This is the multi-page printable view of this section. .
Design research
- 1: Goldmark block-attribute evidence
- 2: Ink and Terminal experiment, 2026-10-05
- 3: OINK 1.2 pre-release review, 2026-10-05
- 4: Visual preset acceptance, 2026-10-05
- 5: Consumer and migration evidence
- 6: OINK comprehensive review, 2026-08-26
- 7: Community issue and PR review, 2026-09-19
- 8: OINK 1.1 release review, 2026-09-20
- 9: CLI maintenance acceptance on 2026-10-03
- 10: CLI acceptance snapshot, 2026-09-29
Research records what was measured, with which inputs and tool versions. Results may explain a decision, but they do not override the current contracts or implementation.
Research belongs in the public Design tree when another maintainer can inspect its method, understand its limits, and repeat the relevant check. Raw agent transcripts, temporary build logs, and local absolute paths do not meet that standard.
Research map
| Record | Evidence |
|---|---|
| Goldmark block attributes | Render-hook visibility and CommonMark container limits on the supported Hugo floor |
| Consumer and migration evidence | A dated corpus survey plus deterministic Book migration results |
| Comprehensive review, 2026-08-26 | Implementation, configuration, output, security, test, performance, and doc audit |
| Community issue and PR review, 2026-09-19 | Reproductions, PR acceptance advice, and remedies for sidebar, focus, and search feedback |
| OINK 1.1 release review, 2026-09-20 | Five runtime repairs, documentation readiness, validation evidence and publication boundaries |
| CLI acceptance snapshot, 2026-09-29 | Executed Starter, real-site, offline, upgrade, and reproducible-archive checks; final local acceptance and public release remain separate |
| Visual preset acceptance, 2026-10-05 | Paper/Slate local implementation, actual output and bounded browser evidence |
| Ink and Terminal experiment, 2026-10-05 | Explicit experimental presets, design tradeoffs and real-site verification |
| OINK 1.2 pre-release review, 2026-10-05 | Final local candidate checks, cleanup, local resources, compatibility and publication boundaries |
Publication rules
A research record states its date, inputs, relevant versions, method, result, and known limits. Volatile counts are labeled as snapshots. External framework comparisons are refreshed from primary sources before publication and distilled into OINK-relevant conclusions rather than copied as a competitor catalogue.
When a result becomes a stable product choice, link it from an accepted decision. When it proposes behaviour that does not exist, move the design question to Proposals.
1 - Goldmark block-attribute evidence
These probes produced byte-identical relevant output on Hugo Extended 0.160.1 and 0.164.0. They explain OINK’s native component forms; the current component contract remains authoritative.
Method
The probe used a minimal Hugo site without OINK templates. Render hooks printed
their context fields and .Attributes as visible markers. The site enabled
Goldmark block attributes, passthrough delimiters for inline and block math,
unsafe rendering for the deliberately inspected raw HTML, and
wrapStandAloneImageWithinParagraph: false.
Each source shape was rendered with the compatibility-floor Hugo and the then current Hugo version. Relevant output was compared byte for byte. The findings below record platform behaviour, not visual styling.
Findings
| Source shape | Hook result | Design consequence |
|---|---|---|
Ordered list with paragraphs, fences, callouts, nested lists, and {.steps} |
The class attaches to the outer <ol> and rich list-item blocks survive |
A Markdown list is the native Steps form |
| Heading inside a list item | The heading remains inside <li> and enters .TableOfContents |
Native Steps can carry navigable headings |
Nested list with {.filetree} |
The class attaches to the outer <ul> |
FileTree needs no wrapper merely to preserve hierarchy |
Standalone image plus {#id num= caption= .class} |
render-image receives IsBlock=true and all attributes |
A Book figure can have a native image form |
| Inline image inside a paragraph | IsBlock=false; the image receives no block attributes |
Inline images cannot use the block-figure contract |
Block math plus {#id num=} |
render-passthrough receives block type and attributes |
A numbered equation can use the native passthrough form |
Table plus {.fields #id num= caption=} |
render-table receives the class and named attributes |
Field tables, matrix markers, captions, and Book numbering can share one hook |
Fenced code plus {#id num= caption=} |
The code-block hook receives the attributes | A numbered example can be the fence itself |
Callout plus {icon= tab=} |
The blockquote hook receives callout metadata and attributes | Folding, inline title markup, icon, and tab metadata can coexist |
| Attribute line separated from its block by a blank line | The attribute silently disappears | Source checks must reject orphan attribute lines |
Adjacent tables with tab= |
Each table hook receives its own tab label | Adjacent-block tabs can extend beyond code fences |
Container boundary
Hugo’s % shortcode delimiter renders .Inner as Markdown, but its template
must put a blank line before and after that inner Markdown. Without both blank
lines, a following list may be treated as literal HTML-block content instead of
Markdown.
A multi-line % container inside a CommonMark list item has a harder limit:
the generated HTML is not indented as list content, so the list closes before
the container and restarts afterwards. This is why OINK keeps a full Steps form
for steps that must contain another full container. Ordinary rich blocks,
fences, and < shortcodes do not have that limitation.
Nested % shortcodes also receive already rendered inner HTML in the relevant
collector shape. A collector that requires the child’s original Markdown uses
< delimiters and renders the captured body through the shared scoped block
renderer.
Attribute ownership
An available attribute is not automatically a public attribute. Every hook
owns a documented allowlist. style and inline on* handlers are rejected;
URL-bearing values pass the shared URL policy. A site class is retained only on
the surfaces where downstream CSS is an established extension mechanism.
The experiment also showed that gallery images inside list items can be block images while still receiving no knowledge of their parent list’s marker. A runtime may therefore need either a theme-emitted marker or a narrow structural fallback; it cannot assume the image hook sees arbitrary ancestors.
Limits and verification
These results cover Hugo 0.160.1 and 0.164.0 with the stated Goldmark settings. They do not promise identical behaviour for a site that changes those settings or for a later Hugo release. A Hugo-floor change reruns the focused component, Book, table, gallery, and Markdown-output checks before this snapshot is updated.
2 - Ink and Terminal experiment, 2026-10-05
Ink and Terminal now compile into the actual theme stylesheet and use the existing Appearance control. These are not injected screenshot styles. They remain explicitly enabled experiments, pending design acceptance.
Inputs and method
This extends the Paper/Slate implementation on the October 5 working trees. Tools: Hugo Extended 0.166.0, Go 1.27.1, Node 26.9.0 and Playwright 1.62.1 on macOS ARM64. The documentation site’s local sibling-theme build is the integration surface; its published pin remains v1.1.0. This is not compatibility-floor, pinned-CI-toolchain or hosted acceptance.
The same Home, configuration, callout and tab content is compared across four presets, EN/ZH, 390/1440 px and light/dark mode. Checks inspect real rendered fonts, overflow, appearance controls and local font requests. Further component checks cover code, parameter fields, Blog, Book, API, Mermaid, ECharts, search and print. API vendor DOM is excluded from axe under the site’s existing policy.
Design choices
| Choice | Improvement | Cost / limit |
|---|---|---|
| Ink: black/white canvas, Inter, red markers, underlined prose links, strong heading rules | Clear hierarchy and link affordance with little decoration | Heavier headings and repeated rules need long-page editorial review |
| Terminal: mono controls/headings, sans prose/tables, teal links and amber emphasis | A recognizable technical interface while retaining paragraph readability | Long Latin navigation labels wrap sooner; CJK uses platform fallback faces |
| Square Ink geometry, 2 px Terminal geometry, no component shadows | Visibly different surfaces using the same content and layout | Scoped component rules add CSS; this is not a global spacing/radius API |
| Compact Terminal desktop navigation only | More useful navigation rows without shrinking article text | Density is a preset decision, not a new reader preference |
| Existing local fonts and state handling | No new font files, external font service, framework or persistence mechanism | All preset CSS remains in one stylesheet |
| Explicit experimental menu entries | Reviewers can switch immediately without changing ordinary menu choices | Four cards make the enabled menu taller |
Ink uses #ffffff / #0b0b0b canvases, #141414 / #ededed text and
#c8102e / #ff5c4d accent. Terminal uses #f4f5f2 / #0c0f0e canvases,
#1d211f / #d3dbd6 text, #0a6560 / #4cc9bd links and
#935400 / #f0a73a accent. Site/section accent overrides still win.
Terminal’s heading markers use empty accessible alternatives; unsupported
engines omit them. Its hero cursor is a static shape, with no typing, blinking,
scanlines or glow.
Try it
The local docs site enables this list. Select Ink or Terminal in Appearance,
then choose light, dark or system independently. Following the October 5 menu
revision, all four options use icon-and-name buttons without experiment badges.
A site may set either as preset without enabling reader choice.
preset_menu: true remains Paper/Slate plus the site default; it does not
include every experiment. Selecting the site’s default preset clears the saved preset.
Font overrides, system typography and pre-CSS initialization use the same
contracts as Paper/Slate.
Verification
| Executed check | Result and scope |
|---|---|
check-presets.py |
AA text/link/accent contrast on three surfaces, light/dark token parity, advisory canvas luminance, frozen Slate v1.1.0 palette; seven strict builds and 28 document roots |
| Theme checks | Parameters, font roles, 32 catalogs with 205 keys, generated schemas, component/output contracts, runtime isolation and namespace passed; 52 existing output goldens unchanged |
| Runtime tests | 49 Node tests passed |
make check |
57 non-browser tests passed; EN/ZH coverage 142/142, Markdown, rendered content and internal links checked |
| Standard browser suites | Eight suites passed 170 tests; the appearance suite passed all 49 after fixing the default-Terminal build issue below. The nine suites total 219 checks; this records the initial run plus the focused rerun, not one uninterrupted successful make browser invocation |
| Appearance coverage | Four presets × EN/ZH × 390/1440 px × light/dark on Home, configuration, callouts and tabs; local font requests and menu axe checks; state, keyboard, print and Giscus asset checks; four experiment/mode checks over 11 page types plus search, and shared Mermaid contrast |
| Font/configuration builds | Actual docs site rebuilt with Terminal as default: system fonts with/without explicit overrides, plus explicit technical-font overrides; all three passed |
| Browser engines | Six checks passed on Chromium, Firefox and WebKit at 390/1440 px, including pre-CSS state, keyboard selection through Ink/Terminal, persistence and focus return; desktop Chromium also used 4× CPU throttling |
| Visual review | 96 actual-output viewport captures; representative Home, Docs and mobile menu images inspected. The local comparison gallery selects content, language, size and mode without injecting styles |
The standard sitemap axe pass used 15 routes: EN/ZH Home, configuration,
callouts, tabs and OpenAPI; English search, Mermaid, ECharts, Blog and
/book/04-design/. The existing responsive axe matrix also ran. This was not
an exhaustive sitemap scan. Standard browser checks used the established
4173 fixture server; the engine gate used the identified sibling-theme dev
server at port 1313. No external font request was observed in the appearance matrix.
The first default-Terminal font build found an omitted entry in the advisory canvas-luminance map, causing false accent-contrast warnings. Both experimental canvases now participate, with checker assertions and authored-accent fixtures. Only the affected appearance suite was rerun after this correction. The added research index entry and updated proposal description were reviewed before refreshing the corresponding two changes in the LLMS golden.
The experiment exposed two new styling faults: the global underline suppression
hid Ink’s links, and Terminal’s selected search row retained dim summary text.
Both received scoped fixes. A separate inherited Mermaid dark-label pair
(#cccccc on #585858, 4.43:1) reproduced in Paper and Slate. The shared
mode-only default label background is now #404040; authored Mermaid values
retain priority. This does not introduce preset-specific chart palettes.
Remaining work
Before stable promotion, review the look on real Windows and Android devices, including CJK fallback faces, underlines, mono heading wraps and long parameter tables. Manual screen-reader speech and first-paint filmstrips remain unverified. CSS initialization-order checks are not a guarantee about every painted frame.
Mermaid/ECharts keep mode-only palettes, API widgets keep vendor styling, and Giscus coverage checks generated palette assets rather than the remote iframe. The experiment does not introduce a complete geometry/density token framework. The decision to promote Ink/Terminal or redesign chart palettes remains open. No commit, push, release, consumer upgrade or deployment is part of this record.
3 - OINK 1.2 pre-release review, 2026-10-05
This review covers the October 5 working trees, including uncommitted changes. It does not certify an immutable release commit or a published 1.2.0 module. The public theme tag and the documentation site’s consumer pin remain v1.1.0.
Scope and inputs
The theme starts at a1979a4 and the documentation site at ed2d0e3.
The reviewed working trees also contain the CJK keyword-summary, literal-percent
outline and repository-source-path fixes, the site’s existing English editorial
changes, and the cleanup below. The separate optional CLI is not part of this
theme release. No tag, push, consumer upgrade or deployment was performed.
Most checks used Hugo Extended 0.166.0, Go 1.27.1, Node 26.9.0 and Playwright 1.62.1 on macOS ARM64. Official, checksum-verified Hugo Extended 0.160.1 and 0.165.0 binaries were used for selected compatibility checks. These are local results, not a replay of the full Linux CI toolchain.
Review findings and cleanup
| Finding | Correction | Impact |
|---|---|---|
| The 1.2 release draft omitted the new default and appearance controls | Update both release drafts and upgrade guidance with Paper, the Slate compatibility setting, independent persistence, current-state icons and experimental preset selection | Readers can identify the visible upgrade change before adoption |
| Current proposal, decision, experiment and source comments still described preview letters, experimental badges, a separate Default card or an undecided release target | Align current descriptions with compact icon/name buttons, site-default reset and 1.2 release preparation; preserve dated test evidence | Guidance agrees with the accepted interface without rewriting historical results |
A working-tree ignore rule hid all site tests/ except two files |
Remove that broad rule; retain existing generated-output exclusions | New regression tests remain visible to Git; no test or build output was deleted |
| Development previews do not expose production-only analytics | Inspect strict production output and distinguish core local resources from explicitly configured services | The local-first claim has an observable boundary |
These cleanup findings required no runtime change. Earlier working-tree runtime fixes are covered by their owning checks and the final integration run.
Executed verification
The local candidate passed the following technical pre-release checks. No release-blocking theme defect was found within this scope. Counts are dated snapshots of this working-tree review.
| Check | Result and scope |
|---|---|
| Preset checker | Passed: seven warning-strict configuration builds, 28 document roots, light/dark token parity, AA text/link/accent checks on three surfaces and the frozen Slate v1.1.0 base palette |
| Runtime tests | 49 Node tests passed, including current-state icons, search summaries, outline tracking, clipboard and dialog focus |
| Theme regression and tooling checks | 40 checker/tool commands passed, including 90 migration tests, snapshot/consumer safety and current output goldens; the PDF browser case was then rerun with an explicit browser, with all three isolation tests passing |
| Documentation checks | Final make check: 57 tests passed; 143/143 bilingual files, 1,197 source headings, 228 rendered content pages and internal links checked; only the new research index entry and changed release title/description required reviewed Markdown-golden updates |
| Standard browser suites | One complete make browser run passed all 219 checks across nine suites, including the full 372-route sitemap axe scan; no failed, flaky or skipped cases |
| Documentation follow-up | A fresh build passed a separate axe scan of 14 updated EN/ZH routes, including this new report pair; this supplements the original full sitemap scan |
| Browser engines | Six appearance checks passed on Chromium, Firefox and WebKit at 390/1440 px; pre-CSS restoration, keyboard selection, persistence and focus return; desktop Chromium also used 4× CPU throttling |
| Visual spot checks | Current-output captures inspected for the Chinese mobile Paper menu, English desktop dark Paper menu and Chinese Terminal reading on mobile/desktop; two-column icon/name options, current-state icons and reading layout confirmed |
| Hugo compatibility floor | 0.160.1 passed preset and reading/math checkers plus a strict minified production build of the actual documentation site |
| CI Hugo version | 0.165.0 passed a strict minified production build of the actual site, Hugo Module/include/static/print checks, system typography, legacy Sass font overrides and expected rejection of invalid typography |
| Production resources | 28 page visits across four presets and seven routes; core fonts and scripts served from the site’s origin; configured external services recorded separately |
| Production output security | Passed on 921 files in the final strict production build with the documented third-party integration policy |
| Book publication | Root and subpath EPUBs passed the theme checker and EPUBCheck 5.3.0 with zero errors/warnings; both PDFs passed the 23-page, five-chapter structure checks; the root PDF script-isolation probe passed |
| Published consumer pin | Existing v1.1.0 resolved and passed the site’s release-pin check with environment replacements and both workspaces disabled; this is not validation of a published v1.2.0 |
The full sitemap scan follows the site’s existing axe policy: OINK-maintained surfaces are checked, Giscus requests are blocked, and Swagger UI/Redoc vendor DOM is excluded. It does not establish accessibility of those widgets. Responsive checks cover 360, 768, 820, 1024, 1200 and 1440 px in English/Chinese and light/dark mode.
Appearance checks use the same Home, configuration, callout and tab content in four presets, both languages, 390/1440 px and light/dark mode. They also cover search, code, tables, input/focus states, Blog, Book, API, diagrams and print. Ink and Terminal remain explicitly selected experiments; passing these checks does not promote them to stable presets.
Publication used local Pandoc 3.11, Java 26 and Chrome headless-shell 151.0.7922.34. The first attempt with the full Chrome for Testing application timed out on this Mac. Selecting headless-shell explicitly, as CI does, produced the verified PDFs. This does not claim compatibility with every Chrome installation. CI pins Pandoc 3.10 and Java 21 on Linux.
Local-first resource boundary
IBM Plex Sans, Inter, IBM Plex Mono, Chakra Petch, icons, KaTeX fonts and core browser libraries are bundled locally. Preset switching introduces no runtime font-service or CDN-script dependency. System typography and explicit font-role overrides retain their documented precedence.
The production audit loaded Home, Chinese configuration, math, Mermaid, Markmap, ECharts and OpenAPI under each preset, then switched dark/light mode. The production base origin was preserved while built files were served locally. Request tracing recorded and blocked off-origin requests; local fonts and diagrams still loaded without uncaught JavaScript or local HTTP errors.
Two configured services requested external scripts: Giscus and Google Analytics. Giscus is an accepted optional comments integration; its OINK palette files are local. This documentation site already configures an analytics ID, so production output includes Google Tag Manager’s script. Neither service is required by the new presets. They were left configured; the documentation site therefore does not have a zero-external-request claim. Authored remote media and explicitly selected diagram services retain their existing opt-in boundaries.
Repeating the checks
Run owning theme checks before the real-site checks. These commands use the sibling theme through the documented Make targets; do not commit a filesystem module replacement:
The full theme checker set and publication commands are defined in
.github/workflows/ci.yml. Run all owning checkers with fresh fixtures,
including parameters/schema, vendored assets/fonts, navigation/search/actions,
components, output/namespace/goldens, migrations, snapshot protection,
consumer tooling and PDF isolation. The engine suite is
npm run test:appearance:engines in the site repository.
For compatibility checks, put the selected Hugo binary on PATH, disable
inherited Go/Hugo workspaces, and identify the sibling replacement explicitly.
Build the real site with --environment production --minify --printPathWarnings --panicOnWarning into a separate output directory. For published-pin checks,
disable the replacement as well. These are different validation targets.
Remaining release steps and limits
Local technical pre-release acceptance passed. A release still needs reviewed changes assembled into commits, CI on those exact commits, a published tag and module archive, consumer adoption and hosted verification. Changing a version label cannot complete those steps. Release notes remain drafts and existing consumer pins were not changed.
Real Windows/Android font rendering, manual screen-reader speech and first-paint filmstrips were not verified. Windows source-path behavior was checked through deterministic fixtures rather than a Windows host. Ink/Terminal design follow-up remains in the experiment record.
4 - Visual preset acceptance, 2026-10-05
This record concerns sibling-checkout theme output, with no injected prototype styles. It is not a release, a consumer upgrade, or hosted-site acceptance.
Inputs
Theme and documentation working trees on 2026-10-05; Hugo Extended 0.166.0,
Go 1.27.1, Node 26.9.0 and Playwright 1.62.1 on macOS ARM64. The ordinary
browser suite uses Chromium; the additional engine gate uses Chromium, Firefox
and WebKit.
The site still pins v1.1.0; make check, make browser, and make dev select
the local sibling theme. The published pin was not changed. This run is not a
Hugo 0.160.1 compatibility-floor or pinned-CI-toolchain test.
Executed checks
| Evidence | Result and scope |
|---|---|
check-presets.py |
Paper light/dark token parity and AA text/link/code/copper contrast; frozen v1.1.0 Slate base palette; four strict configuration builds and 16 HTML roots including 404 and print |
| Existing theme checkers | Parameters, font roles, vendor inventory, 32 locale catalogs, actions, shell, output, namespace, Landing and runtime isolation passed; generated schemas match their sources |
check-goldens.py |
52 surfaces passed after reviewing and updating the 34 HTML/print expectations affected by root attributes, prepaint colors, the menu and its action/runtime; other output formats were unchanged |
| Strict site build | Real sibling-theme EN/ZH site built with --panicOnWarning; translations, rendered Markdown and internal links passed |
node --test 'tests/js/**/*.test.js' |
49 runtime tests passed |
appearance.spec.mjs |
25 tests passed: Paper/Slate × EN/ZH × 390/1440 px × light/dark on Home, configuration, callouts and tabs; menu axe checks; keyboard, persistence, default reset, language navigation, cross-tab sync, blocked storage, invalid values, no JS, print, command palette, reading-anchor/breakpoint handling and generated comment stylesheets |
appearance-engines.spec.mjs |
Six checks passed: Chromium, Firefox and WebKit at 390/1440 px; stored state and browser chrome color restored before CSS, native keyboard selection, focus return and language navigation. Desktop Chromium also used 4× CPU throttling |
| Font requests | All observed fonts were local. Paper requested no Inter; Slate requested no Plex Sans. Two real-site overlay builds proved system typography requests no bundled text face and explicit font roles override both presets |
make check |
Complete non-browser suite passed: 57 tests, 141/141 translated pages and the existing Markdown/rendered-content/internal-link checks |
make browser |
197 tests passed across all nine standard suites; sitemap axe scan scoped to the 15 routes below |
| Visual inspection | Actual Paper desktop Home, mobile long-form Docs, English/Chinese light/dark Appearance panels and Slate dark Home reviewed; screenshots come from browser tests, not injected styles |
The browser suite’s sitemap axe pass is deliberately scoped with A11Y_PATHS
to 15 representative routes: EN/ZH Home, configuration, callouts, tabs and
OpenAPI; English search, Mermaid, ECharts, Blog and a Book chapter. The existing
responsive axe matrix runs in addition. Cross-origin Giscus and vendor API
widget DOM retain the suite’s established exclusions. This is not an exhaustive
sitemap scan.
The integration run found and fixed Paper dark highlighted-line gutter contrast and smooth-scroll interference with reading-anchor restoration. Theme-color checks now assert both presets: Paper’s opaque warm selection surface and Slate’s existing translucent selection surface.
