WRPL
Related · WRPL

WRPL — written for world models, published early

World-Rooted Projection Language

WRPL is the first programming language written in this workshop for world models and global AI. It starts from one claim: the source of truth is a world, not a text. A description in Chinese or English, a JSON document, a graph, an AI agent’s input — each is a projection of one versioned world, made for one observer under stated limits and checked against the world it came from. The basic concepts and theory may be feasible, but WRPL has not been used on an actual world model, so its practical benefit cannot be determined yet. It will be completed further in the future; it is published here early.

Version
v0.1.0
Release
private reference MVP
Used on a world model
not yet
Benefit vs strong baselines
PARTIAL
Tests
213
JSON Schemas
23 (frozen)
Python
3.11 / 3.12 / 3.13
Runtime dependencies
none
License
none selected
Read this first

A concept that has not met a world model yet

WRPL was written for world models, and there is no world model here to run it on. Everything on this page was built and tested in a reference implementation on one small demo world: a room with a table, a shelf, a closed door, a red cup on the table — its colour observed, its material unknown — and one note visible only internally. That shows the architecture holds together on that world. It does not show that WRPL helps a real world model, or that it scales to one.

The release’s own benchmark is mixed, and it says so. Against strong conventional baselines, WRPL adds four capabilities, ties on three properties, and runs 22 to 26 times slower on the demo world. Whether its extra contracts are worth that cost on a large world has not been measured.

In one line: the basic concepts and theory may be feasible; WRPL has not been used on an actual world model; its practical benefit cannot be determined yet; it is published early and will be completed further.

The idea

The world is canonical; language is a projection

WRPL does not write a world down in one language and translate it. It keeps one versioned world and derives every surface from it, under contracts that say what each surface must keep, may drop and may change.

01

World ≠ language

The world is held once, as a versioned WorldIR with branches and revisions: objects, states, relations, evidence, and what is still unknown. Chinese, English, JSON, graphs and agent inputs are derived from it; none of them is the world.

02

Who is looking

A projection names its observer, task, scope and authority, a budget in tokens, time and region, and a level of detail. Declared authority can never exceed what the runtime grants, and widening the scope requires authorizing again.

03

Lossy ≠ incorrect

Every surface leaves something out. WRPL turns the omission into a contract: preserve, allow_loss and forbid_loss say what must survive and what may be dropped, and every surface carries a record of what it dropped, which the verifier checks. They are semantic contracts, not rendering hints.

04

Editable ≠ authorized

A projection is read-only by default. An edit on a surface becomes a patch, then a proposed world mutation, and changes the world only after validation, authorization and an explicit commit, which creates a new revision.

The language

One projection, written in WRPL

One of the five projections in the reference example: the current scene of the demo world, described to a user in Traditional Chinese. A WRPL file declares projections like this one; each says what a surface must be, not how to render it.

wrpl 0.1

projection demo.zh {
    from world current
    observer user
    task "describe_current_scene"
    scope scene.current
    authority inherit

    budget {
        tokens <= 1200
        time_ms <= 500
        region <= 128
    }

    lod 2

    preserve {
        identity
        state
        relation
        epistemic_status
    }

    allow_loss {
        full_history
        deep_provenance
    }

    target natural_language("zh-TW")
    roundtrip proposal_only

    verify {
        source_revision
        identity
        required_invariants
    }

    on_failure fail_closed
}

Natural-language targets default to proposal_only: a sentence may propose a change to the world but can never commit one.

One world, five surfaces

The reference example

The five projections of the demo world. Each is verified independently, and all five reduce to the same revision-scoped semantic kernel, so they are checked against each other as well as against the world.

ProjectionSurface
demo.zhTraditional Chinese text
demo.enEnglish text
demo.jsonstructured JSON
demo.graphnode-edge graph JSON
demo.agentstructured input for an AI agent

The text surfaces are produced deterministically, not by a language model. The agent’s projection gets more detail and a larger budget, keeps the world’s unknowns, and must also pass a check of its own loss contract.

Reading the world

From source to a verified surface

ProjectionIR, the resolved plan, WorldIR and RepresentationIR each have a frozen JSON Schema, and the program, the plan and the semantic kernel are each identified by a deterministic SHA-256 hash.

WRPL source
AST
ProjectionIR
resolved plan
WorldIR
RepresentationIR
surface
independent verification

The verifier is a separate program from the producer. It reopens the written artifacts from disk and checks them against the world — revision, digests, entities, states and relations, epistemic status, unknowns and loss metadata — then extracts each surface’s meaning on its own and compares all five through the semantic kernel.

