Federal tax / Verification
How the federal tax engine is verified
What is tested, against what, and where the testing stops.
Every step has a test
Each calculation step names the tests that prove it (on the calculation order page); the documentation gate fails when a step has no test, or names a test that does not exist. The composition's tests are hand-worked returns on the 2026 parameters (the result and every Form 1040 line), every sign combination of the capital-gain netting, every branch of the senior deduction, and four Form 1040 identities on a random corpus (taxable income, line 7a, total income, total tax).
Every line and branch is executed
The coverage gate builds the engine with coverage instrumentation, runs its tests and fails below these measured floors:
| File | Lines | Branches | Line / branch |
|---|---|---|---|
federal_tax.c | 96 of 96 | 30 of 30 | 100% / 100% |
federal_tax_api_meta.c | 198 of 198 | 55 of 55 | 100% / 100% |
federal_tax_json.c | 295 of 295 | 186 of 186 | 100% / 100% |
state_tax_federal.c | 144 of 144 | 102 of 102 | 100% / 100% |
tax_calculator.c | 178 of 178 | 84 of 84 | 100% / 100% |
No change without a record
The engine was extracted from the planner without changing a single result: a golden corpus recorded from the planner before the extraction (every federal caller: the withdrawal cost and optimiser, every withdrawal policy, the tax-aware simulation's persona panel, full simulation and ACA-bridge responses) is compared bit for bit on every change. A change that moves a result must carry a new engine version, a record in the defects ledger and a re-recorded corpus.
The API is the planner's engine
The API's 2026 parameters are held byte-identical to the planner's 2026 year for every filing status and age pair, and
the state API's computeFederal is held to the planner: for a single filer the federal tax and the state tax it returns equal
the planner's in every jurisdiction. The published schema, rules and worked examples are regenerated from the code and checked on a
seeded corpus of a few thousand requests: every accepted request and every response validates, and every refusal is a documented
message.
Sources are re-checked weekly
Every passage on the sources page is re-fetched weekly from its official source; the job fails when a passage is no longer there, and its date on these pages moves only when the passage was found again.
Where it stops
The engine computes the parts of a return listed on the overview and nothing else; what it does not model is listed there too, and the API refuses a request that would need it. Line numbers follow the 2025 forms until the 2026 forms are published.