Limits and next checks
Manual screen-reader speech and visual filmstrip/paint traces remain unverified. The blocked-stylesheet and throttled-CPU assertions verify initialization order, not every browser’s first painted frame. Slate comparison freezes base palette values and verifies rendered font behavior; it does not claim pixel identity for all 1.1.0 components after unrelated 1.2 work.
Mermaid/ECharts retain mode-only palettes. Ink and Terminal remain research; serif display headings, full geometry/density tokens and preset-colored charts remain later work. No release tag, push, cross-site upgrade or deployment was performed for this work.
5 - Consumer and migration evidence
These counts describe the repositories inspected in August 2026. They are evidence for design choices, not live product metrics or compatibility promises.
Corpus
The authoring survey scanned the content/ trees of eleven OINK consumer sites:
5,325 Markdown files, of which 5,293 had YAML front matter. The set included
single-language English and Chinese references, bilingual product sites,
release archives, custom landing pages, and separate Book consumers.
The survey deliberately measured source Markdown rather than generated HTML. It counted shortcode calls, fenced-code attributes, callouts, table markers, raw HTML, front-matter keys, content types, and site-local layouts. A later Book-focused pass added five long-form consumers.
Findings that changed the design
| Evidence | Resulting choice |
|---|---|
| Content ranged from nearly plain Markdown to pages with many nested components | Native Markdown is the default form; a full form survives only for a named capability gap |
| Documentation, Blog, Landing, releases, and books repeatedly reimplemented navigation or cards locally | Extend the shared shell, registry, and primitive rather than adding a parallel system |
| Site-specific table classes were common, while canonical Field-table headings were rare | Hook attributes use an allowlist but preserve documented site-class extension points; Fields cannot be inferred from arbitrary two-column tables |
| Book sites carried private figure, table, equation, example, and cross-reference conventions | Numbered primitives and migration profiles need deterministic classification, stable IDs, and rendered-target verification |
| Sites mixed single-language, peer-file bilingual, and generated-language content | Language authority and generation boundaries must be explicit; a migration never treats an untracked generated tree as source |
| Rich HTML pages still needed print, Markdown, feeds, and agent output | Every component declares its output degradation before its interactive HTML is accepted |
The evidence also rejected several attractive additions. Documentation sites did not justify a second Landing system; Book sites did not need a new cover component; a serial archive did not justify a new shell type; and remote API collection belonged to site-side CI rather than a Hugo theme that promises local builds.
Block and table evidence
A focused pass over eleven sites plus Book consumers found 11,484 pipe tables.
Only eleven already matched the strict Field-table heading vocabulary, while
roughly 874 were reference-style tables and about 1,300 were compatibility
matrices. The result was explicit .fields and .matrix markers rather than
shape guessing.
The same pass found eighteen Steps blocks in the eleven-site corpus. They all
used the full form with headings and rich content. Platform probes showed that
a native ordered list could carry most of that content, while another full %
container inside a list item could not. OINK therefore keeps both forms for a
technical capability boundary, not merely for stylistic preference.
Deterministic Book migration
Three dated dry-run profiles tested whether the migration rules could account for every recognized source without inventing semantics:
| Profile snapshot | Classified result | Manual boundary |
|---|---|---|
| DDIA v2 | 106 figures, 3 tables, 22 code examples, and all 304 relevant links accounted for | One caption link flattened to visible text; no unaccounted skip |
| DDIA v1 | 90 numbered figures and 203 matching references | 14 decorative or unnumbered images deliberately left alone |
| TPME | 31 figures, 10 tables, 44 numbered references, and 1,018 generic stable references | No skipped recognized item |
| Private Book profile | 119 figures, 5 tables, and 136 numbered references | 3 ambiguous images retained for manual review |
Each profile was dry-run first, wrote only after its ambiguity boundary was understood, produced zero changes on a second run, built with warnings fatal, and passed rendered kind/number/anchor checks. The public migration toolkit and current profile boundaries are documented in Writing a book and the migration contract.
Publication adoption snapshot
An isolated 2026-08-24 pass exercised the released generic Book publication path against two consumers:
| Consumer | Generic publication evidence | Downstream status |
|---|---|---|
| DDIA | 23 ordered pages, 131 typed targets, and 292 resolved cross-references; EPUBCheck, internal, and PDF checks passed | At this snapshot it still retained a semantic preprocessor pending independent acceptance of the new gate |
| TPME | 18 ordered pages, 41 typed targets, and 1,062 resolved cross-references; the same generic checks passed | A second consumer confirmed portability; it created no upstream migration gate |
This is downstream adoption evidence, not an open upstream design boundary.
Limits
These counts should not be copied into product marketing or used as a current site inventory. Repeating the research requires a fresh repository list and a new dated report. Paths, uncommitted content, private repository names, raw agent transcripts, and generated build artifacts are intentionally excluded from this public record.
6 - OINK comprehensive review, 2026-08-26
This page records evidence collected against github.com/pgsty/oink and its integration site on 2026-08-26.
It changes no API and does not mean that any recommendation below is implemented. Current Design contracts,
implementation, and owning checkers remain authoritative.
Superseded in part by OINK 0.7.1. The code findings F01–F06 were fixed in that release — see the 0.7.1 release notes. Read the findings below as the evidence that motivated the fix, not as the current state of the theme.
Review verdict
OINK’s main-line quality is substantially above that of a typical Hugo theme. The default path builds, bilingual coverage is strong, component tests are broad, and the project treats output and trust boundaries seriously. The real site showed no general breakage across desktop, mobile, light/dark, and the primary accessibility paths. Theme and site worktrees were clean, their current remote checks were green, and every locally rerun first-party suite passed.
Green checks do not prove that every published invariant holds. This review found 4 P1, 9 P2, and 5 P3 findings. The recurring pattern is that OINK has a strong modern contract, while several early or peripheral surfaces have not joined it; the current gates are excellent at preserving selected positive scenarios but do not systematically cover configuration space, static-output degradation, or the semantic accuracy of public documentation.
Before the next release tag, at minimum:
- disable Swagger UI’s default online validator and lock zero implicit egress with a non-localhost browser test;
- place all public configuration and Landing data behind common type, range, URL, and CSS-value validation;
- redesign Swagger, Redoc, and Asciinema output degradation and runtime gates; and
- repair generated schemas and bring the public configuration/front-matter references back to current behavior.
Baseline and method
Review baseline
| Item | Snapshot |
|---|---|
| Theme repository | clean main at fe439fdb1d7c2df745088c9bfcbb8c350403ee63, equal to origin/main |
| Current stable tag | v0.7.0 at cbb6f4e0bfe47e17ba7aa41d04b8651c943cf858 |
| Documentation site | clean main at fd5fcde, publicly pinned to github.com/pgsty/oink v0.7.0 |
| Local tools | Hugo Extended 0.164.0, Python 3.14.6, Node 26.4.0, npm 11.17.0 |
| Remote CI | theme HEAD GitHub Actions run 32792753866 succeeded |
Validation executed
- all 31 theme checkers passed;
- all 85 migration unit tests passed;
- all 38 theme browser-runtime unit tests passed;
- all 40 HTML/Print/Markdown/RSS/LLMS golden surfaces passed;
- the strict
tests/siteHugo build passed; - the real bilingual site’s
npm testpassed: 121/121 page pairs, 886 heading IDs, 24,860 internal links, and 3,172 fragments; - the full real-site Playwright suite passed: sitemap-wide axe, 29 accessibility cases, 45 responsive/navigation cases, 16 keyboard cases, 10 content-component cases, 18 code-block cases, 4 PRD5 cases, and 5 theme-color cases;
- extra visual review at 320 CSS px covered the EN home, ZH configuration, ZH Book, and OpenAPI/Redoc pages with no page-level horizontal overflow;
npm auditreported no advisory among the site’s 79 npm dependencies; an OSV Query API batch for the 26 exact versions inVENDOR.jsonreturned no known advisory;measure-baseline.py assets --fixture-sitepassed its isolated strict build.
Severity
| Level | Meaning |
|---|---|
| P1 | Breaks a core product, security/privacy, or ordinary-editing invariant; fix before the next tag |
| P2 | Material behavior, contract, or compatibility defect; fix soon with a behavior gate |
| P3 | Maintainability, performance, process, or documentation-governance debt |
Finding summary
| ID | Level | Finding | Default-site impact |
|---|---|---|---|
| F01 | P1 | Swagger UI enables its online validator on production URLs | Pages using swagger only |
| F02 | P1 | Invalid configuration can crash ordinary Hugo or silently emit bad output | Depends on authored configuration |
| F03 | P1 | Swagger/Redoc/Asciinema violate static-output and runtime-isolation contracts | Pages using those shortcodes |
| F04 | P1 | Landing sends unvalidated data to safeCSS and lets other bad values pass silently |
Related Landing fields |
| F05 | P2 | Custom page-action and archived-version URLs bypass the shared URL policy | Sites configuring those options |
| F06 | P2 | Generated JSON Schemas contain wrong defaults, types, descriptions, and candidate keys | Authors using editor schemas |
| F07 | P2 | The supposedly complete configuration/front-matter references lag v0.7 behavior | All maintainers and consumers |
| F08 | P2 | Design contracts and proposal lifecycle present conflicting authorities | Maintainers |
| F09 | P2 | OpenAPI accessibility defects are excluded while Redoc is presented as an alternative | OpenAPI readers |
| F10 | P2 | Strict-CSP guidance omits theme-owned inline script and style | Strict-CSP consumers |
| F11 | P2 | No browser support baseline; automation is Chromium-only | Firefox, Safari, RTL, forced-color users |
| F12 | P2 | Output-security and rendered-Markdown gates have systematic blind spots | Consumers relying on those verdicts |
| F13 | P2 | Real cross-repository candidate integration is manual and non-atomic | Every public behavior change |
| F14 | P3 | Checker duplication and source-string coupling are high | Maintainers and isolated worktrees |
| F15 | P3 | Baseline CSS and fonts remain the main first-visit payload | Every HTML page |
| F16 | P3 | Vendor integrity is strong, but vulnerability/SBOM and CI supply-chain gates are manual | Release maintainers |
| F17 | P3 | Changelog, implemented proposals, and behaviorless metadata reduce signal | Maintainers and upgraders |
| F18 | P3 | The Print isHTML FIXME no longer explains the real dependency |
Print-template maintainers |
Detailed findings
F01 — Swagger UI implicitly contacts the online validator (P1)
layouts/_shortcodes/swagger.html initializes SwaggerUIBundle without validatorUrl: null. The vendored
swagger-ui-bundle.js defaults that option to https://validator.swagger.io/validator and suppresses the badge only when
the specification URL contains localhost or 127.0.0.1. On a deployed host it creates an online-validator badge whose
request includes the specification URL.
This violates the promises that theme-owned network features are off by default, that same-origin specifications remain local, and that OINK is local-first. An intranet deployment can disclose its internal hostname/specification URL. The localhost exemption is also why every current local browser test misses the request.
Set validatorUrl: null explicitly. Any future online validator should be an explicit opt-in URL, pass the shared URL policy,
and be documented as a privacy/CSP integration. Test a production-like non-localhost origin while intercepting every request
and require same-origin specifications to fetch first-party resources only.
F02 — Invalid configuration does not consistently warn and fall back (P1)
ui-param.html says callers validate types; several do not. Minimal builds produced the following results:
| Input | Actual result |
|---|---|
ui.blog_index_size: nope |
ordinary build fails because .Paginate requires a positive integer |
ui.sidebar_expand_levels: nope |
ordinary build fails in add |
ui.sidebar_menu_truncate: nope |
ordinary build fails while first casts the value |
offline_search_summary_length: nope |
ordinary build fails while truncate casts the value |
ui.sidebar_width_min: "1; color: red" |
warning-free build emits --td-shell-sidebar-min: ZgotmplZpx |
ui.sidebar_width_min: -50 |
warning-free build emits -50px |
blog_index_columns: 2.5 / section_index_columns: 2.5 |
warning-free build feeds 2.5 to CSS repeat() |
ui.sidebar_item_overflow: clip |
warning-free build silently behaves as ellipsis |
ui.sidebar_menu_foldable: definitely |
the non-boolean string is truthy and enables folding |
ui.blog_index_size: 0 |
Hugo default silently converts it back to 12 |
Landing marquee.rows/capabilities.columns and Asciinema numeric parameters also call int/float directly. Other bad
types, such as print.toc or offline_search_max_results, silently change behavior.
This directly contradicts the Diagnostics decision: ordinary hugo server may become unusable, while some bad input reaches
a strict publishing gate without any warning. Add shared integer, positive-integer, range, paired-range, and grid-count
validators. Normalize before arithmetic or output. Every public key needs legal site and page cases plus illegal ordinary
(warn/fallback) and strict (failure) cases. Cross-field invariants such as min <= max, pager size >= 1, and integer grid
counts belong in domain resolvers.
F03 — OpenAPI and Asciinema remain HTML-only islands (P1)
Architecture and Components require Markdown/LLMS without theme component markup, static Print, and safe static RSS or explicit omission. Current behavior disagrees:
- Redoc emits
<style>,<div class="td-redoc">, and<redoc spec-url=...>into generated.md; - Swagger places an executable inline initializer in its shortcode;
- Asciinema
.mdcontains the fulltd-asciinematree and JSON script; - Asciinema Print loads about 185 KB of player JS/CSS and can print only an incidental frame;
- Swagger/Redoc leave empty Print containers and can still select 1–2 MB runtimes; and
- these shortcodes are absent from the Markdown/RSS/Print golden matrix.
Agent output contains theme HTML, paper/EPUB readers receive empty shells, Print carries useless runtime, and Swagger breaks a strict CSP. Reader-facing guides currently document these defects as output behavior, contradicting the normative contracts.
Make all three branch on tdOutputFormat: full behavior in interactive HTML; a titled static link and spec/cast address in
Print/Markdown/RSS, or explicit omission. Only interactive HTML should set capability flags. Move Swagger initialization into
a stable chunk and Redoc styles into a stylesheet; add four-output goldens and runtime-absence assertions.
F04 — Landing CSS, URL, and numeric inputs do not share one trust boundary (P1)
hero.html validates title_size but concatenates media.ratio and media.max_width verbatim before marking the complete
string safeCSS. This input:
builds strictly with no warning and emits:
Landing permits inline sections in page front matter, so this is not merely an internal repository constant. Other section
columns, rules, dimensions, styles, icons, and URLs are handled ad hoc. A javascript: URL often becomes #ZgotmplZ
without warning; bad columns become ZgotmplZ; some direct integer casts abort the build.
Add a section normalization layer with common class, icon, URL, CSS-length, grid-count, boolean, and enum handling.
hero.media.ratio should be two constrained track values rather than arbitrary CSS; max_width should use the length
validator. All Landing actions should reuse content/url.html, and each built-in section needs negative tests.
F05 — Two configuration URL surfaces bypass shared policy (P2)
params.ui.page_context_menu.links passes through url-template.html and directly into safeURL; url_latest_version is
also treated as trusted configuration and marked safeURL. Neither path validates scheme, host, whitespace, or
protocol-relative URLs. A warning-free build can produce:
Clicking executes JavaScript. Site configuration is high-trust input, so this is not a default remote exploit, but it violates the published safe-URL model and gives copied configuration unnecessary execution power.
Allow only HTTP(S) and explicitly supported first-party relative URLs, using the shared resolver. Validate archived-version URLs too. The browser action registry’s second check is good defense, but the progressive-enhancement anchor must not bypass it.
F06 — Generated schemas disagree with actual YAML (P2)
The small parser in generate-config-schema.py does not strip inline comments. At least 11 defaults become strings, including
print.toc ("true # ..." instead of boolean), print.section_break_wordcount, both index column counts, and enum defaults
such as footer_style, blog_index, and typography.
Comment association also drifts: breadcrumb commentary is attached to section_index; quick-link commentary to
sidebar_icon_policy; taxonomy-icon commentary to pager_types; and local-chrome commentary to image_zoom.
The front-matter schema advertises removed detector keys (release, upstream_attribution, downstream_modified) and
misclassifies navbar-menu Params.columns as page front matter. The drift check compares the same buggy generator with its
committed output, so it reliably preserves the error.
Use a real comment-preserving parser or explicit machine metadata markers rather than extending the ad-hoc parser. The scanner must distinguish page, menu, shortcode, and legacy-detector contexts. Tests should compare each schema default to Hugo’s actual parsed value and keep removed keys out of completion.
F07 — Public configuration and front-matter references are not current (P2)
Both reference pages claim to list every key the theme reads. Material drift includes:
- long English date defaults where
hugo.yamlnow uses ISO2006-01-02; - Blog docs missing
hero,table, toggle, size,toc_style, andtoc_taxonomies; - the removed
releasemap and release filters presented as current, whilerelease_urlis absent; images: []described as disabling featured images even though bundle discovery continues;upstream_modifieddescribed as adding a line, while current behavior changes the attribution verb;- inconsistent claims that invalid input directly fails versus warns in ordinary preview and fails only at a strict gate;
- the Book guide saying OINK stops at Print HTML after v0.7 shipped BookManifest/EPUB/PDF tooling;
- Asciinema/OpenAPI guides turning static-output defects into product contracts; and
- Features saying 28 vendor dependencies when the authoritative manifest has 26.
English and Chinese usually agree on the stale answer, so translation parity cannot detect the error. Treat the two references as a focused contract migration. Derive a comparable key inventory from implementation/schema, keep semantics reviewed by hand, and gate current-key coverage, removed-key placement, enums, and defaults.
F08 — The Design tree contains conflicting authorities and unretired proposals (P2)
The clearest contradiction is that Shell retires navbar columns/mega panels and promises a warning plus one column, while
Landing still says navbar mega-menu columns accept 1–4. Implementation and tests follow Shell.
Lifecycle is also incomplete. config-schema is marked implemented but remains an Active proposal. Book publication has shipped
manifest, EPUB, PDF, and most CI work while a Draft proposal duplicates the Architecture contract. Media convergence retains
implemented milestones and the open M4 in one original design record.
Correct Landing, move stable config-schema facts into Architecture/Decision and retire the proposal, and reduce Book publication to the remaining consumer-migration question or replace it with a narrow follow-up. Active proposals should not contain a second current API.
F09 — OpenAPI accessibility claims conflict with test exclusions (P2)
The axe suite excludes both .td-swagger-ui and .td-redoc. Its comments name Swagger’s unnamed server selector and
non-keyboard scrollable version stamp, plus Redoc operation-description contrast. The guide discloses only Swagger’s defects and
presents the rendered Redoc as the alternative, implying that Redoc meets the site’s zero-violation gate.
Publish the real boundary in both languages. Fix Redoc contrast in theme CSS where possible; use a narrow post-render adapter for fixable Swagger DOM. Remaining upstream defects should have versioned waivers, upstream issue links, and a separate axe report instead of excluding the whole supported surface while claiming a site-wide zero.
F10 — The current theme does not directly support a strict CSP (P2)
Deployment guidance says strict CSP is workable but lists only author scripts, ECharts callbacks, analytics, remote specs or diagram services, and Giscus. A normal Docs page already emits two theme-owned executable inline scripts (theme first paint and shell prepaint) plus inline style. Markmap, Swagger, Algolia, and Google CSE add more theme-owned inline initializers. There is no nonce API, hash manifest, or complete sample policy.
script-src 'self' blocks theme first paint and shell-state restoration; style-src 'self' blocks theme color, font roles,
Landing, and several inline custom properties. Consumers must add 'unsafe-inline', maintain hashes, or override templates,
none of which the guide states.
Move stable initializers into same-origin chunks with data/JSON configuration. For unavoidable inline content, provide a
generated hash manifest or one nonce hook. Publish minimal-core, Markmap/OpenAPI, and third-party-integration policies and state
the style-src requirements.
F11 — Browser compatibility has no baseline or cross-engine proof (P2)
CI installs Chromium only, and product documentation names no minimum Chrome, Firefox, or Safari version. The implementation
uses or enhances with :has(), dialog, inert, color-mix(), @property, logical properties, and discrete display
transitions. Some paths have fallbacks, but there is no engine matrix.
RTL assurance is mostly source markers, small JS tests, and one element-level geometry mutation rather than a full RTL-language site. Most forced-color assurance only checks that strings exist in SCSS rather than computed behavior.
Publish a small support matrix and run core shell/navigation/content/dialog cases on Chromium, Firefox, and WebKit. Add a real
languageDirection: rtl integration configuration plus forced-colors, reduced-motion, 320 px, and 200% zoom scenarios.
F12 — Output-security and Markdown gates do not inspect every claimed surface (P2)
For .md, check-output-security.py scans only Markdown-link syntax; it does not feed raw HTML through the HTML scanner, so
Redoc/Asciinema scripts, spec-url, and raw href are invisible. It also ignores URLs in CSS and JSON configuration, while the
fixture runs with a broad --third-party allowance.
check-rendered-markdown.mjs is also misleadingly named: it scans generated HTML text nodes for leftover Markdown syntax; it
does not read generated .md. The actual Markdown golden set covers 15 pages and omits OpenAPI/Asciinema.
Separate HTML trust, machine-output purity, and rendered-text residue into clearly named gates. Give generated Markdown a very narrow raw-HTML allowlist; parse CSS URLs, form actions, JSON URLs, and non-executable JSON scripts deliberately. Every public shortcode should enter at least one Markdown/Print/RSS behavior case.
F13 — Candidate integration across the two repositories is manual (P2)
Theme CI tests only synthetic tests/site; documentation-site CI tests only the public tag pinned by go.mod. Real EN/ZH and
Playwright validation of a theme PR depends on a maintainer’s local HUGO_MODULE_REPLACEMENTS, and changes in the two
repositories cannot be committed atomically.
Both repositories can therefore be green while public references drift from implementation, as this review demonstrates. The written release-state separation is correct, but automation does not enforce the same-delivery rule for implementation, owning checker, and paired contract.
Add a read-only candidate workflow that checks out a theme PR SHA and a declared documentation-site SHA, applies a temporary
module replacement, and runs npm test plus the critical browser suites. Allow a Design-contract PR to identify the candidate
theme SHA too. Tag, pin, and deployment remain distinct, but the candidate pair gains one traceable joint verdict.
F14 — Checker maintenance cost and source coupling are high (P3)
The coverage is valuable, but 34 check-*.py files contain 546 read_text() calls. Many repeat require, temporary-site
creation, file writes, Hugo invocation, and error aggregation. Numerous assertions freeze template/SCSS spelling, nearby
comments, or whole-file equality instead of observable behavior.
Some helpers hard-code theme: oink with --themesDir <repo-parent>, making the checkout/worktree basename an implicit
precondition. There is no unified Python lint/type gate. This makes checkers quick to add but encourages shared blind spots.
