations now have explicit manifest encodings. The existing UTF-8 decoder retains its behavior; a destination must opt into the browser representation.
Pipe-separated records are decoded as arrays of strings. Empty positions and trailing separators retain their place, and repeated query values are checked independently. This matters when a column index describes a measurement value: dropping an empty column shifts every field after it. The decoder does not invent native numeric types for wire strings.
Browser string limits can count UTF-16 code units instead of Unicode characters or UTF-8 bytes. Native JSON numeric sentinels are compared exactly, while URL strings keep literal comparison semantics. Per-event scalar uniqueness checks also keep each event’s array separate. These details prevent a schema that looks plausible from checking the wrong unit or joining unrelated records.
Consent aliases are bound to the selected endpoint.
A destination can document an alternative query name for its consent string. Recognizing that alias globally would allow an unrelated tracker to satisfy a requirement using a field that has another meaning. The engine now permits explicitly declared consent aliases only on a matching, selected, host-bound destination.
Each literal carrier is validated. A valid alias cannot conceal a malformed canonical value, and simultaneous carriers receive an ambiguity warning. The finding points to the actual field that supplied the value. Excluding the destination pack, changing the path, or validating an unrelated host removes that alias context.
The fixtures exercise these boundaries alongside malformed strings, macros and empty carriers. This is a local signal-format check. It cannot determine which consent state applied to a person at collection time or whether an account has the required permissions. Those questions need evidence outside the submitted artifact.
Full corpus replay separates detection gains from storage effects.
The snapshot contains 8,351 VAST trackers,108 URL artifacts and 45 JSON payloads. It contains no complete HTTP captures. Its selection gain is therefore evidence for the newly matched destination surfaces; it cannot measure the transport and raw-body gains introduced by the HTTP work. Those branches are exercised by authored request fixtures.
Artifacts with an error increased from 191 to 216. The raw increase is 25, while the supported gain is 24. IAS requires a populated session identifier on its UVP tracking URLs, and the stored xsId values were explicitly empty. The Nielsen table fixes its st field to image, but the ingestion worker had replaced that value with a redaction sentinel.
We preserved the redacted sample and the source contract. Rewriting the stored value would change the evaluation input, while weakening the vendor enum would change validation to fit an ingestion artifact. The aggregate report keeps the raw delta and marks the affected case ungradable. No captured identifiers, credentials, raw artifacts or customer host lists are published with it.
Independent cases exercise constraints absent from the stored corpus.
The destination expansion added 709 independently authored golden cases. Of these,701 use automatic destination selection and were compared across all three engine revisions. Eight incomplete JSON discriminator boundaries require explicit selection and pass in the workspace suite. Every candidate oracle passes, with no oracle regressions.
Among the automatically selected expansion cases,103 gain error detection and one clears a prior error. This set includes clean source examples and deliberate mutations of required fields, native types, ranges, batch members and protocol boundaries. Fixture counts are evaluation counts, rather than a traffic-weighted estimate of production defect frequency.
Local verification passed 442 workspace tests, Clippy with warnings denied, and npm smoke tests. Native and WASM reports agreed in 28,104 comparisons:27,615 comparisons covering every stored artifact and automatically selected new case across three engine pairs, plus 489 single-entry controls. The audit stores hashes of the source and reviewed fixtures so later edits cannot silently reuse stale evidence.
Remaining gaps determine the next depth round.
All 239 initially uncovered host profiles and one JSON bucket now have explicit dispositions. Review depth varies. Some have documented protocols and new checks; others have a host-level triage or an unsuccessful source-access attempt. A recorded disposition is not a certification that a complete vendor specification was available or implemented.
RTB House impression collectors, private callback variants and several opaque event surfaces still lack enough primary wire evidence for complete validation. Existing packs also record input limitations, version-dependent rules and requirements involving server or account state. The number of packs should not conceal those gaps.
The next round starts with documented local requirements that the engine can expose and test, then returns to the depth of existing packs. More matching endpoints are useful when they bring meaningful protocol checks. A deeper pack is useful when it reaches the vendor’s actual types, alternatives, conditional rules and boundaries with independent examples and an honest account of what remains unknown.
Sources
Contract pages
The dated argument is above. These pages are the field lists.