Changing the world

An edit is a proposal until it is committed

Writing back is a separate path from reading, and the read adapter has no commit method at all. In the demo world an AI agent may propose but not commit; committing takes an internal or admin principal.

surface edit
PatchIR
WorldMutationIR
validation
authorization
explicit commit
new revision
targeted invalidation
verified reprojection

In the reference run the cup is changed from red to blue. The commit creates revision 2, the five revision-1 surfaces are marked stale, and five refreshed surfaces are produced and verified against revision 2. In v0.1 the only executable edit is replacing an existing state field; every other kind of edit fails closed.

Measured

Against strong baselines: four gains, three ties, one loss

The release compares WRPL with a minimal template system (B0) and two strong conventional designs: structured JSON with multiple views (B1), and a graph or workflow source with views (B2). B1 and B2 are the comparison that matters.

OutcomeProperty
tieIdentity traceability
tieInternal note kept out of public views
tieStale and unauthorized writes blocked
WRPLIndependent tamper detection
WRPLExplicit loss contract
WRPLCross-surface equivalence check
WRPLAudit completeness
B1/B2Time per run on the demo world

The release’s own reading: stable IDs, visibility filtering and write guards do not by themselves justify a separate language — B1 and B2 do them too. What WRPL adds is the contract set around the surfaces: independent verification, explicit loss, cross-surface equivalence and full proposal-to-commit lineage. It rates both the benefit and the overhead PARTIAL, and where the extra cost would break even on larger worlds is unmeasured. Times were taken on GitHub Actions runners under Python 3.11–3.13 and vary with the environment.

Boundaries

What v0.1 does not do, or claim

No world model yet

All evidence comes from one small demo world in a reference implementation. WRPL has not been run against an actual world model, so whether it helps one, or scales to one, is unknown.

Narrow writeback

Only replacing an existing state field is executable. Changing relations, creating or deleting objects, splitting or merging identities, ontology and epistemic changes, distributed commits and acting on the outside world are not supported; such edits fail closed.

Deterministic text only

The natural-language surfaces are deterministic Chinese and English, and the verifier is built for exactly those. Checking the meaning of text written by a generative model is open work.

Bridges are bounded

Version-pinned bridge contracts connect WRPL to four other runtimes from the same workshop. They pass their tests, and a local Windows run against the pinned versions passed. That is bounded interoperability evidence, not production, security or future-version certification.

Not claimed

WRPL does not claim to be a universal representation of reality, a replacement for all programming languages, a solution to hallucination, or proof of general machine understanding.

Relation to EML

The same rule, applied to a world

The shape will look familiar from CAIR, elsewhere in this area: one authoritative source, many projections, and edits that arrive as proposals rather than commits. CAIR applies it to programs. WRPL applies it to a world — objects, states, relations, evidence and unknowns — and adds the pieces its design gives a world shared by people and AI agents: observers, authority, budgets and declared loss.

With EML it shares the working rule of this whole area: a layer an AI sits on top of has to be deterministic and has to fail loudly. WRPL’s surfaces are produced deterministically and verified by a program separate from the one that produced them, and the reference projections are declared fail_closed: one that cannot keep its contract stops instead of producing a plausible description.

Source documents

Release, grammar, benchmark, falsification

WRPL began as a series of thirteen design papers (00–12, complete as design drafts) and was built phase by phase, P0 to P10, each phase closed by its own gate and validation report.

RELEASE_NOTES_v0.1.0

private reference MVP · 2026-09-30

The release statement, the read and writeback paths, phase closure, the canonical hashes, the writeback boundary and the distribution boundary.

WRPL_GRAMMAR_v0.1

DEFINED · P0

The frozen first parser target: the .wrpl source file, the core EBNF, and the P0 semantic constraints — read-only by default, authority never above what the runtime grants, natural language proposal-only by default.

schemas/catalog.v0.1.json

23 JSON Schema contracts

The frozen v0.1 contract catalog: WorldIR, ProjectionIR, RepresentationIR, PatchIR, WorldMutationIR, the resolved plan, the semantic kernel, reports, receipts and bridge manifests.

WRPL_MVP_BENCHMARK_REPORT_v0.1

P8 · Python 3.11 / 3.12 / 3.13

The B0, B1 and B2 baselines, the four gains, three ties and one loss in the table above, and the time per run for each Python version.

WRPL_FALSIFICATION_STATUS_v0.1

F0–F12

Thirteen falsification gates: F0–F9 supported (F6 and F7 within stated bounds), F10 and F11 partial, F12 supported only for the tested pinned runtimes — plus the list of open work.

P0–P10 validation reports

11 reports

One report per phase gate: contracts, parser, type system, runtime plan, surfaces, verification, writeback, invalidation, benchmarks, bridges and release closure.

Like the other projects in this area, WRPL is a research and engineering archive. Its repository is private and no software license has been selected, so its own release manifest keeps public_distribution_ready = false, and this page offers no downloads.