Create a common fixture builder and assertion library; move negative cases into table-driven data. Keep source checks for true topology invariants only and move the rest to parsed output or computed styles. Load the theme through an explicit symlink or module replacement rather than repository basename.
F15 — Runtime splitting succeeded, but baseline CSS/fonts dominate first visit (P3)
The isolated strict fixture baseline was:
| Metric | Value |
|---|---|
| Cold/warm build | 1.256 s / 1.273 s |
| Pages | 249 |
| Stable JS chunks | 18 |
| Main + Font Awesome CSS | 549.8 KB raw / 91.1 KB gzip |
| Fonts total (FA portion) | 999.7 KB raw / 248.5 KB gzip |
| Median Docs-page JS | 176.9 KB raw / 55.3 KB gzip |
| Generated public | 26.2 MB |
| v0.7.0 Go module zip | 7.8 MB (about 20.5 MB and 1,140 files expanded) |
Stable first-party capability chunks correctly removed combinatorial bundles, and large third-party runtimes are page-local. The remaining common cost is Bootstrap/theme/Landing CSS and the complete Font Awesome distribution.
Do not prune Font Awesome by observed template usage; that would violate the authoring contract. Instead measure whether Landing, Book, or Swagger CSS can become independently cached/surface-local, inspect fonts actually requested on first visit, and maintain a trend report rather than an arbitrary hard threshold.
F16 — Vendor builds are reproducible, but advisory and CI supply-chain gates remain manual (P3)
Positive evidence: VENDOR.json pins 26 packages, 56 artifacts, 31 license files, and tree hashes; check-vendor.py passed;
OSV and npm audit reported no known advisory in this snapshot.
The custom manifest is not part of a common SBOM/advisory gate, and npm audit cannot see vendored browser packages.
Two documentation-site workflows download a Hugo .deb and immediately install it with sudo dpkg -i without a checksum.
Actions use movable major tags, and theme CI floats Python at 3.x.
Generate CycloneDX/SPDX from VENDOR.json, schedule OSV scanning, pin Hugo archive/deb SHA-256, pin high-trust release actions
to commit SHAs, and choose a specific Python version or matrix.
F17 — Design and release records have lost signal (P3)
CHANGELOG.md has 1,768 lines; the v0.7.0 section alone is about 300 lines, and Unreleased spends about 20 lines on one checker
retry. The narratives are useful engineering history but make breaking changes, migrations, and observable behavior harder for
upgraders to find.
book_kind and book_part are acknowledged by contract and repeated in content front matter while templates explicitly do not
read them. They impose API-like authoring cost without behavior. Implemented proposals remaining active add another duplicate
answer.
Keep the changelog to observable changes, breaking/migration notes, and concise fixes; move long design stories to Blog/Research and link them. Give behaviorless metadata a consumer/schema or demote it to site-owned fields.
F18 — The Print isHTML FIXME is no longer accurate (P3)
hugo.yaml says to leave isHTML unset until Hugo fixes issue #14381. Hugo closed that issue on 2026-01-17, and the fix shipped
before OINK’s 0.160.1 floor. Simply enabling isHTML: true still produces missing page/section/landing Print-layout warnings in
the current theme, causing a strict build to fail.
The actual dependency has shifted from “waiting for an alias fix” to “the current Print template names rely on non-HTML lookup rules.” Do not simply delete the workaround. First complete the HTML-classified Print lookup matrix and alias/subpath tests; if false remains intentional, update the comment to the real reason and add a test that prevents cleanup based on a closed issue.
Strengths
- Source, local validation, commit, tag, public module, consumer pin, and deployment are explicitly separated.
- The Hugo 0.160.1 floor plus 0.164/0.165 theme matrix is strong.
- Most newer components follow warning/fallback, four-output, shared URL/attribute, and capability-flag contracts.
- The 32 locale schemas match, with strong real EN/ZH page, heading-ID, link, and narrow-navigation gates.
- Search, keyboard behavior, surface coordination, page actions, and theme color have both unit and browser behavior tests.
- Vendor license/hash checks and EPUB/PDF path, loopback, CSP, and overwrite boundaries are thoughtfully designed.
- Manual 320 px review found no page-level overflow; current core visual quality is good.
- Builds are fast, and first-party JS now uses stable capability chunks.
Recommended remediation roadmap
Phase 0: before the next tag
- Set Swagger
validatorUrl: nulland add a production-origin no-network test. - Build the public-parameter inventory and validate every F02/F04 field with negative cases.
- Redesign four-output behavior and runtime gates for Swagger, Redoc, and Asciinema.
- Validate custom action and archived-version URLs.
- Repair the schema parser/scanner and regenerate both schemas.
- Synchronize paired Config, Front matter, OpenAPI, Asciinema, Book, Features, and Landing-contract pages.
Phase 1: contract gates
- Create a minimum HTML/Print/Markdown/RSS coverage map for all 29 shortcodes.
- Split and strengthen output-trust and machine-output-purity gates.
- Normalize all Landing section input centrally.
- Externalize theme-owned inline initializers and publish CSP guidance.
- Add a cross-repository candidate workflow.
Phase 2: compatibility and structure
- Add Firefox/WebKit, real RTL, forced colors, and 200% zoom.
- Consolidate the Python checker harness and source-string assertions.
- Evaluate surface-specific CSS and actual font requests.
- Generate an SBOM, schedule OSV, and pin CI download digests.
- Retire implemented proposals and reduce changelog volume.
Acceptance criteria
- A same-origin Swagger specification on a production-like origin makes no third-party request.
- Every invalid public configuration warns and falls back/omits in ordinary builds, fails strictly, and emits no
ZgotmplZ. - Generated
.mdcontains notd-*, theme script/style, or empty interactive container. - Print loads no Swagger/Redoc/Asciinema runtime and provides an understandable static alternative.
- Schema default types exactly match Hugo parsing, and removed keys are absent from completion.
- EN/ZH configuration and front-matter key/enum/default inventories match implementation.
- Core Playwright passes on Chromium, Firefox, and WebKit, with real RTL and forced-color behavior assertions.
- Every candidate theme SHA has a traceable joint validation against the real documentation site.
Review limits
This pass did not individually audit every consumer repository, production response headers/CDN caches, real Firefox/Safari, or screen readers, and it did not manually reverse-engineer 13 MB of minified third-party source. Advisory checks are a 2026-08-26 snapshot and may change. Existing CI/contract evidence was used for DDIA/TPME EPUB/PDF consumers; no site was republished or deployed during this review.
7 - Community issue and PR review, 2026-09-19
This research records source inspection, live GitHub status, local builds, and targeted browser observations on 2026-09-19. At the initial review checkpoint, the recommendations were not yet accepted contracts or implemented features, and no PR had been merged, release published, or contributor reply posted. The implementation follow-up at the end records the subsequent changes.
The initial review is preserved below. The maintainer subsequently authorized merging PR #43 and implementing the remaining items directly on main; see the same-day implementation and acceptance follow-up.
Verdict
The reports identify useful problems, but they are not all defects of the same kind. Fix hidden navigation focus first. Accept the direction of PR #43 as a small correctness fix, after clarifying its boundary and adding coverage. Treat search-tail registration and public sidebar state as additive APIs with their own acceptance work.
| Item | Finding | Recommendation |
|---|---|---|
| PR #43, MagicFollower | Self-root collection ignores an explicit sidebar_root_menu: false. Reproduced. |
Conditional acceptance: the patch is correct for the global candidate list; document the current-root exception, add regression tests, and obtain successful CI. |
| #41, imbajin | Hidden whole-sidebar content remains focusable; disclosure state has several writers and no public API. | Split a correctness repair from an optional API. The former has higher priority. |
| #44, lloydsun | Pointer focus followed by a key produces the reported outlines. Reproduced on another platform. | Improve the main-content focus treatment; retain useful keyboard cues for scrollable content. The browser heuristic itself is expected. |
| #42, aucru | Existing hiding and divider options do not provide a complete non-link section group with its children. | Explain the options separately, obtain the author’s exact minimal example, and implement the missing group behavior if confirmed. |
| #40, imbajin | There is no supported way to append a query-dependent action to local search. | A reasonable small extension proposal, not a failure of existing local search. Lower priority than correctness repairs. |
Baseline and method
GitHub API reads found four open external issues and one open external PR. The other open issue, #37, is the maintainer’s release tracker. The reviewed external items had no discussion comments or submitted PR reviews at the snapshot time.
| Input | Verified snapshot |
|---|---|
Remote theme main |
93ac292014a3cd81f7c41caec4df98ed9d2dc45a |
| Local theme | 75ddc95; its only difference from remote main is release text in CHANGELOG.md |
| PR #43 head | 8eeb8ecaf525097cc56572fe22234db381bfc16a, one changed template line |
| Local documentation | ff0ba39; go.mod still requires OINK v1.0.0 |
| Published release | GitHub’s latest release is v1.0.0; no remote v1.1.0 tag was returned |
| Build tools | Hugo Extended 0.166.0, Node 26.9.0, npm 11.19.1 |
| Browser observation | macOS, Chromium 153.0.0.0, light theme, real sibling documentation site using a command-scoped module replacement |
The Design section’s released-v1.1.0 labels and the local release-preparation
commits do not establish that version’s publication. A source change, tag,
consumer pin, and hosted deployment remain separate facts. The public consumer
was not upgraded as part of this review.
The method combined the complete issue/PR bodies and comments, the exact diff,
the bilingual Design contracts, owning templates and JavaScript, a temporary
bilingual site under a /sub/ base path, and targeted browser interactions on
the documentation site. No theme implementation was changed in the shared
checkout.
PR 43: accept the small fix with a precise boundary
The first pass in
root-menu-roots.html
filters top-level sections by sidebar_root_menu. The second pass collects
sections whose sidebar_root_for is self, but omits that filter. A section
excluded by the first pass can therefore re-enter through the second pass.
The PR adds the same explicit-false predicate to the second pass:
This preserves the existing default for an absent or true value, retains the section constraint and URL deduplication, and does not change navigation-tree or pager ordering. It also preserves language-specific caching. There is no reason to replace this with a broad navigation refactor.
However, root-menu-entries.html subsequently appends the current resolved root when absent. That behavior already exists and is described in the navigation guide. It is not a new PR regression, but it prevents the broad claim that false now hides the root on every page.
The local probe used a top-level Blog root and a nested Docs root, both with
sidebar_root_for: self and sidebar_root_menu: false, plus a visible Docs
root and a self-root with no visibility override. Results were identical for
English and Chinese, retaining the /sub/ language-aware URLs:
| Viewed page | Before the PR | With the PR |
|---|---|---|
| An unrelated Docs page | Both hidden self-roots appear | Both disappear |
| A page inside the hidden Blog root | Blog appears | Blog still appears through current-root fallback |
| A page inside the hidden nested root | Nested root appears | Nested root still appears through current-root fallback |
| A visible self-root | Appears | Still appears; no duplicate |
Recommended contract: false removes a root from the site-wide selectable candidate set, while the current root may remain available for orientation. Keeping that existing exception is the smallest compatible interpretation. State it explicitly in both languages. If the intended contract instead means absolute exclusion, the current-root fallback and switcher trigger need a separate, coordinated change; adding one more predicate without checking zero and one-entry states is insufficient.
Before merging:
- Add an output-based case to
bin/check-shell.pyfor hidden top-level and nested self-roots, absent/true values, deduplication, and current-root behavior. Cover one-entry degradation and EN/ZH subpaths. - Update the Shell contract and navigation guide together. Correct the PR
description’s YAML comment from
//to#so its example is pasteable. - Resolve the workflow’s
action_required result
and run the required checks on the final head. At this snapshot there are
no successful check runs or commit statuses for the PR head. The API reports
MERGEABLEandUNSTABLE; neither is evidence that tests passed.
The maintainer can add these small finishing changes while preserving the contribution. Do not make acceptance depend on implementing #40 or all of #41.
Issue 41: repair isolation, then expose state
There are two separate findings.
First, whole-sidebar hiding uses transforms and, on desktop, opacity. The
drawer and collapse controllers do not remove hidden controls from keyboard
navigation. In the browser probe, clicking Collapse sidebar left focus on the
now-transparent collapse button; pressing Tab moved focus to the hidden root
switcher. The panel had opacity zero and no effective inert or
aria-hidden ancestor. This is a reproducible usability defect, not merely a
missing integration hook. The mobile closed-panel implementation uses the same
kind of off-screen positioning without explicit isolation.
Second, disclosure writes are duplicated across the click controller and responsive relocation and cached active-path hydration. There is no public setter, getter, or committed-state event. Existing storage for overall collapse, width, and scroll position does not persist each branch’s disclosure state across navigation. The authoring guide’s statement that reader expansion state is stored locally needs this distinction.
Recommended repair:
- Centralize whole-sidebar isolation at initialization and every open, close, collapse, hover-overlay, restore, and breakpoint transition. Remove isolation before moving focus inside; restore focus to a visible external control before making the content inert.
- Isolate the content, preserving the external restore button and the
deliberate desktop edge hover target. Applying
inertto that pointer sensor would break the existing hover interaction.aria-hiddenalone does not prevent keyboard focus; the HTML inert contract addresses interaction as well as accessibility exposure. - Separately route disclosure changes through one commit function, updating
aria-expanded, the open class, and localized label before emitting one event. Repeated writes of the current value should be no-ops. - Expose a small setter/getter and event only after specifying stable IDs, invalid-ID behavior, initialization readiness, and restoration order. Keep version/locale storage policy downstream-owned and let the active path win after restoration.
The proposal needs one scope correction: the responsive TOC/backlink/taxonomy groups can move out of the sidebar into the right rail. A controller that only looks up descendants of the current sidebar cannot also own those wide-layout writes. Register OINK-owned targets independently of their current DOM parent, and keep the public sidebar API restricted to its intended registered subset.
Acceptance must check real Tab order and the accessibility tree in hidden states, restored desktop collapse on first load, hover entry/exit, focus return, Escape, backdrop close, scroll unlock, and the 768/1200 breakpoints. Preserve the visible no-JavaScript fallback from #24. Static axe scans and assertions that a drawer can open do not establish these state-transition properties.
Issue 44: real symptom, partly expected behavior
On the documentation configuration page, clicking the article heading, a table
header cell, or a code block focused main#td-main-content,
div.td-table-scroll, or pre.chroma, respectively. In each case,
:focus-visible was false after the click and true after pressing the unbound
letter z. The main/code outline changed from none to the browser’s auto
outline; the table used the theme’s solid outline. This reproduces the
mechanism without the reporter’s Linux compositor or Super key.
The Selectors specification explicitly describes keyboard activity changing focus indication even when the focused element does not change. Therefore the report is useful UX feedback, but the expectation that a mouse-focused element must never acquire a ring after keyboard activity is not a browser correctness requirement.
Recommended treatment:
- Keep the main element’s skip-link target and focusability. Replace its oversized container outline with a localized, visible content-entry cue, such as a title-area indicator, and verify actual skip-link activation.
- Keep keyboard-visible focus for scrollable tables and code. Normalize its appearance if needed. Their focusability enables keyboard scrolling.
- Do not apply global
outline: none, remove alltabindexattributes, or blur the active element on arbitrary key presses. - If OINK chooses to suppress only the pointer-origin reading path, define that additional behavior explicitly and scope it to these non-editable containers. It needs focused pointer/Tab/skip-link/programmatic-focus tests, including dark and forced-colors modes. A global input-modality framework is disproportionate to this report.
This review supports a focused presentation improvement. It does not support removing the table/code keyboard cues simply to make the symptom disappear.
Issue 42: distinguish hiding from grouping
The question names _index.json and relies on screenshots rather than a source
fixture. The original screenshots were not successfully visually inspected in
this review; the author’s exact intended first change remains unresolved.
Request a small directory tree and its actual index/front matter when replying.
Do not assume _index.json is either a supported page source or a typo without
that evidence.
The existing options have different meanings:
| Option | Current behavior and limitation |
|---|---|
no_list: true |
Removes the child list from the section’s content body; does not hide its sidebar row. |
hide_summary: true |
Removes an item from a parent section’s body list; does not change sidebar grouping. |
toc_hide: true |
In the content-tree walker, filters out the node before recursion, also removing its subtree from that tree. |
sidebar_root_menu: false |
Controls root-switcher candidates, not the node’s row in the reading tree; see PR #43. |
sidebar_root_link_self: false |
Redirects a self-root’s row to its parent; does not turn it into a non-link group. |
sidebar_divider: true |
Emits a non-link heading, but the shared renderer does not emit the supplied children in that branch. |
build.render: link |
Suppresses the section HTML while retaining its permalink; the current sidebar still emits a link to it. It is not sufficient by itself. |
The temporary site confirmed that a divider section’s child HTML still exists
while its sidebar link disappears. A section with only build.render: link
has no section HTML but keeps a clickable sidebar row and its child. This
matches Hugo’s documented
build-option semantics
and the theme’s
shared node renderer.
For a real “group label with child links, but no directory-page navigation”
requirement, first consider completing sidebar_divider for section nodes:
retain the existing leaf divider, preserve children for a section, and use a
real disclosure button when folding is enabled. Check existing consumers before
settling that interpretation; introduce a separate node-level switch only if
the divider contract cannot express it compatibly. Keep publishing a section
page separate from whether its navigation label is a link.
The change must preserve hierarchy and active-path expansion in both walkers, keep children in the pager, and avoid dead targets in breadcrumbs, search, root switching, Print, and machine-readable navigation when the section page is intentionally unpublished. Hiding a whole node with CSS is not a solution.
Issue 40: a narrow extension is reasonable
Source inspection confirms the stated gap: groupsFor only composes built-in page/action groups, the public Palette object exposes no provider registration, and registerExecutor accepts only built-in action IDs. Static URL commands cannot substitute for a row that carries the current query. The existing Palette/model tests pass; that is evidence that the present feature works, not that this extension exists.
The proposed search-tail slot is a useful upstream boundary if kept small: synchronous data-only row creation, asynchronous activation, local results first, and OINK-owned rendering, selection, keyboard handling, and ARIA. It does not require OINK to bundle an AI provider, credentials, remote search, or a generic plugin system.
Before adopting the proposed API, settle and test:
- Exactly which settled text-search states call the provider; preserve empty, command, choice, loading, and default no-extension behavior.
- Snapshot the query/locale used to render each row. Preserve native empty and index-error messages, retry behavior, and the distinction between local page count and total selectable rows.
- Validate and copy descriptors; render titles and descriptions as text; isolate provider exceptions, duplicate IDs, and invalid descriptors.
- Handle synchronous throws and rejected promises, release pending state, reject duplicate activation, cancel stale sessions, and make unregister handles safe when an ID is later reused.
- Test handoff to another dialog. Existing Palette close already avoids restoring focus when focus has moved outside; preserve that guard. Define how successful surface handoff differs from cancellation, since a blanket “every close aborts activation” rule can cancel the assistant being opened.
- Preserve the default local-only network behavior and conditional bundles. A trusted extension’s documented purity is not an enforceable sandbox.
Promote the accepted API shape into a bilingual Design proposal before implementation. A downstream Ask AI wrapper can continue operating until a tagged release provides the hook. This is not a prerequisite for shipping the small correctness fixes.
Delivery order and ownership
| Order | Delivery | Owning checks and documentation |
|---|---|---|
| First | PR #43 completion and hidden-sidebar isolation as separate small changes | check-shell.py; site responsive/keyboard/accessibility cases; EN/ZH Shell contract and navigation guide |
| Next | Main-content focus styling and clarified grouping behavior | Content/reading and navigation checkers as appropriate; browser focus/scroll/skip tests; EN/ZH architecture, shell, and authoring guidance |
| Later | Public disclosure controller, then search-tail API | Theme JS tests and check-navigation-contract.py / check-palette.py; real site fixtures; accepted bilingual API contracts |
For every behavior change, first run its owning checker, then use the sibling
site’s make check, make browser, and make dev workflow for the relevant
integration and visual review. Do not make these unrelated proposals into one
large sidebar/search rewrite or delay small fixes until every feature exists.
Suggested response content, not posted: acknowledge #43’s filter bug while explaining the current-root exception; accept #41’s isolation defect and split its API request; acknowledge #44’s reproduction with the standard focus explanation; give #42 the option distinctions and request its minimal input; mark #40 as a scoped enhancement rather than a local-search failure.
Historical external issues are already closed. #22 was resolved by enabling Goldmark passthrough, with confirmation from its reporter. #21 received the Mermaid viewer and fixed centered presentation; arbitrary right alignment was explicitly not included. Neither should be silently counted as a new open bug.
Validation and limits
Executed for this review:
- The owning
python3 bin/check-shell.pypassed on the local baseline and in an isolated checkout of PR #43’s exact head. - The Palette controller and model test files passed, two test files and no failures.
- Strict temporary Hugo builds before/after the actual PR diff reproduced
self-root filtering and fallback in EN/ZH under
/sub/; the same fixture demonstrated the grouping limitations. - The real bilingual documentation site built with
--panicOnWarningusing the local theme. Targeted Chromium interactions reproduced all three focus outlines and the desktop hidden-focus defect. - The site’s bilingual, rendered-content, and link checks passed, as did all
57 tests in its non-browser suite. The initial
make checkstopped at thellms.txtsnapshot because this report added an index entry. After verifying that one-line addition and updating the golden, the affected and remaining test groups were rerun successfully.
The new bug assertions are investigative probes, not committed regression tests. This was not a full release certification or an all-browser matrix. The local Hugo version was 0.166.0, not the CI-pinned 0.165.0 or the declared 0.160.1 floor. Linux Super-key behavior, mobile accessibility-tree isolation, dark/forced-colors cases, and the author’s exact #42 screenshots still need the acceptance coverage described above. No hosted deployment, release, consumer upgrade, or upstream discussion was changed.
Implementation and acceptance follow-up
The maintainer chose to merge the contributor’s patch first, then complete the
repairs and extensions directly on main without another pull request.
PR #43 merged as
6e814089.
The merge was pulled while preserving the existing local release-note commit.
The implementation follow-up is
56bfe37.
| Item | Implemented behavior | Owning acceptance |
|---|---|---|
| #43 | Both root collectors honor explicit false. Current-root orientation remains compatible; dividers and unpublished sections do not become switcher links. | Strict EN/ZH subpath fixtures cover hidden top-level/nested roots, absent/true values, deduplication, current-root fallback, zero and one entry. |
| #41 | One disclosure controller commits ARIA, classes, labels and inert state. A late-safe API supports downstream persistence. Hidden whole-sidebar content is isolated while hover and drawer restoration remain usable. | Runtime tests plus browser checks for atomic events, no-op writes, scope, active paths, blocked storage, responsive relocation, focus return, real Tab traversal, Escape, backdrop and breakpoints. |
| #44 | A pointer-origin mark suppresses later incidental container outlines. Tab and fresh programmatic focus retain visible cues; the skip destination outlines the title. | Browser checks for article/table/code in light, dark and forced-colors modes, plus keyboard and skip-link regression coverage. |
| #42 | Divider sections keep their children under a non-link label. build.render: never suppresses their own page. Breadcrumb, search, pager, navigation JSON, Book TOC/Markdown and Print agree. Explicit navigation also works under bilingual subpaths. |
Strict generic/data-tree fixtures, Book depth-three heading checks, EN/ZH browser fixtures and no-JavaScript traversal. |
| #40 | Trusted site scripts can register synchronous data-only search-tail rows and asynchronous activation. Native ordering, ARIA, validation, error isolation, cancellation, unregistering and focus handoff remain OINK-owned. | Runtime lifecycle tests and a Chinese browser scenario covering pointer/keyboard selection, literal display text, context snapshots, external-dialog focus and unregistering. |
Acceptance against the sibling theme checkout completed on macOS with Hugo Extended 0.166.0, Node 26.9.0 and Chromium:
- All 44 theme JavaScript tests passed.
check-shell.py,check-reading.py,check-palette.pyandcheck-keyboard.pypassed. A broader run passed 29 of the other 31 commands from the theme CI configuration. The two local failures were the media checker’s version-specific processed-image hashes and four goldens containing Hugo 0.166’s changed KaTeX output; ordinary navigation markup matched after preserving its existing whitespace. The fixed CI toolchain is verified separately below, rather than rewriting unrelated expected output.make -C ../oink.pgsty.com checkpassed: bilingual source/rendered/link checks and all 57 non-browser tests.make -C ../oink.pgsty.com browserpassed all 141 tests: 30 accessibility, 45 responsive/blog/palette, 16 keyboard, 10 content, 18 code-block, 4 scenario, 5 theme-color and 13 community regressions. The accessibility suite included the complete multilingual sitemap scan.- Strict theme fixture output and namespace checks passed. Local Book packaging produced an EPUB with five chapters and zero checker errors, and a 23-page PDF containing all five expected Book pages with zero checker errors.
make devserved the real documentation site for visual inspection of desktop light, Chinese dark, collapsed-sidebar restore and a 375px mobile drawer. Escape returned focus to the visible drawer opener. The temporary browser viewport and development server were cleaned up afterwards.
The accepted contracts are in Shell and Architecture, with matching Chinese sources and updated navigation, organization, palette and Print guides. The regression suite belongs to the documentation repository; the theme keeps only its focused checkers and synthetic inputs.
The merged PR’s
fixed-toolchain CI
passed all three jobs. The final implementation’s
CI run also passed on
exact revision 56bfe37092a43fc12c0e16f865d3d3407c55cbde: Hugo 0.165.0, browser
runtime tests and Book publication all succeeded. This includes the media and
four-state golden checks that differed locally on Hugo 0.166.0, plus publication
under root and subpath URLs. The supported 0.160.1 floor was not separately
retested; the declared continuous-test toolchain remains 0.165.0.
This is source and integration acceptance, not a new release. No new tag was
created, the documentation consumer still pins v1.0.0, and production was not
upgraded. The sibling documentation changes are prepared on local main for the
next theme publication; pushing their new browser gate against the old public
pin would test the wrong implementation. No contributor reply was sent, and issues #40, #41, #42 and #44 remain open. The exact original #42 screenshots and the reported Linux
Super-key setup were not independently reproduced; the explicit grouping
requirement and equivalent pointer-plus-key behavior were tested as described.
Image-copy follow-up
The maintainer also reported preview instructions appearing below images after
copying a blog article into a rich-text editor. The blog pins OINK v1.0.0 and
enables params.ui.image_zoom. That release and the reviewed main revision
inserted a visually hidden text span after each eligible image. Native Chromium
copy reproduced the extra Open image preview and Chinese equivalent in the
clipboard; this is a theme defect independent of the destination editor.
Theme commit 75052f8 moves the
image description and localized action into the button’s aria-label. No helper
text node is added to the article. The image alt text, authored captions, native
button operation and dialog focus return are preserved. The
component contract
and image guide document the copy behavior.
check-image-zoom.py passed, as did all 57 non-browser site tests. The focused
browser run passed 16 tests: the 14 content-component cases, including four new
EN/ZH image/gallery clipboard regressions, and two desktop-light/mobile-dark
dialog accessibility cases. The regressions read both plain-text and HTML
clipboard data, check text after removing its styling context, and verify
retained image URLs, alt text and captions. They also check accessible names.
No live Zhihu editor was used for acceptance. The blog dependency and hosted deployment were not changed; the fix reaches that published consumer after its theme dependency is upgraded and the site is rebuilt.
8 - OINK 1.1 release review, 2026-09-20
This record separates the reviewed baseline, committed fixes, completed validation, and remaining publication steps. A passing baseline CI run does not certify the later fixes. The sections through Limits preserve that pre-publication snapshot; later release evidence is appended under Publication follow-up.
Scope and baseline
The review starts at theme commit
75052f8a3106d13ef313644836a5ad545135f484,
after the community fixes and image-copy repair. It examines the v1.0.0..main
change set, the behavior requested by issues
#40,
#41,
#42,
#44, and merged
PR #43, plus the bilingual documentation
and release boundary. The
previous review
records those original reports and their implementation.
Method: inspect owning JavaScript, templates and contracts; exercise transition boundaries with focused regressions; compare failing assertions before a fix with the repaired implementation; then run the theme checkers and the real sibling documentation site’s integration and browser suites. The review does not add another feature program or claim a comprehensive security audit.
At this snapshot, the public release, documentation go.mod pin and configured
public version are still v1.0.0. The blog consumer’s theme pin is unchanged.
Findings and repairs
Five P2 correctness defects were reproduced and repaired in theme commit
08f6563,
pushed to main. They concern the new
APIs’ ordering and existing focus/navigation behavior; they do not require a
new configuration format or a content migration.
| Finding | Trigger and observed failure | Minimal repair |
|---|---|---|
| P2: sidebar readiness fires before hydration | A consumer awaits OinkSidebar.ready or handles oink:sidebar-ready. The readiness microtask can run between DOMContentLoaded listeners, before the cached sidebar’s active path is hydrated. Consumers see incomplete initial state. |
Resolve readiness in the next task, after all initialization listeners and aside placement finish; preserve the existing ready Promise and event contract. |
| P2: a pending action can enter a native choice menu | Start an asynchronous search-tail action, then activate a native choice such as theme selection. The pending guard ran after the choice branch, allowing that menu to replace the pending action’s rows. | Check pending activation before any row-type branch. After completion, ordinary choice activation is available again. |
| P2: a collapsed right TOC rail remains focusable | Collapse the desktop right rail. Its hidden control and links remain keyboard targets; focus can stay inside the hidden panel. | Apply inert and aria-hidden to the rail panel, move focus to the visible restore control, and return it to the column control on restoration. Keep the movable aside outside that isolation when relocated. |
| P2: arrow navigation skips non-link groups | From a child of a divider-only group, Left/a cannot consistently return to the parent disclosure and fold it; the group button is absent from the tree’s focus sequence. |
Include group disclosure buttons in tree focus navigation and direct-parent traversal. Right/d opens or enters the group; previous/next page navigation still uses links only. |
| P2: drawer focus wrapping counts inert descendants | In the mobile drawer, collapse an aside group and wrap with Shift+Tab. Hidden descendants still counted as focusable can make the wrap fail or leave focus stuck. | Exclude controls under inert or hidden, and controls with hidden/collapsed visibility, from the drawer’s focusable set. |
Implementation and regression ownership:
| Finding | Theme implementation | Owning regression |
|---|---|---|
| Readiness | assets/js/sidebar-state.js |
tests/js/sidebar-state.test.js; site tests/browser/community-feedback.spec.mjs snapshots the active path from both readiness signals in EN/ZH |
| Pending choice | assets/js/command-palette.js |
tests/js/command-palette.test.js exercises pending extension → native choice → completion → available choice |
| Right rail | assets/js/docs-shell.js |
Site tests/browser/community-feedback.spec.mjs covers EN/ZH collapse, Tab traversal, restoration, reload and aside relocation across desktop/tablet/mobile |
| Group keys | assets/js/keyboard-nav.js |
tests/js/keyboard-nav.test.js covers LTR/RTL, arrows/WASD and link-only paging; site community tests exercise real EN/ZH groups |
| Drawer trap | assets/js/docs-shell.js |
Site community tests collapse the relocated groups, wrap Shift+Tab and Tab, and assert focus never enters an inert or hidden subtree |
The readiness and pending-choice regressions failed against the previous implementation before their fixes. The right-rail browser assertions also failed in both English and Chinese before isolation was added. The repaired code is kept small: timing, one earlier pending guard, explicit rail isolation, tree focus targets and the drawer’s visibility filter.
These changes preserve the already accepted behavior: both root collectors
honor sidebar_root_menu: false; non-link groups retain their children; pointer
focus avoids incidental article outlines while keyboard cues remain visible;
search-tail callbacks retain their cancellation and handoff contract. The image
preview fix continues to use an accessible name without inserting helper text
into copied article content. Final regression results are recorded separately
below rather than inferred from code inspection.
Documentation readiness
The current documentation update covers 28 files in 14 EN/ZH pairs:
- The six Design contract pairs use
candidate-v1.1.0and describe implemented main behavior without announcing a published release. - Navigation, layout and front-matter guides match the current root filtering, divider groups, bilingual deployment paths, centered navbar, narrow-screen drawer and in-place navbar reveal behavior.
- Organization and palette guides explain runtime load order, readiness, feature detection and site-owned persistence/integrations. Keyboard and image guides explain the fixes and the older-version boundary.
- Installation guidance distinguishes the validation toolchain from the public version. Existing heading IDs remain stable; the new sidebar API heading has a matching Chinese ID.
The two 1.1.0 release-note files and two upgrade-guide files are also prepared. The release note remains a draft/candidate. Both home-page release entries point back to the published 1.0 version. These source edits neither update the site’s module dependency nor deploy new behavior. Historical research remains a dated record and is not rewritten to erase its earlier release-state observations.
Validation snapshot
Counts below are the 2026-09-20 snapshot for theme 08f6563. Site acceptance
uses the sibling checkout through a command-scoped module replacement; it does
not certify an unpublished module tag or a production deployment.
Local site checks used Hugo Extended 0.166.0, Node 26.9.0 and Playwright 1.62.1;
the candidate CI used the pinned Hugo 0.165.0 toolchain. The 0.160.1 floor was
checked separately with the official binary.
| Check | Result and scope |
|---|---|
Baseline 75052f8 CI |
Passed all three jobs: pinned Hugo toolchain, browser runtime tests and Book publication. Exact baseline run. |
| JavaScript unit suite after the fixes | Passed: 44 tests. |
| Official Hugo Extended 0.160.1 | Passed the focused i18n and shell checkers; i18n covers 32 catalogs × 194 messages. The real documentation site also passed a production build with --panicOnWarning against the local candidate: 376 pages per language. The draft release is absent and both home-page links point to 1.0.0. This is selected compatibility-floor evidence, not a second complete CI matrix. |
| Bilingual source and style checks | Passed including this report: 129/129 page pairs, 988 source headings, Markdown style and git diff --check. |
| Final focused theme checkers | Passed: shell, palette, keyboard and image zoom. |
| Final real-site non-browser suite | make check passed all 57 tests; 200 rendered content pages, 331 linked HTML pages, 39,803 internal links and 3,863 fragment links were checked. Only the two expected Markdown goldens changed, for the release summary and documentation index. The floor production build also passed links: 327 pages, 39,059 internal links and 3,833 fragments. |
| Final browser suite | make browser passed all 149 Chromium tests in eight suites: 30 accessibility, 45 responsive/blog/palette, 16 keyboard, 14 content components, 18 code blocks, 4 scenarios, 5 theme-color and 17 community regressions. Includes the full multilingual sitemap, six viewport widths, light/dark, forced colors, clipboard and no-script cases. |
| Agent documentation sample | 93/100 (A) across 50 same-origin sampled pages. Sampled links resolve; 49 provide Markdown and all 270 sampled code fences close correctly. The checker warns that the HTML llms.txt discovery hint is missing or too deep. |
| Rendered review | Reviewed the Chinese release note in a desktop dark view and English in a narrow light view. Right-rail collapse removes its descendants from the accessibility tree and moves focus to the restore button; restoring returns focus to the visible rail button. |
| Final theme revision and its CI | 08f6563 passed all three jobs: Hugo 0.165.0, browser runtime tests and Book publication. Exact candidate run. |
| Public v1.1.0 tag, consumer upgrade and deployment | Not performed. |
Within this review’s scope, no unresolved implementation blocker remains. The candidate is ready for the publication steps below.
Repeat the checks from sibling checkouts, keeping the published dependency pin intact during development:
Remaining publication steps
Publication has not been executed. After the final revision passes acceptance:
- Finalize
CHANGELOG.md, release date and the release record; publish the v1.1.0 tag and GitHub Release from the verified theme revision. - Verify that the module proxy resolves that tag to the intended revision.
- Update the documentation consumer pin and version configuration together
with its home-page release entry, contract status and release-note
draft: falsestate. - Rebuild and accept the documentation site using the published dependency,
without
HUGO_MODULE_REPLACEMENTS; deploy it and verify the public routes.
The final sign-off must identify the tested theme revision and distinguish local source acceptance, public module availability and deployed output.
The remaining optional improvement is an earlier, consistent llms.txt
discovery hint for agents entering through HTML. This scorecard warning does
not invalidate the current Markdown outputs or require a new feature before
1.1. A Safari/Firefox pass and a real Zhihu paste check are useful follow-ups;
neither is claimed by this Chromium acceptance run.
Limits
Browser evidence is from Chromium, not a Safari/Firefox matrix. The automated accessibility gate covers theme-owned surfaces and retains its existing exclusions for vendored Redoc and Swagger UI. The native clipboard regressions cover plain text and rich-text HTML, image descriptions and authored captions; they do not certify the live Zhihu editor’s paste behavior. Neither the blog’s dependency pin nor its hosted output was changed or accepted in this review. The focused Hugo floor checks do not establish that every publication path was exercised on that version.
This is a release-readiness review of the named source and behavior. It does not claim unbounded security coverage, production rollout, or support for additional requested features.
Publication follow-up
After this review, the v1.1.0 release
was published on 2026-09-20 from
3a18234.
This revision changes only the changelog from the accepted 08f6563
implementation. All three release-commit CI jobs
passed before the annotated tag and stable GitHub Release were published.
A fresh-cache download using only the official Go module proxy resolved the
tag to that exact commit. Its .info, .mod, .zip, version-list entry and
signed checksum record were verified. The module checksum is
h1:121L5g57ChRCPyidzEBBcln2Co+0zYRQ+XDDXjymd0Q=; the go.mod checksum is
h1:pHvbUhJCfseB41n5RGwsF7abT3i32VSTpofLQoq4b7Y=.
The public records are the proxy version
and checksum entry.
The documentation publication update pins v1.1.0 in go.mod and go.sum,
aligns the advertised version and both home-page release entries, publishes
both release notes, and promotes the six contract pairs to released-v1.1.0.
The historical acceptance tables above continue to describe the earlier
sibling-checkout run. Published-dependency validation is tracked separately by
the site’s Site checks
and Browser quality
workflows, with both Go and Hugo module workspaces disabled.
Local validation of this published module passed all 57 non-browser tests,
26 focused Palette/community browser tests, and the strict production build
(378 pages per language). The checks ran with GOWORK=off,
HUGO_MODULE_WORKSPACE=off, and no HUGO_MODULE_REPLACEMENTS. The complete
149-test browser suite is also run by the publication commit’s Browser quality
workflow; its result is separate from the earlier local candidate run.
9 - CLI maintenance acceptance on 2026-10-03
This record preserves earlier R1–R8/A18 acceptance. Command changes do not rewrite those results. The reduced CLI and its Cobra/text/JSON/YAML interface on 2026-10-04 are defined by the current contract and guide. Earlier runtime qualification does not qualify a changed binary automatically.
The initial audit is retained below. R1 implementation and owning checks have passed their local scope, including refreshed consumer reports and scoped rendered EN/ZH acceptance. R2’s scoped local gate is also accepted, with a separately tested numeric-equality supplement. R3’s runtime and paired documentation gates have passed and its local stage is accepted. R4 supported implementation and read-only corpus gates have passed locally; guarded canonical documentation validation is recorded separately below. R5 corrected implementation/read-only corpus and guarded canonical documentation gates have passed; its supported local scope is accepted. R6 explicit workspace and optional adapters passed frozen owning/runtime, exact-binary consumer and guarded canonical source/render gates; supported R6/A07/A15 scope is accepted locally. R7 read-only Studio/A16 also passed its browser, four-consumer and guarded canonical rendered gates. R8 reviewed editing/A17 passed its corrected frozen owning/browser, exact-binary consumer and guarded canonical source/render gates. R1–R8 supported scope is accepted locally. The 2026-10-04 supplement refreshes the changed backend and closes current A18 runtime/archive qualification for the three declared targets. Canonical lifecycle promotion/render has a separate exact-byte receipt boundary; public release, adoption and deployment have not occurred.
Scope and evidence rules
The maintenance roadmap defines the authorized R1–R8 scope. The current CLI contract defines its compatibility baseline; the original roadmap does not add Docsy migration, version lifecycle, OpenAPI, theme publication, or the conditional E1–E4 extensions to this program. Hugo remains an external renderer and generated sites remain ordinary Hugo projects.
Stages are accepted in dependency order. Every stage needs a complete usable flow, its owning tests, relevant actual Hugo integration, known limits, a reviewable diff, and accepted EN/ZH contract and guide updates. Passing an aggregate command alone does not close a case. New public behavior moves from the proposal into the owning contract only after its implementation and acceptance evidence exist.
In the tables below, existing, not rerun means code or a named test was inspected but its current runtime outcome was not established. Partial means the first candidate provides a reusable part of the required behavior. Open means new implementation or decisive acceptance evidence is missing. Passed, failed, unverified, and unsupported must describe a specific executed input and scope when later runs are recorded. No historical result is relabeled as a current pass.
Inspected inputs and tools
The initial 2026-10-03 audit read both repositories’ instructions, the documentation README and translation rules, both maintenance PRD languages, the original proposal, the current CLI contract, and existing Go packages and test names. It executed version and Git inspection commands only; it did not run the owning suites or write consumer sources.
| Input | Observed initial state |
|---|---|
| Host and Go | darwin/arm64; go version go1.27.1 darwin/arm64 |
| Hugo | hugo v0.166.0+extended+withdeploy darwin/arm64, Homebrew build dated 2026-09-09 |
| Node and npm | v26.9.0; 11.19.1; contributor/documentation tools, not CLI consumer requirements |
| Git | 2.54.0 (Apple Git-157) |
| CLI source | e623d93d589c49e5c58b8fae1bd5db720fc904cb, main; clean initial tracked/untracked status; generated bin/, dist/, tmp/ ignored |
| Documentation source | 907d873eb05cfc2e194f492462dfa94849e93474, main; 184 initial porcelain entries, including existing proposals, contracts, guides, and unrelated content changes |
| Embedded Starter | 137843b25bacd76ddd1f7ce71330bf2e3155b954; provenance and license already recorded by internal/starter |
| Declared theme baseline | github.com/pgsty/oink v1.1.0 in Starter and the three selected sites; effective resolved bytes still require each acceptance run |
The 2026-09-29 acceptance record contains historical first-candidate checks. It supplies useful reproduction inputs, but does not prove the new maintenance scope. Existing dirty files are preserved; this initial research addition does not accept or overwrite them.
Stage requirements and implementation evidence
| Stage | Required complete flow and invariants | Initial implementation evidence | Acceptance evidence still needed |
|---|---|---|---|
| R1 | Shared page identity, languages, publication state, source provenance, actual outputs, translations and observed references from Hugo; oink.yaml owns check policy only; links/translations/style share analysis; severity and exclusions cannot hide required incompletion; trustworthy locations |
Partial: internal/site isolated snapshots and Page.OutputFormats probe, internal/outputcheck, internal/report; no shared translation/page facts or policy commands at initial audit |
Real Hugo routes, aliases, mounts, unlisted/generated-source cases and language relationships; public focused-check/policy cases; required unknown/tool/build/input failures remain 2; source locations only when reliable |
| R2 | Three language layouts; strict/manual and localized policies; duplicate, missing and draft states; explicit versioned review records bind source language and source/translation hashes; bounded native syntax rules; effective-theme coverage; visible versioned baseline; reviewed fixes validate before narrow apply | Open: no translation/review/native-rule/baseline public command at initial audit; rendered-reference checks remain reusable | A04–A07; valid/invalid reviewed content corpus; no mtime review inference; disabled/localized languages handled; acknowledged findings stay visible; missing required checks stay incomplete; fix preservation |
| R3 | Preserve thin default build/dev; build --check checks and manifests one strict Hugo output, exports only to new/empty target; digest/provenance manifest and optional minimal public identity; both local CI templates upload the same tree; release diagnosis; explicit-network public verification |
Partial: direct wrappers, strict isolated checks and licensed workflow inputs exist; managed build/export, digest verification, CI plans and public verify are absent at initial audit | A08–A10; exactly one Hugo build; stale-byte rejection; revision/dirty/input/theme/tool/settings/coverage provenance without secrets or machine paths; workflow customization/conflicts/provenance and immutable source input; example address policy; fallback/language/resource/canonical/timeout/auth/rate-limit HTTP fixtures |
| R4 | new, snippets and editor setup create ordinary inputs without overwrite; docs/blog/book/project profiles compose one licensed Starter; upgrades provide readable diff and old/new routes, aliases and enabled outputs; unsupported migrations give manual action; existing protections survive |
Partial: fixed archive language profiles and hash-bound single-site module upgrade with candidate validation, backups, dirty/workspace/replacement/vendor protection | A11–A12; all new profile/language combinations build with ordinary Hugo; unknown editor settings retained; upgrade route/capability regression and readable diff; source provenance and licenses retained |
| R5 | inspect, impact --since, bounded context, preview move; shared plans include touched files, diff, base hashes, translations, attachments, output/route changes and alias advice; candidate validation and stale/concurrent-safe recovery; ambiguous references require review |
Partial: module-specific upgrade plan/apply primitives; no shared content plans or inspect/impact/context/move flow at initial audit | A13–A15; deleting B includes unchanged inbound A; translation/attachment/derived-output impact; uncertain/global changes force full checks; no content execution; candidate/stale/failed-write preservation and ambiguous-link handling |
| R6 | Explicit versioned site registry reuses single-site engine; per-site and aggregate completion; writes only to selected sites; configured preinstalled markdownlint/Vale/lychee adapters normalize findings and declare syntax/network coverage | Open: no workspace/adapter public command at initial audit | A07/A15/A18; direct/per-site parity; no sibling discovery, implicit installation or default formatting writes; required missing tool 2, optional omission visible, external network uncertainty distinct |
| R7 | Read-only loopback Studio with overview, issues, translation comparison, page relationships and publication views; filters, known sources, actual Hugo preview, comparisons and copied actions; CLI parity; prebuilt assets; explicit allowlist, separate preview origin, Host/Origin/session protection | Open: no Studio server or assets at initial audit | A16; browser/keyboard/screen-reader/mobile/light/dark/long-list flows; same underlying results as CLI; unauthorized hosts/origins/sessions and preview-to-management requests rejected; Node unnecessary for consumer runtime |
| R8 | Markdown/text and front matter forms, selected components and collision-safe attachments reuse plans; authorized allowed writes with visible diff, hashes and candidate validation; no-op bytes and unknown fields/comments/order/encoding/whitespace retained; unsupported form syntax stays text | Open: editing follows accepted read-only R7; no editor API at initial audit | A17/A14; byte-identical no-op, surgical YAML field updates and text fallbacks; stale external-editor saves, traversal/symlink escapes and preview requests fail safely; attachments never overwrite; no management API in static publication |
R1 local validation
R1 now provides shared Hugo page/translation/source facts, rendered reference
and anchor evidence, strict oink.policy/v1 input, check links,
--format json, visible reviewed exclusions/external scopes and required-work
precedence. Translation and style selections explicitly return required
unsupported coverage; they are not implemented engines. Default build/dev
remain direct Hugo operations. The following evidence accepts the tested
shared-facts/policy scope without closing R2–R8 or the full A01–A18 cases.
| Requirement | Executed evidence | Current outcome |
|---|---|---|
| Public result/policy and incomplete precedence | make test: all packages and vet; public severity/exclusion/unimplemented-group/JSON-alias tests; TestEveryRequiredUncompletedCoverageFails |
Passed R1 scope; any required uncompleted status, including not_checked, remains 2 |
| One build and shared facts | TestPublicCheckSharesOneBuildAndRenderedFacts |
Passed; one strict Hugo build supplies page and observed target/anchor facts |
| Hugo authority and source mapping | Actual TestPageFacts* fixtures: translationKey, actual routes/aliases, unknown generated nodes, custom mounts, excluded-page analysis and failure preservation |
Passed; separate analysis preserves production facts/artifact bytes and source bytes/modes |
| Repeatable real Hugo gate | Corrected make test-hugo includes TestPageFacts* and TestHugoRendered*, alongside Starter and manifest fixtures |
Passed; scoped route/reference, reviewed external-scope and original-output preservation cases |
| Fresh Starter | Bilingual init, check links, ordinary strict Hugo using isolated provisioned v1.1.0 module archives |
Exit 0; 223 files, 4,461 references, 66 page facts; dependency preparation remains explicit |
| R1 documentation source and schema | Markdown style under content/docs; bilingual source checker; JSON parse and equality of CLI/docs result schemas; scoped diff whitespace check |
Passed: 88 Chinese docs, 137/137 source pairs and 1,085 headings; schemas remain additive oink.result/v1 with exits 0/1/2 |
| Final candidate reports and rendered EN/ZH | Refreshed current-binary consumer reports; actual rendered source/Markdown/link owning checks below | R1 scoped gate passed; existing draft-release omission in production is recorded separately |
Earlier offline R1 trials returned 0 without diagnostics on three consumers:
| Earlier trial | Source files | Built files | HTML files | References | Page facts | Bytes/modes/Git inventory |
|---|---|---|---|---|---|---|
| OINK documentation | 421 | 1,139 | 512 | 74,689 | 341 | Exact before/after equality |
| PIG project site | 858 | 1,392 | 424 | 64,440 | 248 | Exact before/after equality |
| Repository catalog | 2,294 | 3,287 | 1,635 | 851,535 | 1,572 | Exact before/after equality |
These earlier reports spell optional unselected coverage not_selected,
outside the existing result-schema enum. The final code corrects it to
not_checked and includes project.pages coverage. Their measured counts and
exact inventories remain valid earlier-binary observations; final JSON
conformance is established by the final reports below. Raw evidence stays in task-named local
acceptance directories outside consumer sources. These trials do not prove
external availability, deployment, Linux runtime or translation/style acceptance.
The final R1 binary was rebuilt from the dirty CLI working tree based on
e623d93d589c49e5c58b8fae1bd5db720fc904cb. The recorded input inventory includes
file hashes, modes and Git-status identity. Its SHA-256, computed over sorted
JSON serialization, is
518260f07f3c916468ee3d56c4eeca03c131514155aa82539564ccd2f3c1f664.
The exercised binary SHA-256 is
3deb7e357fc86f6907df60da0769d93f2d41ba5e01949b641548a67d7f459d12.
This identifies local inputs and an executed binary, not a maintenance commit,
public archive or published module.
| Final current-binary trial | Source files | Built files | HTML files | References | Page facts | Acceptance |
|---|---|---|---|---|---|---|
| OINK documentation | 421 | 1,139 | 512 | 74,755 | 341 | Exit 0, valid result, complete page facts, exact source bytes/modes/Git preservation |
| PIG project site | 858 | 1,392 | 424 | 64,440 | 248 | Exit 0, valid result, complete page facts, exact source bytes/modes/Git preservation |
| Repository catalog | 2,294 | 3,287 | 1,635 | 851,535 | 1,572 | Exit 0, valid result, complete page facts, exact source bytes/modes/Git preservation |
Each final result has check.links: complete and project.pages: complete,
both required. Unselected translation/style coverage is not_checked, optional.
The final offline make test and vet passed; the corrected actual-Hugo owning
target also passed. The recorded tools remain Go 1.27.1, Hugo Extended 0.166.0,
Git 2.54.0 on macOS arm64. The three exact before/after inventories were
independently compared while preparing this record.
Production output passed rendered Markdown and link checks. Its global
translation checker returned 1 solely because the pre-existing draft
content/blog/release/1.2.0.md / .zh.md pair is correctly absent from
production. The changed R1 pages rendered in both languages. A separate explicit
analysis build with HUGO_BUILDDRAFTS, HUGO_BUILDFUTURE and
HUGO_BUILDEXPIRED set to true passed all three owning checks: 137/137 paired
sources, 1,085 headings, rendered Markdown and rendered links. That view is
nonpublishable evidence for excluded sources; it never replaces production
output and does not change or publish the draft. No existing draft file was
modified to make the global production checker green.
R2 local validation
The local candidate now implements translation policy/status/diff/hash review,
syntax-bounded native content rules, visible reviewed baselines and shared
oink.plan/v1 preview/validate/apply. Default check requires links,
translations and style. Production output and the explicit draft/future/expired
analysis are separate; the latter is not publishable. Stable behavior and
examples are in the contract and
guide. The R2 local gate passed owning checks,
final frozen-input consumer reports and rendered bilingual documentation.
The exact exercised binary and the subsequent narrow equality fix are recorded
separately below; no public release or consumer write is implied.
| Requirement | Executed owning evidence | Outcome and limit |
|---|---|---|
| A04 translation relationships/policy | Actual TestHugoFilenameDirectoryAndTranslationKeyLayouts; scope, duplicate/missing/disabled-language, draft, strict/localized and selected-constraint tests |
Passed owning tests; no universal heading/code/localization parity |
| A05 explicit review and diff | Full byte hash/current/source/translation/both-changed, mtime-independent, unknown/unreadable/ambiguous and malformed-record tests; public status/diff/review preview/apply fixtures | Passed owning tests; review state is change evidence, not semantic judgment |
| A06 source boundary and provenance | Actual Hugo enabled/disabled canonical title/block attributes and configured passthrough fixtures; front matter/CRLF/BOM/shortcode/code/HTML tests; every public v1.1.0 source/license SHA verified |
Passed owning tests; unsupported syntax remains incomplete and custom hooks remain outside catalog attestation |
| A07 baseline scope | Capture/visible acknowledgement/new finding/incomplete precedence and malformed-record tests; public baseline preview/apply fixtures | Passed R2 baseline scope; external tool adapter acceptance belongs to R6 |
| A14 shared metadata plans | Stale bytes/modes/existence/guards; edits during validation; exclusive commit collision; partial restore; later editor bytes/modes/deletion; old open inode write; new-directory children; confinement/identity/diff tests | Passed owning tests and vet; candidate/source overlap refused; later move/reference ambiguity remains R5 scope |
| Frozen runtime gates | macOS arm64 make test/vet, owning actual Hugo and focused race runs |
Passed; logs /tmp/oink-r2-frozen-go-gate.log, /tmp/oink-r2-frozen-hugo-gate.log, /tmp/oink-r2-frozen-race-gate.log; final all-owning-package Hugo gate /tmp/oink-r2-owning-hugo-final.log explicitly includes configured passthrough |
| Bilingual documentation | Narrow source style/pairing/IDs, equal result schemas, scoped whitespace and actual production/analysis node checks | Passed scoped gate: 88 Chinese docs, 137/137 source pairs and 1,092 headings; production draft omission separately recorded below |
The frozen parser corpus at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r2-source-corpus-lqx25kwr/summary.json
records parser input SHA-256
a601200ec4fe275d2bd4baf11d4db7d46a2cc6f1674900c1fd801769e55d12de.
Each scope parsed completely with zero findings. The core uses actual Hugo
site-source identities from the recorded configuration; supplemental Markdown
includes disabled/unpublished files and does not invent routes or relationships.
These captures precede the authorized R2 documentation edits.
| Corpus | Unique actual Hugo source files | Supplemental local Markdown | Source inventory files | Bytes/modes/Git |
|---|---|---|---|---|
| Starter | 52 | 78 | 97 | Exact before/after equality |
| OINK documentation | 272 | 274 | 421 | Exact before/after equality |
| PIG | 212 | 212 | 858 | Exact before/after equality |
| Repository catalog | 1,568 | 1,572 | 2,294 | Exact before/after equality |
Preliminary public-command reports at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r2-final-qu_zprps/summary.json
used binary c8d87e6d73d3101fefcb62c5d6845518573c02c400f474dc9f4603afafc774d5
and CLI input inventory d8a75be0e074365a4164b7aaaa27d82a1e844e04406a36c3dd6d39ff2b6e873f.
They precede the final parser/doc freeze and are not final acceptance evidence.
The initial Starter invocation selected the enclosing evidence folder and
returned 2; it was a validation setup error. Selecting its actual site child
returned 0, with evidence in
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r2-starter-27vmi0w5.
| Preliminary check | Exit | Page facts | Built files | References | Translation statuses | Outcome |
|---|---|---|---|---|---|---|
| Correct Starter child | 0 | 66 | 223 | 4,461 | 28 | Complete; 97 source files/inventory unchanged |
| Documentation | 0 | 341 | 1,139 | 74,755 | 144 | Complete; 421 source files/inventory unchanged |
| PIG | 0 | 248 | 1,392 | 64,440 | 120 | Complete; 858 source files/inventory unchanged |
| Repository catalog | 1 | 1,572 | 3,287 | 851,535 | 788 | Completed policy check: 10,462 actual HTML_ID_DUPLICATE findings in existing merged-print output; 2,294 source files/inventory unchanged |
The repository catalog result is a completed finding outcome, not a passing site or implementation failure. No policy was weakened and no consumer source was changed. Informational review states remain visible.
The final frozen-input reports at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r2-candidate-6xzcs7fk/summary.json
exercise binary SHA-256
ff88b407a6cddb9007f94275c65a80ed4c9c4fd13f5e821f9b7a4a8973abaa56
from CLI input inventory
bd8c71b55250a89dc15c7534924bb82a5447d6f2628eba23c8cb3d864309ee9f.
All four exact source byte/mode/Git inventories were independently compared
equal before/after. These reports supersede preliminary public-command trials:
| Final check | Exit | Source files | Page facts | Built files | References | Translation statuses |
|---|---|---|---|---|---|---|
| Starter | 0 | 97 | 66 | 223 | 4,461 | 28 |
| Documentation | 0 | 421 | 341 | 1,139 | 74,825 | 144 |
| PIG | 0 | 858 | 248 | 1,392 | 64,440 | 120 |
| Repository catalog | 1 | 2,294 | 1,572 | 3,287 | 851,535 | 788 |
No final report has incomplete diagnostics. The repository catalog retains
10,462 actual merged-print HTML_ID_DUPLICATE findings and 788 informational
review states; the other sites retain informational unknown review states.
This accepts the tested checking behavior and source preservation, without
calling that catalog a passing publication.
Kept production docs at
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-site-2201601475/public
passed rendered Markdown and links. Global translation checking returned 1
only for the existing draft release 1.2.0 pair absent from production. The
separate explicitly nonpublishable draft/future/expired analysis at
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-site-3698773232/public
passed all three node checks: 137 pairs/1,092 headings, 216 content pages/41,586
text nodes, and 347 pages/48,682 internal links/4,171 fragments. Evidence logs
are /tmp/oink-r2-docs-production-{translations,markdown,links}.log and
/tmp/oink-r2-docs-analysis-{translations,markdown,links}.log. Neither analysis
output nor authored draft replaced production or was published.
A final review identified optional equal_fields comparing JSON 7.0 with
YAML/TOML numeric 7 by representation. The narrow supplement now normalizes
decoded numeric values recursively to an exact rational number tag, preserving
strings versus numbers, map keys and array order. Tests cover decimals/exponents,
negative zero, integers beyond float64 precision, nested differences, source
byte preservation and required incompletion for unrepresentable values.
Actual-Hugo translation tests passed in /tmp/oink-r2-numeric-translations-gate.log;
all public maintenance actual-Hugo cases passed in
/tmp/oink-r2-numeric-public-gate.log; owning vet and whitespace checks passed.
Supplemental source SHA-256 values are:
| Source | SHA-256 |
|---|---|
internal/translations/check.go |
24664377e14b4ae2fc554d0d7fde2ec33cc987707250e130fd88d9a25d5e1637 |
internal/translations/translations_test.go |
f58f4a305fe9fe3f5500ddfcf85faf3cfa37d72f8c220a1cb16ce4ccfbddb74d |
The frozen real-site reports and Linux qualification above/below predate this supplement. Those sites configured no numeric equality constraint, so their recorded outputs are unaffected and were not rerun for this narrow fix. Later full runtime and archive qualification must refresh the subsequent source. The evidence amendments here are authorized documentation writes after the acceptance runs; their before/after preservation scope ends before this amendment.
A18 remains open. macOS arm64 is exercised; an attempted Darwin amd64 runtime
on this host failed with arch -x86_64 / posix_spawn: Bad CPU type in executable
(/tmp/oink-r2-darwin-amd64-gate.log). This is unavailable host runtime support,
not a code failure or Darwin amd64 acceptance. No system installation was made.
Native Linux arm64 and Docker Desktop Rosetta-emulated Linux amd64 were both
actually executed with the same runtime/schema/license input SHA-256
0f786df68ef3c4844c983a51595f79242d1cb1d2bf6c5b5eb7f2c6415fb8d861.
Evidence is retained at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-a18-linux-ajbbnvki
in arm64-results, amd64-results, commands.json, candidate-inputs.json,
preparation.json and qualify.sh. Each target passed 270 test/subtest cases,
with no failures and two optional external corpus/provenance skips: full
actual-Hugo go test ./..., vet, built CLI version/bilingual init/doctor/full
check/translation status and missing-Hugo exit 2 smoke. JSON stdout and source
byte/mode inventories were verified. Go 1.27.1 ran on Linux arm64; Hugo Extended
0.166.0 architecture assets were SHA-verified. This qualifies those source
runtime paths, not final archives or hosted CI. Darwin amd64 remains open;
cross compilation does not close it. Later stages and future command/adapter/browser
acceptance remain open.
R3 local validation
R3 adds managed build --check, oink.artifact/v1 sealing/export/local
verification, explicit-network HTTP verification, release diagnosis and
guarded local CI generation. The default build/dev path remains ordinary Hugo.
The executed runtime and paired contract/guide gates passed; R3 is locally
accepted. Hosted CI and deployment were not executed.
| Requirement | Executed owning evidence | Outcome and limit |
|---|---|---|
| A08 one checked artifact | Public fake/actual Hugo one-renderer tests; exact export, manifest/marker, post-check byte/mode/missing/extra/symlink tampering, failure/concurrency and source-preservation tests | Passed local scope; a failed/incomplete check cannot seal/export; local artifact verification does not rebuild |
| A09 both CI providers | Offline deterministic generation, pinned source/Hugo archives and action revisions; safe bootstrap archives; guarded public preview/apply/stale-input cases; actual-Hugo original-input binding | Passed local configuration scope; every existing generated target is refused and custom workflows remain unchanged |
| A09 upload identity | Both local provider rehearsals and TestProviderUploadRehearsalPreservesActualSealedManifestIdentity |
Passed: one managed build, separate verification, then the same tree; GitHub tar includes the hidden marker, Cloudflare rehearsal receives that verified directory; no provider upload executed |
| A09 custom workflow diagnosis | Generated-plus-other-custom and standalone-custom/no-metadata public tests, actual-Hugo preview and owning vet | Passed supplement in /tmp/oink-r3-ci-custom-owning-gate.log and /tmp/oink-r3-ci-custom-vet-gate.log; each unrepresented workflow stays unknown, informational and optional release.ci: not_checked, including beside valid generated metadata |
| A10 deployed identity | Local HTTP fixtures for all recorded files/routes/languages, marker, canonical/base/inert-template behavior, HTTP 200 fallback, wrong bytes/language/build, missing resources/Markdown/search JSON | Passed local fixture scope; definite mismatches return 1; browser JavaScript is explicitly unchecked |
| A10 unknown network state | Explicit network/credential refusal, timeout before headers/during body, authentication/rate-limit/server errors, required marker absence, bounded body/gzip and redirect/no-cookie fixtures | Passed local fixture scope; incomplete states return 2 with remaining requests unknown; no public deployment was contacted |
| Frozen runtime gates | Full tests/vet, owning actual Hugo and focused race checks | Passed on macOS arm64 in /tmp/oink-r3-frozen-go-gate.log, /tmp/oink-r3-frozen-hugo-gate.log, /tmp/oink-r3-frozen-race-gate.log; the subsequent custom-CI change has the focused supplement above |
The latest single-binary corpus is retained at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r3-ci-final-ahc4csjk/summary.json.
It compiled an exact captured CLI input copy, with binary SHA-256
425845c1d2db7b1cd3c3cdb5f28475cb06ba6f656054909759e2359a39925dd2,
67 runtime/schema/license inputs SHA-256
6789a3a0235ff8d81453b9bfde37824979eac7d56af3710da390e4d2ef8479dc,
and 108 broader CLI inputs SHA-256
4ca473a4cb586d232baeb4cee029b281469c5bb03c831cc199b95451e6832c60.
Runtime inputs remained exactly equal after all runs. Live tools were Go
1.27.1 and Hugo Extended 0.166.0 on Darwin arm64. The manifest’s normalized
Hugo version excludes vendor build text and private paths.
Each run used offline build --check with fresh external destination/manifest
paths, the optional marker and retained isolated work. These existing local
consumer inputs were checked without --release; their configured workspaces
were preserved. Every raw report records exactly one strict Hugo renderer,
zero incomplete diagnostics and zero required unfinished coverage.
| Final managed build | Exit | Source files | Copied source inputs | Page facts | Built files | References | Exported files | Local artifact verify |
|---|---|---|---|---|---|---|---|---|
| Starter | 0 | 97 | 94 | 66 | 223 | 4,461 | 224 | 0 |
| Documentation | 0 | 421 | 427 | 341 | 1,139 | 74,825 | 1,140 | 0 |
| PIG | 0 | 858 | 861 | 248 | 1,392 | 64,440 | 1,393 | 0 |
| Repository catalog | 1 | 2,294 | 2,299 | 1,572 | 3,287 | 851,535 | None | Not exported |
Both inventories compare exact bytes, modes and file types before/after; the primary inventory also compares logical Git state. Git sites include tracked and non-ignored untracked sources; the non-Git Starter includes its existing generated files and lock. The supplemental copied-source inventory also includes ignored workspace/editor metadata read by snapshots, excluding existing generated output/cache trees. Counts alone are not the proof. All four comparisons were exactly equal.
The repository catalog retains 10,462 existing merged-print
HTML_ID_DUPLICATE findings, so neither destination nor manifest was created.
This is a complete policy finding, not a passing publication or implementation
failure. Production review states number 28/143/120/786; analysis includes
unpublished pages, explaining the earlier R2 144/788 counts. Existing custom
workflow information remains visible, and Starter’s example address is a
warning in this non-release run.
The three fresh exports match the retained independent ordinary-Hugo trees
in every original file’s SHA-256, size and mode. The sole extra file is
.well-known/oink-build.json. Their original source inventories and complete
manifest input hashes match the earlier capture, so reusing those ordinary
trees does not substitute different inputs. The helper source SHA-256 is
13e4957a3d7847eb28c8b1eeba3588a4f4a9982c2bfca2ebc729ab2827159607;
its binary SHA-256 is
b2699fe7a7aa3a34c41f9e4aba4b22d39cf8d0c156a369f3dfc4ca8c8c0fbce5.
Raw helper and ordinary evidence are in
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r3-candidate-wb643dhh;
the temporary compilation source was removed after building the helper.
Earlier R3 captures remain historical: the first capture preceded runtime
freeze; the first frozen capture at oink-r3-final-pisrr21h preceded custom-CI
diagnosis. An initial /Users/vonng/pgsty/PIG selection returned 2 because
that different repository is not the intended site; corrected
pig.pgsty.com passed. Those setup trials are retained, not relabeled as
candidate failures. This latest corpus supersedes their managed-build results.
The CI templates/bootstrap are independently authored from recorded primary
provider contracts; no provider implementation code was incorporated.
The scoped R3 documentation gate passed at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r3-docs-render-pljj5aqd/summary.json.
Ten paired contract/guide/roadmap/index/overview edits were installed only after
matching their original bytes/modes; recorded hashes are at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r3-doc-drafts-s0b3g48l/applied-files.json.
Source style passed 88 Chinese docs; translation coverage passed 137 pairs and
1,099 headings; schemas remained equal and scoped whitespace passed. Actual
production Markdown passed 214 pages/41,871 text nodes; links passed 345
pages/48,344 internal links/4,171 fragments. Production translations returned
1 only for the unchanged draft release 1.2.0 absent from production. A
separate explicitly nonpublishable draft/future/expired analysis passed Hugo
and all three owning checks: 137 pairs/1,099 headings, 216 pages/42,177 text
nodes and 347 pages/48,720 links/4,199 fragments. All 421 canonical and 488
copied source files retained exact bytes/modes throughout these rendered
checks. Analysis was not published and did not replace production. This
acceptance amendment follows that frozen preservation boundary.
This gate does not claim hosted workflow execution, uploads, publication, minimum-version combinations, browser behavior or current Linux/Darwin amd64 qualification. A18 remains open; historical Linux R2 results retain their original source hash. Authorized bilingual evidence/contract/guide writes occur after these preservation inventories and are outside their no-write scope.
R4 authoring and upgrade acceptance
The supported R4 implementation and read-only corpus scope are locally accepted after frozen owning/full gates. This record covers profiles, ordinary authoring/editor/snippets and bounded upgrade views. Guarded canonical documentation promotion and fresh scoped rendered validation also passed as recorded below; R5–R8 and final A18 qualification stay open.
| Executed profile evidence | Outcome and limit |
|---|---|
| One fixed licensed archive | Snapshot verification against commit 137843b25bacd76ddd1f7ce71330bf2e3155b954 passed without --write; archive SHA e55bde279715f6d8d19d3d88671a2cf7561b515be46915b0f12c640d0ce1d958 and MIT license unchanged; projection metadata/script match |
| Composition and preservation | Default/explicit project byte parity; selected archived model/localized home, invalid profile, nonempty target, concurrent validation/publication and cancellation recovery tests passed; unit/vet/race gates passed |
| Ordinary Hugo | All four profiles × three language choices × root/subpath passed 24 actual warning-strict offline builds using provisioned public OINK v1.1.0; complete source byte/mode/no-extra-file and rendered-reference checks passed |
| Public init workflow | Four profiles with en/en,zh, actual subsequent root/subpath Hugo URL facts/checks, workflow/license preservation and default parity passed; unknown/nonempty refusals 1, missing/failed Hugo 2, empty/absent targets and pure JSON/separate logs verified |
| Public authoring and source identity | Actual candidate/apply/ordinary Hugo, review-unknown and source preservation passed in /tmp/oink-r4-authoring-public-gate.log; fresh-directory/site guards and vet passed in /tmp/oink-r4-new-input-race.log and /tmp/oink-r4-public-core-vet.log. Actual ignored input refuses 2 without a saved plan or source writes even when source groups are disabled; selected draft peers still force analysis identity in /tmp/oink-r4-authoring-sourceproof-gate.log. Supported owning scope passed |
| Bounded upgrade owning gate | Seven actual-Hugo synthetic pinned module-fixture cases, observed-stream digest/inventory fidelity, independent cross-page alias-retarget blocking, source/concurrency/exclusive installation and later-edit rollback protection passed under race; vet passed. Final hardening logs /tmp/oink-r4-hardening-owning-gate.log, /tmp/oink-r4-hardening-final-focused.log, /tmp/oink-r4-hardening-vet.log; final public/full frozen gates passed |
| Integrated authoring/editor hardening | Actual-Hugo language-directory plan/apply/ordinary builds, link/never new-source refusal, external schema/license/full-mode/module identity and legacy schema reproof, shared translation/baseline/CI regression and full Starter docs→new draft peer→editor→check→ordinary Hugo flow passed. /tmp/oink-r4-app-authoring-hardening-gate.log (58.241s), focused race and vet passed; post-candidate external mutation proof /tmp/oink-r4-app-external-during-validation.log passed. Opaque saved external-input hashes and canonical workspace-origin guards passed /tmp/oink-r4-external-plan-binding-final.log, /tmp/oink-r4-workspace-origin-gate.log and their vet logs. Frozen full-stage, corpus and scoped canonical rendered documentation gates passed |
| Actual language mounts | Standalone ordinary per-language contentDir and explicit site-matrix fixtures each passed config/mounts/strict-render with source bytes/modes unchanged; Hugo0.166 emits sites.matrix.languages and distinct physical files with reciprocal public translations. /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r4-language-mounts-lgmve1sk/summary.json; public actual language-directory plan/apply/ordinary-Hugo integration passed |
Owning evidence is retained at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r4-starter-owning-0pv41lw5/summary.json.
Logs are /tmp/oink-r4-starter-{unit,hugo,vet,snapshot,race}-gate.log and
/tmp/oink-r4-public-init-gate.log, /tmp/oink-r4-public-init-vet-gate.log.
Generated source counts are project 94, docs 58, blog 40 and book 34. No Starter
checkout edits, release, consumer adoption or deployment occurred.
Final frozen gates all returned 0: make test/vet
/tmp/oink-r4-frozen-go-gate.log, make test-hugo
/tmp/oink-r4-frozen-hugo-gate.log and actual-Hugo core race
/tmp/oink-r4-frozen-core-race-gate.log. The final public flow includes
Starter docs → primary/translation draft → editor → check → ordinary Hugo;
post-candidate external schema mutation still refuses before source writes.
Seventeen owning and three final gate logs are retained verbatim with hashes
in the final corpus’s owning-gates.json.
The exact four-site evidence is
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r4-corpus-lw2cjyq6/summary.json
with bounded summary.compact.json, raw JSON/logs and per-command inventories.
Binary SHA is c169b3d4d046c811dca80867068b86fb66ada5c8ce6910dd5cda7353c406f377;
82 runtime-input files bind SHA
fdff7f50d49b44f03fa1db79eec6b6c9b9bd5e52f8967a88aed84b3207a7b3c6,
which equals the final root inventory with no runtime changes. The broader
139 CLI inputs bind SHA
562e838d9eccb628eac86ae59b9b9587c1e23ad52991ec50eafb1e604e3924da.
Driver SHA is d3ac41dc2e18295bfb26134d1a696935c8174913e2801a5766dbf7a1139d89f8.
Actual tools were Go 1.27.1 and Hugo 0.166.0 Extended on macOS arm64.
| Frozen consumer | Primary/copied source files | Pages; output files; references | Managed build / artifact verify | Read-only upgrade / new / editor |
|---|---|---|---|---|
| Starter | 97 / 94 | 66; 223; 4,461 | 0 / 0; 224 exported files including marker |
0 / 0 / 0 |
| Documentation | 421 / 427 | 341; 1,139; 74,937 | 0 / 0; 1,140 exported files including marker |
0 / 0 / 0 |
| PIG | 858 / 861 | 248; 1,392; 64,440 | 0 / 0; 1,393 exported files including marker |
0 / 0 / 0 |
| Repository | 2,294 / 2,299 | 1,572; 3,287; 851,535 | Completed finding 1; no export/manifest |
Completed finding 1; new/editor not attempted after blockers |
Each managed build used exactly one strict production Hugo render and had no
required incompletion or uncompleted required coverage. Primary Git-visible
source bytes/full modes/logical Git state, supplemental copied inputs and
source directory modes matched exactly before/after every command and each
complete site flow. Repo’s 10,462 existing merged_print duplicate HTML IDs
remain visible; its completed finding is neither a passing artifact nor an
implementation failure. No policy or consumer inputs were adjusted.
Consumer upgrade previews selected the available public v1.1.0 pin and did not apply writes. Cross-version route/alias/output regressions use explicit synthetic fixture pins, not an invented published theme release. New/editor plans were validated previews; no consumer plan was saved or applied. Multi-host and unknown relative-alias identities stay incomplete. Nondeterministic output may require a fresh v2 plan preview; browser/universal compatibility, configuration migration and current cross-platform/archive qualification remain outside this scoped result. The prior Linux R2 source hash remains historical; Darwin amd64 and final A18 refresh are still unverified. Authorized bilingual canonical writes occur only after this frozen no-write evidence boundary.
Fresh canonical documentation acceptance passed after the parent applied the
ten guarded files. Evidence is
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r4-docs-render-v01eima0/summary.json;
the promotion manifest is
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r4-doc-drafts-3i8bw994/applied-files.json.
The frozen c169b3… CLI performed one strict production render and its focused
link check returned 0.
| Fresh canonical documentation gate | Executed result |
|---|---|
| Source owners | Translations 0: 137/137 pairs and 1,104 headings; complete canonical style 0: 137 Chinese files, 181 strong spans, no emphasis; ten-file whitespace check and public JSON schema equality passed |
| Production rendered Markdown/links | Both 0: 214 content pages / 42,214 text nodes; 345 pages / 48,360 internal links / 4,187 fragments |
| Production translations | 1 solely for the pre-existing draft content/blog/release/1.2.0.md absent from production; no new pairing/heading finding |
| Separate nonpublishable analysis | Fresh ordinary Hugo with the actual original snapshot environment/rebased paths and explicit draft/future/expired flags returned 0; all three owners 0: Markdown 216 pages / 42,520 nodes, links 347 pages / 48,736 links / 4,215 fragments, translations 137/137 pairs / 1,104 headings |
| Source preservation | Canonical 421 Git-inventoried files and 427 copied inputs retained exact bytes, modes, Git state and directory modes; production copied 428 and analysis copied 427 files remained unchanged through their checks; analysis build also retained copied full modes |
Production output remained separate and was never replaced by the analysis
tree; the analysis is not publishable. The temporary helper copied the frozen
core without modifying it: helper source SHA
7faea7e726a6c6fb2e0747be1a4428f4c5fb5734fa52b6f981157a5fe37d9989
and helper binary SHA
532638e76f96f8b173c122e512b3bf5fc2c4d4a7130f59c99c2c69e135e87073
are retained with raw logs. This authorized bilingual research amendment
occurs after the exact no-write capture boundary and receives narrow source
checks separately. R4’s scoped local documentation gate is accepted; this
result does not claim publication, deployment, R5–R8 completion or final A18
qualification.
R5 implementation and documentation acceptance
R5’s supported local scope is accepted after focused public/core, corrected frozen full-stage, exact-binary read-only consumer and guarded canonical source/rendered documentation gates. The bounded outcomes remain explicit below. R6–R8, workspace A15 and final A18 qualification stay open. The first promotion and separately authorized post-render status/evidence amendment retain distinct preservation boundaries.
The actual public Git/Hugo flow at /tmp/oink-r5-public-final-flow.log passed
in 53.963 seconds. Its committed synthetic site owns its local theme, bilingual
pages and binary attachment; ordinary modes 0640 and 0600 remain full
current facts while historic Git comparison uses executable bits only.
Deleting B selects unchanged inbound A, the remaining translation, removed
attachment and actual RSS output. Actual alias-inbound uncertainty, global
configuration/template/data and unknown-input changes expand full scope.
Completed inspect/impact/context returns 0 with separate current-check
findings 1; check-since retains current quality 1 and full validation scope.
Missing/unborn/foreign history returns 2, retaining every known current
page/attachment/reference/output with no fabricated prior identity or change.
Malformed selectors/limits, missing tools and failed renderer logs are tested.
Bounded context gives reasons/versions/source and excerpt hashes, visible
omission/truncation and no execution of literal document instructions.
Saved move preview/apply and subsequent ordinary Hugo passed, retaining
binary bytes, raw full modes, unrelated files and Git index/revision. Actual
opaque HTML/shortcode references remain manual; inline/fenced/opaque spans
stay unchanged. Their broken final candidate returns 1, with no saved plan
or source writes. Source/config/attachment/mode/fresh-target drift returns 2
and preserves the later edit. A deterministic mutation after the actual
candidate renderer also refuses before writes and preserves editor bytes/mode.
Focused actual move race passed in 8.286 seconds at
/tmp/oink-r5-public-move-race.log; app vet passed at
/tmp/oink-r5-public-vet.log.
Before the cached-module supplement, frozen parent make test/vet and
make test-hugo both passed at
/tmp/oink-r5-frozen-go-gate.log and /tmp/oink-r5-frozen-hugo-gate.log
(actual app fixtures 185.709 seconds). Actual move/source race and vet passed
/tmp/oink-r5-move-hugo-gate.log, /tmp/oink-r5-source-move-race-gate.log
and its vet counterpart; full inventory/mode/selector plan safety passed
/tmp/oink-r5-plan-owning-final.log.
A first frozen consumer trial exposed an actual cached-public-module guard
gap: resolved module inputs present in the original graph were absent from a
fresh outer candidate hash. It returned false incomplete 2, without source
writes. Content plans now resolve/capture the same module inputs before
comparison, retaining legacy metadata/authoring plan scopes. The separate
checksum-verified public OINK v1.1.0 regression passed preview, fresh saved
apply and ordinary bilingual Hugo in 27.42 seconds (package 28.220) at
/tmp/oink-r5-public-cached-module-move.log, including raw modes, binary bytes,
unrelated inputs and Git preservation. Corrected current-binary corpus and
supplemental race evidence remain separate from the earlier unaccepted trial.
The corrected current candidate passed full make test/vet at
/tmp/oink-r5-corrected-frozen-go-gate.log and actual make test-hugo at
/tmp/oink-r5-corrected-frozen-hugo-gate.log (app 278.787 seconds). The
cached/public and committed/in-site move safety race passed in 38.578 seconds
at /tmp/oink-r5-public-cached-seam-race.log; its app vet also passed.
/tmp/oink-r5-corrected-runtime-freeze.json records 96 runtime inputs with
SHA-256 e5b6e0eda972116dbb94a8086668e6ef34bfaa56138cf31f1f71f4832c477842
and 165 broader CLI inputs with SHA-256
4965a0c92cb6126f67a6dabd548c7c25ee5d7c9c57e14cce5e55ebb7a22fca2d.
The corrected binary SHA-256 is
d7675aecca2f77b1eb37bb4f664c3314cf5207149e6abbb86523686c5c50bff0.
These are local working-input/executable identities, not a new commit or
published archive. The corrected four-consumer capture completed 16 commands
in 831.825 seconds at
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r5-corpus-corrected-y2eue81h.
Its bounded final-receipt.json has SHA-256
b86e0e6c7dbfbaed62c845c03a55d963068f7d9a16771de5ff3b0974e76fce3b;
the receipt retains 12 copied owning gate logs, all 20 observed move routes
and links to the complete raw JSON/logs and per-move classifications.
| Site | Primary/copied inputs/directories | Inspect/context | Current check | Impact | Move preview |
|---|---|---|---|---|---|
| Starter | 97/94/21 | 0/0 |
0 |
2: no Git baseline |
0: validated, unapplied |
| Documentation | 421/427/109 | 0/0 |
0 |
0: complete historical comparison |
1: six candidate missing references |
| PIG | 858/861/52 | 0/0 |
0 |
2: historical foreign-input provenance incomplete |
1: 32 candidate missing references |
| Repository | 2294/2299/48 | 0/0 |
1: 10,462 existing duplicate HTML IDs |
2: unborn HEAD baseline unavailable |
1: the same existing duplicate IDs |
Starter and Repository impact retain known current facts without inventing
prior pages or changes. PIG’s actual baseline is complete (theme v1.0.0 versus
current v1.1.0), but required foreign-input provenance is incomplete, so the
comparison expands full scope and returns 2. These are distinct outcomes.
Documentation impact completes with 192 captured input changes, 343 affected
prior/current pages and full scope. All completed fact queries expose current
quality findings separately; Repository inspect/context remain 0.
Documentation move proves 18 rewrites and four routes. Two ordinary literal
/docs/admin/comments/ occurrences in content/docs/customize/repository.md
at lines 216 and 313 remain manual because repeated source/output occurrences
cannot be attributed precisely across ordinary and print outputs. Their six
missing candidate references block validation. PIG moves two Markdown files
and four binary attachments, with eight proven page/processed-resource routes.
Equal-byte paired outputs prove processed featured_hu_* resources, but not
new URLs for the four original absolute image references
/article/pgext-day/{featured,topic,venue,schedule}.webp. Their 32 candidate
missing references block validation; no guessed original-asset rewrites occur.
These ordinary Markdown limits are separate from opaque HTML/shortcode limits.
Repository move proves ten rewrites and four routes; its candidate has only
the same 10,462 existing duplicate-ID findings, with no new missing reference
or required incomplete finding. Starter’s zero-link bilingual move is
validated. All four moves remain unapplied, no consumer plans were saved and
no consumer source writes occurred. Failed candidates have validated: false.
All JSON stdout is pure. Primary/copied inputs, full modes, directory
inventories and logical Git/index state are unchanged; ignored copied inputs
are included. The Git metadata inventory excludes immutable object storage.
The runtime and broader CLI inventories still match the captured identities.
The receipt does not qualify another platform, browser runtime or deployment.
The first ten-file guarded canonical promotion was qualified in 62.37
seconds with the corrected frozen binary and runtime hashes above. The
separate rendered receipt is
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r5-docs-render-ks2tw82c/summary.json,
SHA-256 06ae844a4b3f1c01bb5faa8a21091d5461c28aab592d12c4310fb34bc176c5d4.
| Canonical documentation gate | Executed result |
|---|---|
| Source owners | Translation 0: 137/137 pairs, 1,109 headings; style 0: 137 Chinese files, 181 strong spans, no emphasis; scoped whitespace and public JSON schema equality passed |
| Frozen CLI | Production check links returned 0 using the exact corrected binary |
| Fresh ordinary production Hugo | Build 0; Markdown 0: 214 pages/42,571 nodes; links 0: 345 pages/48,376 links/4,203 fragments |
| Production translation owner | 1 only for the pre-existing draft release-1.2 omission from ordinary production output; no new R5 discrepancy |
| Separate ordinary analysis Hugo | Fresh nonpublishable -DFE build 0, without the CLI probe; Markdown 0: 216 pages/42,877 nodes; links 0: 347 pages/48,752 links/4,231 fragments; translations 0: 137 pairs/1,109 headings |
| Input preservation | All per-command and overall guards passed: 421 primary files, 427 copied inputs, 109 directories and 36 mutable Git files retained bytes/full modes/logical Git state; both isolated source copies remained unchanged |
The analysis tree did not replace production output and is not publishable.
The permanent first-promotion applied-files.json in
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r5-doc-drafts-t3_klnck
retains the ten authorized files and their original modes. This separately
authorized post-render amendment touches only six paired proposal/index/research
files, after the recorded no-write boundary; the qualified contract and guide
bytes remain frozen. Its guarded originals, prepared diff and focused source
checks are retained separately. It does not retroactively claim these later
evidence bytes were in the earlier rendered capture, and no full corpus or
rendered rerun is inferred from the amendment.
Core owning logs /tmp/oink-r5-frozen-core-hugo.log,
/tmp/oink-r5-owning-race.log and /tmp/oink-r5-owning-vet.log passed.
A13 impact and A14 move safety passed their required supported CLI scope;
A15 bounded context passed, while workspace/direct parity remains R6 scope.
No consumer source write, commit, publication, network deployment, remote
model integration or incremental speed claim is made.
R6 workspace and adapter acceptance evidence
R6 supported scope is accepted locally after frozen owning/runtime, exact-binary consumer parity/preservation and guarded canonical source/render gates. The supported registry/tool fields belong in the contract and guide. R1–R6 are accepted locally; historical receipts remain intact. A07 adapter and A15 workspace/direct/context supported scope passed the gates below; R7/R8 and final A18 remain open.
The registry is independently versioned oink.workspace/v1: strict one-document
regular YAML, 1–64 entries, at most 256 KiB, exact ASCII names, literal
relative/absolute directories, proven canonical identities and overlap
refusal. Missing-site results stay per-site incomplete while later selected
sites run. Selection preserves registry order; no default named site,
sibling discovery, Hugo settings duplication or automatic multi-site apply is
provided. Optional tools extend oink.policy/v1, with pinned protocol versions,
configuration/full-mode provenance and typed omissions/coverage.
Workspace owning receipts
| Focused gate | Executed local evidence |
|---|---|
| Registry core | Strict fields/document/bounds/names/literal paths, existing aliases/case-inode ancestry, duplicate/overlap refusal, missing-directory listing and exact subset order; go test -race ./internal/workspace -count=1 passed in 1.414 seconds, /tmp/oink-r6-workspace-core-race.log |
| Public actual Hugo | OINK_TEST_HUGO=1 go test ./internal/app -run '^TestPublicR6Workspace' -count=1 -v passed in 10.498 seconds, /tmp/oink-r6-workspace-public-hugo.log |
| Public race | The same workspace public suite with -race passed in 12.426 seconds, /tmp/oink-r6-workspace-public-race.log; excluded commands specifically reject registry selection |
| Vet | go vet ./internal/workspace ./internal/app completed with exit 0, /tmp/oink-r6-workspace-vet.log |
| Public outcomes | Actual bilingual committed fixture sites retain direct diagnostics/coverage/exit parity for links and full checks. A missing first site yields 2 while later clean/finding sites yield 0/1; explicit subsets preserve registry order, invalid unregistered siblings remain untouched and human output retains findings |
| Selected application | Saved translation-review preview is validated but unapplied; a different registered name is refused before writes and preserves plan/source bytes/full modes/Git. Explicit matching-name apply writes only its planned review file; other registered and unregistered sites remain unchanged |
These are owning fixture outcomes, not consumer adoption or permission to apply
plans to actual consumers. The inspected core workspace.go SHA-256 is
cf2cbc9509e8c83eedf6d8833c9eb0ea6492de9a85c959798112fa3f105213f4;
its owning test is
9070a8e2c3e58680f6567f2394160ec682bf0457c068c2addf354921e7612d6b;
the public test is
3e57a6417ae2e7604f7cb06933759bb06a2f40758ff7059848593cedbaa6570a.
All three inspected files retain mode 0600. These owning source captures are
covered by the frozen all-runtime inventory below; their individual hashes do
not identify the exercised binary.
Corrected protocols and stage gates
| Protocol or gate | Recorded status |
|---|---|
Actual markdownlint-cli 0.49.1 and Vale 3.24.0 |
Corrected public trial passed: exactly one finding mapped to the original UTF-8/BOM/CRLF line; excluded front matter/shortcode/math/raw HTML/enabled attributes/code produced no false original attribution |
Actual lychee 0.24.2 |
Corrected trial actually reached the local HTTP fixture: 200 → 0, 404 → 1, 401/403/429/503/timeout → required 2. Optional offline → 0, required offline → 2, both with zero HTTP requests |
| Final focused actual-tool receipt | /tmp/oink-r6-public-actual-tools-final.log passed in 15.192 seconds; the earlier corrected 14.686-second run is retained as prior evidence. Node preload and discovered JS configuration did not execute; source full modes/Git were preserved |
| Fake/protocol failure receipt | /tmp/oink-r6-public-fake-tools-final.log passed in 13.089 seconds: malformed output, version mismatch, timeout, unsafe configs, required missing/optional/group omissions and raw stderr normalization |
| Focused public race/vet | /tmp/oink-r6-public-tools-race.log passed in 30.273 seconds across fake and actual cases; /tmp/oink-r6-public-tools-vet.log completed with exit 0 |
| Frozen runtime inputs | Parent freeze at 2026-10-03T10:58:01.807947Z, /tmp/oink-r6-runtime-freeze.json: 103 runtime inputs bind b85affd96378b45bfc56a996b0c5672d02ee4c6cc9bc95335fa5072f6c42a03b; 179 broader CLI inputs bind fbb8176ebc58f1aa26336f4e6036cf9bd5f7a0d62b142f16532b50a8071e9fbe. The exercised 0.3.0-r6-local binary SHA-256 is aa8b347fbe01071f9da729f4d98aa2f50d7264456be6c5f05771bcfadadc371f |
| Frozen owning suites | Full Go/vet completed with exit 0, /tmp/oink-r6-frozen-go-gate.log; full actual Hugo plus pinned tools completed with exit 0, /tmp/oink-r6-frozen-hugo-gate.log (app 382.832 seconds). Workspace/core/protocol/source-mask/policy/report race and vet receipts passed and are copied into the final receipt |
| Four consumer sites | Qualified: exact-binary direct/aggregate diagnostics, coverage, exit, identity and registry-order parity for all four sites; per-command/overall source byte/full-mode/type/logical and mutable Git/ignored-input/directory guards passed. Aggregate completed 4, finding 1, incomplete 0, exit 1 |
| Canonical EN/ZH | Passed: guarded first ten-file promotion, source owners and fresh ordinary production/nonpublishable rendered evidence; only the known production draft-release omission remains |
| Stage decision | Supported R6/A07/A15 scope accepted locally after the required receipts; R7/R8/final A18 open; no public release, consumer source write, adoption or deployment |
The durable focused-tool receipt is
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r6-tools-6bf67ltv/r6-public-tools-acceptance.json,
SHA-256 16b6e47fc0618c76d2f9e3680a4112b6e47b478af8aabd3f2fc84821f840cc8a.
It binds the provision record, executable/configuration evidence and 1,422
resolved Node package files. Markdownlint reports original content/tools.md
line 7, bytes[80:92] (ppears here.); Vale reports the same line,
bytes[71:78] (BADTERM). Each of the seven network cases actually makes
one HTTP request. These records do not certify every transitive interpreter,
another runtime target or the full consumer corpus.
The exact-binary consumer receipt is
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r6-corpus-59_asiyr/final-receipt.json,
42,212 bytes, SHA-256
0ad86afaf235bdcff0c474e76b08e0591591a7b22c7992b02e20fb17975d029e;
the completed summary binds
467b66eb6d178829508115050d4243909313acf1b4d59317ecda37ab7383ca55.
It retains 14 copied owning/completion gate logs. The six original operations
sum to 314.912887 seconds, excluding candidate compilation and receipt-only
correction. workspace list returns 0; four direct full checks return
0/0/0/1; the aggregate returns 1 with all four sites completed.
| Site | Preserved source files | Direct/aggregate child exit | Diagnostics/coverage | Recorded finding boundary |
|---|---|---|---|---|
| Starter | 97 | 0/0 |
28/29 | Translation review information only |
| Documentation | 421 | 0/0 |
144/34 | Translation review information only |
| PIG | 858 | 0/0 |
120/41 | Translation review information only |
| Repository | 2,294 | 1/1 |
11,250/29 | Existing 10,462 duplicate-ID findings and 788 translation review information items |
Direct and aggregate child identities, order, every diagnostic and coverage record match. All four consumer sources retain full modes/types, logical and mutable Git metadata, ignored copied inputs and directory inventories after every operation and overall; the complete root CLI inventory also still equals its frozen capture. The 478,603,149-byte direct repository JSON and 635,470,795-byte aggregate JSON were validated streamingly rather than truncated. Optional-tool protocols are qualified by their separate pinned-tool fixtures; the consumer registry is task-local and writes no consumer policy.
The initial acceptance driver overwrote a summarized result’s command string
with invocation argv, producing a false parity exception after all six CLI
operations and their per-operation guards had completed. The failed driver and
summary remain preserved as pre-correction.r6_qualify.py and
pre-correction.summary.json. Receipt completion corrected only invocation
metadata, verified unchanged raw-result SHA-256 values and header commands,
retained all original full-stream diagnostic/coverage digests, and rechecked
overall consumer/root guards. No CLI runtime correction or Hugo/CLI rerun was
needed. The receipt-only completion took 2.002 seconds and exited 0 in
/tmp/oink-r6-corpus-receipt-completion.log.
The executed driver SHA-256 is
4d2a360c6f7f6f96c38698bd189bc4d4b2cb02a7509858920d752897fdd85988;
the corrected driver is
4870f5c0374fcc11ad1a6b2e3aefe36f493b6f9f4666c293993dc6a59df8a11b;
the receipt-completion driver is
cd50d3fe704370f73fa4e7d94ce8e4bc925d11ec8ef04d463aacec37c2053daf.
The streaming helper binds
144f778cdb7907372797b47b97f817f340e70423701a2a958dee589281a9a11c,
and the inventory helper binds
d3ac41dc2e18295bfb26134d1a696935c8174913e2801a5766dbf7a1139d89f8.
This receipt qualifies local darwin/arm64 with Go 1.27.1, Hugo Extended
0.166.0, Node 26.9.0 and Apple Git 2.54.0. It does not refresh final A18,
qualify Darwin amd64 or another platform, apply a consumer plan, publish or
deploy. At corpus capture, canonical promotion and actual rendered EN/ZH owning gates
were separate pending work. The later receipt below closes that boundary; the
first-promotion bytes do not claim this post-render amendment retrospectively.
The initial actual-tool trial was preparation evidence, not a passed
qualification. It exposed Darwin /var versus /private/var staging identity,
actual loopback proxy routing, and an invalid inline-block-attribute/line
assertion in the Vale fixture. Staging is now canonical; the Vale fixture uses
a real standalone block attribute without changing the source-mask boundary.
The qualified child environment forwards literal NO_PROXY/no_proxy host-list
data while omitting proxy URLs/credentials and Node preload settings. Neither
an empty proxy environment nor NO_PROXY=* established the tested Darwin
loopback path; no universal operating-system proxy bypass is claimed.
Supported source diagnostics require proven original ranges; rendered lychee locations remain output file/DOM pointers, with no inferred Markdown line. Offline lychee is not invoked. Authentication/rate-limit/server/transport uncertainty cannot become required success through severity, exclusions or baseline acknowledgement. External fragments, browser execution and remote content identity are not proven. The declarations, output envelope and required-incomplete precedence remain independent from final platform/archive qualification; Darwin amd64 and final A18 are still open.
The first guarded ten-file promotion and its fresh rendered qualification are
now complete. The receipt is
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r6-docs-render-dcwtcmyl/summary.json,
555,297 bytes, SHA-256
ee153932900dc6f1ec62beef1a75927fc60b857efccfbcc558bf0e2c2b12cc04.
The 64.17-second run used the exact qualified aa8b347f…371f binary and unchanged
103-input b85affd9…a03b runtime inventory recorded above.
| First-promotion documentation owner | Actual result |
|---|---|
| CLI production links | 0; one strict production Hugo renderer, no analysis build |
| Ordinary production Hugo / Markdown / links | 0 / 0 / 0; 214 content pages and 43,376 text nodes; 345 HTML pages, 48,438 internal references and 4,259 fragments |
| Ordinary production translations | 1 only for the existing draft content/blog/release/1.2.0.md absent from production; not a new R6 failure |
| Independent ordinary nonpublishable Hugo / Markdown / links / translations | All 0; 216 content pages and 43,682 text nodes; 347 HTML pages, 48,814 internal references and 4,287 fragments; 137/137 pairs and 1,118 headings |
| Source owners / schema | Translation, style and whitespace all 0; 137/137 pairs, 1,118 headings; 137 Chinese files, 181 strong marks, zero emphasis marks; CLI/documented result schema both bind 7468c2d04cde8a368ce0ba44a1f27125b5fca364b6d4672353519b9545b3bdda |
| Preservation | All 12 owner commands, CLI/schema checks and overall comparison preserve 421 primary files, 427 copied inputs, 109 directories and 36 mutable Git files with full modes/types/bytes and logical Git; both private ordinary source copies and all 103 runtime inputs unchanged |
The first-promotion installer receipt,
oink-r6-doc-drafts-ymjop499/applied-files.json, binds
13c965592d64056d8365aed1927d2d422fadec8adc54ee7050b22e2ea0ad6270.
It retains captured actual original inodes in private temporary storage,
preserving later old-open-handle writes; recovery also preserves later target
edits or deletion. The subsequent paired status/evidence amendment has its own
full-byte/full-mode guards and source-owner receipt. It updates current notes,
command status and this ledger, preserving earlier receipts and configuration
examples. Its new bytes were not inputs to the 64.17-second rendered run, and
that run is not claimed as their rerender. Supported R6/A07/A15 is accepted
locally after these gates; R7/R8 and final A18 remain open. No duplicate corpus,
public release, consumer plan application/adoption or deployment is claimed.
R7 read-only Studio candidate evidence
R7 implements the embedded five-view browser and authenticated loopback API candidate described in the contract and guide. R1–R6 historical sections and their exact receipts remain unchanged. Frozen core/browser and exact-binary four-consumer qualification and guarded canonical rendered gates passed within the declared scope. R7/A16 supported read-only scope is accepted locally; R1–R7 are accepted. R8 editing and final A18 remain open.
Focused native and browser evidence
| Owning boundary | Evidence status |
|---|---|
| Native/public parity | Actual shared check reports preserve diagnostic/coverage/exit identity for 0/1/2; explicit selected workspace startup, cleanup/signal and no-source-write proofs are recorded separately by the owning test receipts |
| HTTP management/source/preview | Literal-loopback selection; exact Host/origin/Bearer checks; no arbitrary request paths/writes; captured source/diff bounds and source-mode/output inventory guards; focused core/new browser and current corpus receipts below bind this supported scope |
| Initial held browser | 14 axe checks with zero violations and 14 screenshots; five desktop light views, captured BOM/CRLF source/diff, desktop dark, mobile dark and all five 320-pixel light views plus capture changes. Synthetic actual-Hugo fixture retains 228 native diagnostics and coverage parity; copied suggestions use a private test clipboard, leaving the host clipboard unchanged |
| Browser preview attack | Actual attack script executes in the isolated preview, but parent access, management fetch and popup are blocked; token query refused. Actual draft-only page remains production 404. This proves the tested browser/CSP scope, not an OS network sandbox |
| Snapshot preservation | Captured source instructions/HTML stay literal data; the initial capture retains its old bytes before refresh after an explicit task-fixture external edit. Source full modes/Git/directories preserved except that declared fixture edit; changes show the actual modified captured input |
| Preceding held browser | Passed refreshed held UI/backend receipt: all 14 axe checks zero violations and 14 screenshots, including declared/captured theme rows. This predates the partial-preview runtime correction and does not qualify that new runtime |
| New partial-preview browser | Passed new frozen partial-preview runtime: 14 axe checks with zero violations and 14 screenshots; actual Hugo normal HTML 200 and 67,108,865-byte output 413; native 1/228 diagnostics and coverage retained, required partial coverage visible and Studio/refresh 2 |
Initial browser receipt:
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-studio-browser-AfwaYi/summary.json,
SHA-256 930fbd1ab86806069b963bff2e3e95aaa07e3634400cec65e2b8c7922e2a1707.
Its exact binary binds
92e5b962e40fbe828a0b006f3ae76a2bddf4ad7e8b1c5b6967e365b8f1827879;
the subsequent declared/captured theme metadata row is not claimed tested by
that preceding binary. The qualified local versions are Node 26.9.0,
Playwright 1.62.1, @axe-core/playwright 4.13.0 and Chromium 151.0.7922.34.
These are explicitly prepared contributor dependencies, not consumer runtime
requirements or automatic installations. Clipboard evidence covers the actual
UI click with a private clipboard implementation, not the whole host clipboard.
The refreshed held UI/backend browser receipt is
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-studio-browser-vn0ofb/summary.json,
SHA-256 520603779f712539865c6e9ef7a9ad3ad21ec1906adfb067ec607cc69d071b7e,
with exact binary 73bf90c69dce84849ee20ddfbfe825b9f2dd46f0cd37a228ce1b041a83afa33f.
All 14 axe runs and 14 screenshots passed, including declared/captured
theme metadata and all five views at 320 pixels. It retains the same bounded
synthetic-fixture/source/preview/clipboard claims above for that preceding
runtime. It does not qualify the later partial-preview correction; new browser,
full-stage, consumer and rendered-documentation qualification remains separate.
The initial parallel whole-suite trials in
/tmp/oink-r7-frozen-go-gate.log and
/tmp/oink-r7-frozen-hugo-gate.log failed and are not qualification receipts.
The failures were existing ten-second CI-test deadlines under parallel package
load and a graph test observer refreshing its own Git index. The isolated CI
target sets then passed in 12.149 and 2.291 seconds; the controlled Git-observer
graph run passed in 1.354 seconds. Only
internal/projectgraph/hugo_test.go changed: its read-only observer disables
Git optional locks, filesystem monitoring and the untracked cache. The ordinary
actual-Hugo graph run passed in 1.562 seconds after that test-only correction.
No runtime or embedded UI bytes changed.
The corrected freeze is recorded in
/tmp/oink-r7-corrected-runtime-freeze.json: the 113 runtime inputs retain
15a7de85a1ae9e6a73d8ea6570aa4f97bdd0ad5677ad7ca996fdd081ad43f7b5;
the 193 broader inputs now bind
67c6d36cf91d175f208f79cdd4d337aab6d2ef71e43453b20394b677678725e8,
with only the test-observer file changed from the preceding
85ad60d24c93e899020fbdcd34f8252c578253ce5afaf8652e561a432ecc8067
freeze. Corrected serial Go tests and vet passed in
/tmp/oink-r7-corrected-go-gate.log. The corrected serial actual-Hugo/pinned-tool
suite also passed in /tmp/oink-r7-corrected-hugo-gate.log, SHA-256
2aed822ff6fc8be04919aa74ca6ada721789232c14c1d77f1d44113bc0d235a7;
the application package took 220.782 seconds. The independent post-Go
source-preservation audit is
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r7-postgo-audit-qygh7bcc/receipt.json,
SHA-256 5ee45fe041536243bc1229054516835c61b27909a4f296ac226b1a138e4bc8dc.
It verifies the full physical/logical input guards, not Hugo or consumer results.
The durable corrected owning-gate receipt is
/tmp/oink-r7-corrected-owning-gates.json, SHA-256
c7f94a740e33a7349886b3f3689419719f857f39031375e80ca384a3dac36e67.
It binds both successful serial runs to the corrected freeze and preserves the
failed trials as unqualified. The prepared documentation renderer now requires
the completed consumer receipt to prove a private captured-source rebuild
byte-identical to the final browser binary. Its source-only independent audit,
oink-r7-docdriver-audit-ig_r8ud1/receipt.json, binds SHA-256
858cc48bf602fbdb26fcbda03c78ca485338b1295d64257d32cfb14b24f1ade3
and prepared driver
f25d9ac4bf1a7ef43d5526b7b3cbadf84dd64ad8a57fd82d1c82e76fdb2b3435.
That audit did not execute or qualify canonical rendering.
The first consumer driver trial, oink-r7-corpus-h1lOFl, stopped with
KeyError('preview_base_path'): it indexed a field legitimately omitted when
the actual preview base path is empty. Its private rebuild was byte-identical
to the final browser binary
73bf90c69dce84849ee20ddfbfe825b9f2dd46f0cd37a228ce1b041a83afa33f,
and all four consumer source inventories and the root inventory were preserved.
That failed driver run does not qualify the four-consumer gate. The fresh
oink-r7-corpus-corrected-cByXTa driver changes only those two accesses to
get(..., ''), with SHA-256
4c409acacbb9b82e658e6705eddefd9a3541def5c63c340b65678a6c9a8354e4.
That fresh run subsequently failed when the repository produced an inventoried
file larger than 64 MiB: the preceding runtime refused all production preview.
Its native check retained outcome 1, while required unavailable preview made
Studio outcome 2. Starter, docs and PIG completed that run with outcome 0;
all four source inventories and the root inventory stayed preserved. The failed
cByXTa trial is retained and does not qualify the four-consumer gate. Neither
empty-base-path driver correction changed runtime or consumer sources.
The parent then authorized a narrow runtime/test correction for partial
preview. It keeps the 64 MiB limit, exposes guarded production files within the
limit, returns 413 for the exact skipped oversized paths and keeps required
studio.preview coverage incomplete. Native check outcome remains unchanged;
Studio still returns 2 for required incomplete preview. The embedded UI is
held unchanged. All preceding browser/owning/binary/corpus receipts describe
their earlier runtime boundaries, not this new runtime. The new owning/browser
gates are recorded separately below rather than inferred from those earlier
receipts; exact-binary four-consumer qualification remains separate.
The old failed capture proved that an output exceeded 64 MiB but did not expose
its captured path/size; ignored repository output is not evidence for that
capture’s identity. The new bounded coverage detail will record actual omitted
relative paths, sizes and count. A prepared real-Hugo browser fixture adds
static/oversized.bin at 64 MiB plus one byte to exercise an available guarded
HTML preview, an exact skipped-file 413, native outcome 1 and required
partial-view outcome 2. That fixture preparation alone was not browser
qualification; the subsequent completed browser proof is recorded below.
The new partial-preview freeze is
/tmp/oink-r7-partial-preview-runtime-freeze.json, SHA-256
c426ce3e641ed7b39bb711a26006306cab22e761c5062f2164f10deb4bea8765.
Its 113 runtime inputs bind
4900ae05abbdf4409b0be54f276fb4135269cf0a49e9071013ccf42544d35c84;
193 broader inputs bind
8b172cef2b228e2642f0139d6cc569136e86843f818e52e412fa4a2d56add25d.
Only internal/studio/preview.go changed among runtime inputs; the broader
changes also include its test and scripts/test-studio.mjs. All three UI files
retain their exact bytes and modes. Focused core final race passed in 1.748
seconds, with vet and scoped whitespace checks also passing. Its receipt,
oink-r7-partial-preview-owning-a56dunn4/receipt.json, binds SHA-256
7b6ecb491f283d04fe54347e564dba426b1a84d152040a1d945af54bc67756ac.
The initial sparse-fixture mode trial is excluded: host umask 0077 made a
requested 0640 file actually 0600; explicit fixture chmod to 0640 corrected
that setup without changing production behavior. Focused proof covers normal
200, oversized GET/HEAD 413, changed identity 409, private path 404
and refusal for other unknown output errors. It does not substitute for the
subsequent independent broader browser/owning/corpus/render gates.
Whole serial Go tests for the new partial-preview freeze then passed in 61.481
seconds, and vet passed in 0.571 seconds. Completed logs are
/tmp/oink-r7-partial-preview-go-gate.log, SHA-256
be7d6eccf99a6f4c1b8f09d1fb782455c7cbd3bad4a2f37e2f0e9da916bcb313,
and /tmp/oink-r7-partial-preview-vet-gate.log, the empty SHA-256
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855.
The independent held-input audit
oink-r7-partial-held-audit-o6p98i1l/receipt.json, SHA-256
e567efc5f580db9395afab8ad36c4db842c3db95db442eb1cb1c740dbd43ec31,
verified all 113/193 inputs and physical/logical identities during that parent
Go/vet run. It is not a post-suite or browser/corpus/render completion claim.
The new whole actual-Hugo/pinned-tool invocation subsequently completed with
exit 1 after 285.649 seconds. Its sole failure was the parent’s unavailable
Markdownlint preparation path /md/node_modules; all other actual cases passed.
The log remains a failed invocation:
/tmp/oink-r7-partial-preview-hugo-gate.log, SHA-256
1ab6b8cfd399d484e08a1d1f05d25475754caa731991dd1eec1cca03cf6ce970.
The sole owning case was rerun with the exact provisioned
/markdownlint/node_modules executable, with no source/runtime change, and
passed: application package 2.317 seconds, wall 3.265 seconds. Its receipt is
/tmp/oink-r7-partial-preview-corrected-tools-gate.json, SHA-256
62b75e563e8074995ed9dd354434e653b2f5f2c6d20767226286d0c08d4c667c;
log SHA-256 is
e9bddac210654d219d9c5d6ebabaa3b91a0f5f4de4daf228b3ae21aeaac7673a.
The executable comes from provision receipt
268e601e81bc03a263296d57257b85635371bda642d0632532a7d9318c981461.
The independent case-matrix/held-source audit verifies cumulative executed
actual-owning-case coverage 0 from the failed whole invocation plus that
corrected case. Its receipt,
oink-r7-partial-case-matrix-audit-16_bl9hr/receipt.json, binds SHA-256
0a9e4a1a1e1a08f597becb2f27e743c9f23df672c713c2757241704edb16b51e.
All 113/193 physical/logical inputs remain frozen. Optional
TestArtifactCorpus and TestPublishedRuleSourceProvenance cases were explicitly
skipped. This never relabels the whole invocation as exit 0, nor claims those
skipped cases executed.
The new post-Go input audit,
oink-r7-partial-postgo-audit-g1hcqdtl/receipt.json, SHA-256
b369737ec48456f673c850ea702cb3cb7efffb8ecc129d87e00dc03af82b2e3b,
then confirmed the complete held 113/193 physical/logical inputs after Go/vet.
That scope does not claim whole Hugo, browser or consumer completion.
The new partial-preview browser passed against exact binary
f39d6754f7ad13599e4e849394e0f470b2c6f26edf96ce40f199d27b65a8030e,
version 0.4.0-r7-local, 16,000,578 bytes and mode 0700. Its summary is
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-studio-browser-cE9be3/summary.json,
SHA-256 9099e6c407fd0f9de3c29ce80e03f034a4223d7d7a7c1f1378052e8b9084e0ae;
provenance SHA-256 is
85b9f537fb09eecbb09d133b53a297c78184c11200ab0938734c0d10f3449095.
The private oink-r7-browser-partial-ZZIqzZ/source-binding.build.json, SHA-256
7a89ab8318c3a38455ab6ce12bcdbc53ae5ce0674fb5aaaa1df0fcf68a093399,
binds all 113 runtime and 193 broader source inputs plus physical identities
before capture/build/after to the new freeze; root inputs stayed unchanged.
All 14 axe checks had zero violations and all 14 screenshots passed, retaining
the keyboard/mobile/light-dark/source/clipboard/security checks described above.
Actual Hugo emitted oversized.bin at 67,108,865 bytes, reached through its
rendered /sub/oversized.bin link and returning 413; ordinary actual HTML
returned 200. Required partial preview coverage stayed visible; 228 typed
native diagnostics and native coverage/outcome 1 matched the CLI/API/UI,
while Studio and the subsequent refresh returned 2. Source preservation still
excludes only the declared task-fixture external edit. This is the bounded
synthetic browser proof, not a completed four-consumer or canonical render gate.
Another prepared, unexecuted corpus driver had assumed that an available normal
preview always appends a studio.preview coverage row. Actual normal
Starter/docs/PIG Overviews do not emit that row; the preparation assumption
was corrected without changing native coverage. The repaired fresh
oink-r7-corpus-partial-pZLwY0 driver, SHA-256
47778df62505beeb7432985be927f1b001e03824e9dee3a6dbed9d9b2dbe049c,
was reviewed against those three retained actual Overviews and the current
partial browser capture. Normal availability still requires its actual preview
URL and independent HTML 200; a partial capture retains its actual required
row, omitted count/identities and 413. The preparation audit is
oink-r7-partial-driver-correction-audit-sa98cm6k/receipt.json, SHA-256
a519a5bc6ae83438146ff4710d53f5edb0e656a05d0532c02123e5771416f07e.
Its earlier f762 preparation was not executed or qualified. The parent has
released the corrected driver for a fresh all-four run; its completed
qualification is recorded next.
The fresh four-consumer qualification completed with driver outcome 0 in
234.6425 seconds. Its current summary is
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r7-corpus-partial-pZLwY0/summary.json,
SHA-256 d7b5a4f1607b6f75ae6a596c19cbab28685fb67dac750096173060ed097c8bf5;
log /tmp/oink-r7-partial-corpus-gate.log binds SHA-256
a7b724500569bd594d8e01502ec1956eb089cc9153b04b693992a9322013c811.
The durable current corpus qualification.receipt.json binds SHA-256
4e5df7c3fda9f0b763091af3e6cb85c68c736c319a1de68030b81d5cd5b384bc;
primary source inventories contain 97/421/858/2,294 files respectively.
The private captured-source rebuild is byte-identical to the new browser binary
f39d6754f7ad13599e4e849394e0f470b2c6f26edf96ce40f199d27b65a8030e.
Runtime 113/broader 193 inputs and root physical identities stayed frozen;
every operation and the overall boundary preserve all four consumer bytes,
full modes/types, logical/mutable Git, ignored copied inputs and directories.
| Consumer | Native outcome | Typed diagnostics | Studio outcome | Actual captured pages |
|---|---|---|---|---|
| Starter | 0 |
28 review-info records | 0 |
66 |
| docs | 0 |
144 review-info records | 0 |
343 |
| PIG | 0 |
120 review-info records | 0 |
248 |
| repo | 1 |
10,462 existing duplicate-ID findings plus 788 review-info records | 2 |
1,576 |
Nested native headers, typed diagnostics, coverage and exit match direct CLI
checks exactly for all four sites. Issues were fully paginated; other views
were bounded samples, with captured physical source and translation diff
available on all four. The first three actual production previews returned
HTML 200; they emit no studio.preview omission row, and the driver invents
none. The repository normal HTML returned 200 with 60,100 bytes. Its current
capture exposes exactly four oversized print paths; each actual HEAD returned
413 with zero response-body bytes:
| Captured omitted relative path | Captured byte size |
|---|---|
_print/pkg/index.html |
73,976,221 |
_print/pkg/pgsql/index.html |
69,903,999 |
zh/_print/pkg/index.html |
73,086,240 |
zh/_print/pkg/pgsql/index.html |
69,052,754 |
These identities come from current bounded capture detail and live requests,
not the earlier ignored-output clues. Required studio.preview remains
incomplete, so repository Studio 2 retains native 1. Actual analysis-only
draft routes returned production 404 in docs and repo; that test was explicitly
not applicable in Starter/PIG without a unique captured draft route. Workspace
subset/full/healthy-subset sessions selected only registered sites and closed
listeners without captures; unknown or selected missing sites returned 2
before startup. This is local Darwin/arm64 CLI/API evidence with Hugo 0.166.0
Extended, Go 1.27.1 and Git 2.54.0; browser scope remains the separate synthetic
fixture. No source writes, install, publication, adoption or deployment occurred.
Independent final corpus audit
oink-r7-final-corpus-audit-xr3_u5dt/receipt.json, SHA-256
b8a8eedf5c899fe5830bdde959783c46b3f191ab144c0d3798077555d55238fc,
verifies raw typed native/API/shutdown parity, all 132 operation preservation
comparisons and four overall guards without rerendering or new HTTP requests.
Only guarded canonical promotion/render and the explicit R7/A16 stage decision
remain pending; R8 and final A18 remain open.
For temporary disk capacity, the parent retired only three explicitly created
private Go build caches, totaling 366,184,826 bytes, as recorded in
/tmp/oink-r7-private-cache-retirement.json. Sources, binaries and qualification
evidence were retained; no global, user or system cache was removed. This
preparation action is not a runtime correction or a qualification gate.
Remaining stage gates and promotion boundary
| Required gate | Current status |
|---|---|
| Frozen runtime input/binary identity | New partial-preview freeze binds 113 runtime inputs 4900ae05abbdf4409b0be54f276fb4135269cf0a49e9071013ccf42544d35c84 and 193 broader inputs 8b172cef2b228e2642f0139d6cc569136e86843f818e52e412fa4a2d56add25d; all UI bytes/modes unchanged. Source-bound browser binary f39d6754f7ad13599e4e849394e0f470b2c6f26edf96ce40f199d27b65a8030e passed; fresh private consumer rebuild is byte-identical |
| Full Go/vet and actual Hugo | New whole serial Go/vet and browser passed. New actual-Hugo/pinned-tool whole invocation remains exit 1 for a preparation path; sole corrected owning case passed 0, yielding independently verified cumulative executed actual-case coverage 0; two optional cases explicitly skipped |
| Four consumers | Completed exact-binary CLI/API qualification; native 0/0/0/1, Studio 0/0/0/2, exact nested native parity and source byte/full-mode/type/Git/ignored-input/directory guards; repository partial preview remains required incomplete |
| Canonical paired sources/render | First guarded TEN promotion and scoped actual render passed; the post-render status amendment has separate fresh source checks and is not claimed rerendered |
| Stage decision | R7/A16 supported local scope accepted; R1–R7 accepted locally, R8 and final A18 remain open |
The next prepared documentation installer retains the actual captured old inode outside canonical source storage on both success and recovery, without unlinking its last name after an earlier target identity check. This private helper hardening and its new recovery fixture are a new preparation boundary; executed R6 installers/hashes/receipts remain immutable and are not retroactively claimed to contain it. R6’s successful promotions already retained originals. No consumer plan writes, release, adoption or deployment are implied by this candidate documentation or the local browser fixtures.
The completed first-promotion rendered gate is /private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r7-docs-render-n8tw2tbw/summary.json, SHA-256 35e79f51d39803b3e4cdf134ed277957dd627acba42e0e0dc785e4745ec3c481, with log SHA-256 de3a07eac661c15805070e0ed2e364a71ebbd38e15d8907aab3bdf716e95131d and elapsed 63.33 seconds. Exact qualified binary f39d6754f7ad13599e4e849394e0f470b2c6f26edf96ce40f199d27b65a8030e passed production CLI links with one strict Hugo build. Ordinary production Hugo without a probe passed rendered Markdown (214 pages/44,075 text nodes) and links (345 pages/48,482 internal links/4,303 fragments). Its translation owner retained exit 1 only for the existing nonpublished release 1.2.0 draft. Independent draft/future/expired analysis passed Markdown (216 pages/44,381 nodes), links (347 pages/48,858 internal links/4,331 fragments) and translations (137 pairs/1,129 headings); it did not replace production output. Source translation/style/whitespace checks passed and CLI/docs schema 7468c2d04cde8a368ce0ba44a1f27125b5fca364b6d4672353519b9545b3bdda remained identical. All twelve operations, schema and overall guards preserved 421 primary files, 427 copied inputs, 109 directories, 36 mutable Git files and 113 runtime inputs.
The first guarded promotion receipt oink-r7-root-promotion-p9g1u7pz/summary.json, SHA-256 323a5ce267e39aaf8f97dc4a12cccbdde83730155a199efb5f3815e29b334e4a, verifies actual original inodes retained outside canonical source. Its post-apply receipt lookup initially used 0 instead of 00; that metadata-only driver failure is preserved, followed by receipt finalization with unchanged raw guards. The successful source installation was not reapplied. Executed R6/R7 helpers and first-promotion receipts remain immutable.
R7/A16 supported read-only local scope is accepted after the frozen cumulative owning-case/browser/corpus and canonical gates above. The original whole-Hugo invocation still has exit 1; the corrected sole tool case plus independent matrix establishes cumulative executed-case coverage. Repository native 1 and required partial preview/Studio 2 remain visible. R1–R7 are accepted locally; R8 editing and final A18 remain open. This post-render status/evidence amendment has its own byte/full-mode guards, unchanged headings/command fences, paired source checks and retained-inode installer fixtures. Its new bytes are not claimed tested by the preceding 63.33-second render; no additional rendering, consumer write, public release, adoption or deployment is implied.
R8 accepted reviewed editing evidence
R8/A17 supported editing scope is accepted locally after the corrected frozen
owning/browser/corpus and guarded canonical rendered gates recorded below. CLI edit text, field, snippet and attachment preview the same
bound oink.edit/v1 intent used by explicit studio --edit. Saved-plan apply or
explicit acknowledged Editor Apply owns selected source writes. The default
Studio session remains read-only. This section retains capture-time candidate
facts and trials, followed by the completed current qualification; it does not
extend earlier R1–R7 evidence to changed code.
Candidate scope and preservation
Known site-owned UTF-8 Markdown is bounded to 1 MiB. Full text and supported
ordinary top-level YAML scalar forms retain the declared BOM/line-ending and
source-span preservation boundaries; unsupported form shapes remain text.
Exact value_json numeric tokens avoid browser Number rounding. Scalar forms
bound numeric literals to 4,096 bytes and absolute decimal exponent 10,000;
larger/nonfinite constructs remain manual text. Field JSON is at most 1 MiB;
escaped lone surrogates refuse, valid Unicode pairs are supported. Catalog
components use original UTF-8 body byte offsets; attachments require actual
leaf-bundle identity, at most 4 MiB and an exclusive new clean basename.
Source hashes, full modes, all site/external inputs, regenerated intent and
fresh actual Hugo validation bind the same shared guarded application path.
The Editor displays the complete UTF-8 review, selected-file base/after
identity and native candidate result; the review is capped at 2 MiB and its
literal bytes are hash-checked before acknowledgement. The actual selected
candidate HTML is draft/future/expired analysis, visibly nonpublishable and
separate from the original production preview. Required candidate-view
incompletion may raise the proposal/session to 2 without changing native
findings. For page-file edits, the selected candidate source hash/full mode
matches its reviewed After state; attachment/no-op proposals retain the
selected page’s reviewed Base state.
Stale/replayed plans, attachment collisions and untrusted preview requests are
refused; applied-with-refresh-error remains explicitly applied.
Focused preparation receipts
| Candidate evidence | Current observation and boundary |
|---|---|
| Pure editing core | Owner’s focused exact-numeric tests passed for 18446744073709551615 and 7.12345678901234567890123456789, exact no-op raw bytes and changed final decimal digit; broader frozen receipt pending |
| Actual DFE output ownership | Live ordinary output is copied through a confined os.Root, exclusive target files and guarded streaming reads; files over 64 MiB can be captured while serving limits remain unchanged |
| Copy cancellation/race | Context-aware helper focused 0 in 0.703 s, race 0 in 1.856 s, vet/whitespace 0; actual first-chunk cancellation retains partial output, source bytes/modes/identity unchanged; source FIFO replacement cannot block before descriptor proof |
| Helper log identities | Focused c227a88210ab0dc46b24eaff50a347d5c494e9ce23f5bdef5d5b822efab4976f; race 13f0616d55fd4df791ecded0712a18096392c88cb9b849383414c305e50b6779; vet is empty SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 |
| Read-only candidate integration review | Selected actual HTML URI/base prefix and inventory, retained private DFE lifetime, source SHA/full-mode equality, native versus view coverage and cancellation reviewed; no new material defect found within this code review scope |
| First Editor browser trial | Harness stopped on ambiguous global Open editor selector; retained as failed trial, no UI qualification claim |
| Corrected-selector Editor trial | Desktop field/component/binary apply checks and axe checks passed before 320 px draft-review horizontal overflow failed; retained original trial, not a final browser pass |
| Narrow layout correction | Editor review hashes/receipt text wrap and intrinsic widths are bounded; prior CSS and failure evidence retained separately. Development rerun passed 12 axe checks/screenshots, including real 320 px dark review and light receipts/refusals; final frozen-source/binary rerun pending |
The helper evidence is focused file-copy/cancellation qualification, not the whole editing application or all platform support. Browser trials describe their actual stopped scope. They do not establish final A17, consumer adoption, deployment or a successful current frozen browser binary.
The preceding preparation rows were captured before the first complete R8
freeze. They remain development history. The first whole frozen gates later
passed for binary 84b804d3246a5be581e44884ed910fa3f45d8be29734b8babdeeb763a11fa882
(0.5.0-r8-local), runtime 123/58517b8e98b80df6642be4ee6275a0074ec187768b20e009f41da2607b635d46
and broader 212/d81335c78413acc60e27adee0ac794862285e41cb2a3a7687ec820c1065ba003.
The whole-gate summary is b49f4a3272af3e3dcc92e7e9b38d4289bb49cb19aa3e9354ea148d2d8cb2cea8:
Go tests 0/56.523 s, vet 0/0.904 s, whole actual Hugo plus all three pinned
tools 0/320.044 s, core race 0/16.610 s and public R8/helper race 0/48.319 s.
Its source guards passed. These receipts qualify those earlier bytes only.
The first frozen browser receipt
eb6977235ef9ae6cec28651b5654eb101685af67abe0cbed0acb0f8375458d9c
binds that same binary and source freeze. Editor had 12 axe runs with zero
violations and 12 screenshots; retained read-only Studio had 14/zero/14.
The actual form preserved the literal 1e400, its planned after hash and diff,
then discarded it; exponent ±10,001 and a 4,097-byte numeric literal refused
locally without an API request. Four acknowledged field/component/binary/draft
applications occurred only in disposable fixtures. Default read-only refusal,
stale preservation, no-op source bytes, preview isolation and native-result
independence passed. This is development browser evidence for the first
freeze, not a four-consumer or current corrected-runtime acceptance.
The first exact-binary consumer trial then stopped at Starter after 37.533 s.
Its immutable failed-trial receipt is
853a8397ba4c527c03aa3cc9ac7cacc41c0ab0379549d145b874f1d1ecc3901c.
Two failures are recorded separately. A driver event hash depended on JSON
object-key order even though recursive comparison proved API/CLI arrays equal:
28 diagnostics, 29 coverage rows and native exits 0/0. Separately, repeated
resolved cache capture produced a genuine duplicate module input
.gitattributes; required candidate graph capture became incomplete, mutation
outcome 2, with native check still 0, no actual selected DFE HTML and no
applicable lease. The public published-cache fixture reproduced that defect;
its retained failing log is
50ab704e715665096e0f36391bb1364841c3a2b2ac88dd262915ce53fb66afa6.
All 48 recorded per-operation source proofs and four overall consumer guards
preserved bytes, full modes, types, Git, ignored copied inputs and directories;
root inputs stayed exact. No Apply or saved plan was performed. This stopped
trial has no completed four-consumer qualification claim.
The narrow runtime correction gathers complete resolved-module rows before
committing additions. Identical repeated or reordered captures retain the
original inventory. Changed hashes/full modes, added or removed paths within
an existing scope, missing scopes, conflicting identities or capture errors
refuse without refreshing prior evidence or appending partial additions;
non-module rows remain exact. Site owning receipt
e7b284b9dece1c5f2b696cd76166d2286fcbec69e6c48912ab9a78204bdb980b
records focused 0/0.746 s, site 0/2.123 s, focused race 0/1.958 s and vet
0/0.167 s. This compares reobserved complete rows; it does not lock module
files against concurrent writers.
The corrected published-cache receipt
6358dc81f06e34b789cb47a0f4442d6d036d2e33423a06f5dbe85b3064766da6
records actual github.com/pgsty/[email protected] from a task-local copied checksummed
archive, with no downloads or replacement. Original and candidate graphs each
have 1,256 unique inputs, including 1,198 module inputs. Full API/CLI typed
diagnostics, coverage, exits and plan identity match; actual selected DFE HTML
returns 200, with source bytes/full modes/Git unchanged and no Apply or saved
plan. Owning race passed in 30.255 s; vet passed. Its corrected race log is
c7d21a30b8af141d9d9604a80ddf9cf3f608320b97a441a06a742376e2119551.
The current complete corrected freeze is
fb276500a3d2643bd0aa220f8bebb380fce2c98493d62b0502b6497b2f02949f,
runtime 123/cdf629eeb4bbef6d4d88ee27fe3fb0a73b07b6bf6438336e033a18fb7feb1c17
and broader 212/f6e305e792733a550814eb841615d12fa14a9a6bb2a97c4ada85f7275183e579.
Only source_inputs.go, its owning test and the public published-cache test
differ from the first freeze; held UI/helper bytes and all full modes remain
unchanged. The rebuilt candidate is
bd25f9e0b35ec10e227aabf9582ae40b0b367390f64b93668de6ae85222c3d71
(0.5.0-r8-local). Its observed corrected source-bound browser receipt
33a698985a55c14c3e64e981da1f8e74c686497083dc0edb241406f185e3eeb8
again reports Editor 12/zero/12 and read-only 14/zero/14 with complete 123/212
pre/post source preservation. Corrected whole owning gates, the fresh
four-consumer corpus and protected canonical rendering are still pending at
this evidence amendment. R8/A17 is not stage accepted; final A18 stays open.
At the next evidence observation, the corrected whole gates completed for
that held bd25f9e0…22c3d71 binary and fb276500…02949f freeze. Summary
208f156c0954e803eccbada678a4689683dc1576c543c379e5cc04b3497ef772
records Go tests 0/57.826 s, vet 0/0.521 s, whole actual Hugo plus all three
pinned tools 0/378.847 s, core/site/Studio race 0/17.937 s and public
R8/attachment/output-helper race 0/85.159 s. Every gate’s source pre/post guard
passed. The actual-Hugo log has 434 top-level passes and zero failures; the two
optional external fixtures TestArtifactCorpus and
TestPublishedRuleSourceProvenance remained explicitly skipped. Those skips
are not claimed as executed corpus or provenance qualification.
The corrected whole actual-Hugo log is
4eb1a2afdce2adbe570b10922fd53b6d8954f7c95747370c3c661e94d2f71a05;
Go log ea59463e9649ffe2f8aff9da66c91cf6895c86fde96a524db23c89cd4eb35925,
core race cdd3d761b5ca7b5e986b25aee3129d65663e3e5ebb83eecb6fbb080387298a58
and public race bb610bdcd7a299cb9b66f4c69e30e246c20546efae47653c01d350b1026ea2de.
The corrected browser-only evidence above remains bound to the same current
source and binary. The separately authorized fresh four-consumer trial is in
progress; no completed corpus, canonical render, R8/A17 acceptance or final
A18 qualification is inferred from these owning gates.
The 434 passes and two optional skips above are top-level counts. The same
whole invocation also skipped the nested Unix-socket refusal fixture because
the Darwin temporary pathname exceeded the socket limit. A first shorter
private-path trial still skipped: receipt
93106854ca890b497d3c74522b895f597ac60cec55ced42cad7b187d334da200
retains process exit 0 but explicitly records no actual socket execution and
failed qualification. It is not relabeled as a passing fixture.
A subsequent nonresolved short private TMPDIR executed the same frozen
socket fixture under race detection without a skip: 0/2.954 s. Receipt
531a503b3b91e1b423c2be61b92ed806d3a813738c38d57e5ec122577b4337f9
and log 236c84f1842ffce76174c834f3888718a109cec6377ada6f3242b02f551f00b3
bind fb276500…02949f and all 123/212 logical/physical/Git inputs unchanged
before/after. This supplies the actual socket-refusal case without changing
source or the original whole invocation’s skip history. Corpus, canonical
render, R8/A17 stage acceptance and final A18 remain pending.
The preceding pending-corpus statements record their observation times. The
corrected four-consumer trial subsequently completed in 845.705 s. Summary
af4fc53326163c4a03aa2982c1f01363fbbdd5a447c9baed3639bd8599d46370
and qualification receipt
4d6fd02543c1920497e1a1bb0a68fcf89b0546130fd9cc12c1df391b7e673e75
bind a byte-identical private rebuild of bd25f9e0…22c3d71, the complete held
123/cdf629ee…feb1c17 runtime and 212/f6e305e7…5183e579 inputs. Original
failed corpus, published-cache regression and first frozen browser/gate bytes
remain separate historical evidence; all 2,383 entries of the first failed
trial retained their exact bytes/full modes/types.
| Corrected consumer | Native/current and native candidate exit | API candidate outcome | Full diagnostics/coverage | Actual selected analysis HTML |
|---|---|---|---|---|
| Starter | 0 / 0 |
0 |
28 / 29 |
200, 48,149 bytes, /blog/design/content-model/ |
| Documentation | 0 / 0 |
0 |
144 / 34 |
200, 61,738 bytes, /blog/oink/immersive-reading/ |
| PIG | 0 / 0 |
0 |
120 / 41 |
200, 55,641 bytes, /404/ |
| Repository | 1 / 1 |
2 |
11,250 / 29 |
200, 92,352 bytes, /blog/infra/2020-12/ |
These are actual selected Hugo HTML routes in the separate, visibly
nonpublishable draft/future/expired candidate view; each expected candidate
marker was present. API and CLI matched full typed diagnostics/coverage, native exits, plan ID,
Base/After hashes and full modes, unified diff and the selected page’s proposed
source. The complete literal API review and its hash were independently
validated. No consumer Apply or
saved plan occurred, and no listeners remained. The repository retained
10,462 existing duplicate-ID findings and 788 information records. Its four
actual PRINT outputs remained required partial-preview incompletion:
_print/pkg/index.html 73,976,221 bytes,
_print/pkg/pgsql/index.html 69,903,999 bytes,
zh/_print/pkg/index.html 73,086,240 bytes and
zh/_print/pkg/pgsql/index.html 69,052,754 bytes. Each bounded HEAD request
returned 413 with zero body; selected in-limit HTML remained 200. Native
1 remained unchanged, proposal/session 2 and Apply refusal stayed visible.
The other three complete previews had no invented explicit complete-coverage
row: actual guarded HTML 200 supplied that evidence.
Exactly 53 protected operations each checked all four sources: 212 per-operation source proofs plus four overall proofs, with source bytes/full modes/types, copied ignored inputs, directories and logical/mutable Git unchanged. Each source proof compared four inventory categories, yielding 864 raw inventory pairs including the overall comparisons. All 53 root guards and the final complete 123/212 logical/physical inputs also matched. All issues and pages were paginated; the other five view endpoints were sampled to their first 50 records, with one known source and one bounded diff per site. Full native/CLI record parity used the declared bounded complete-record codec; object order was canonicalized while array order, types, null and field presence remained significant. This does not claim every relationship was visually reviewed or every source was edited.
Independent audit receipt
6b72ca06d8392a5271fc40757f176f26e1144c21eec93dbd035e0a1bd645657b
verified 69 artifact hashes, complete bounded API/spool/shutdown typed records
and the large native/CLI raw-file digest bindings. It did not separately
repeat multi-gigabyte native semantic scans. Its additive receipt
335f137663d4ec0b2a0d3e49c8d70b9918f86078ab6264855171a2644d8aa6c6
also verified the fresh current root’s complete logical Git inventory against
the freeze; the original audit stayed immutable. Corrected owning, socket,
browser and four-consumer supported scopes are qualified. Canonical TEN
promotion/rendering, the R8/A17 stage decision and final A18 remain pending.
The preceding R8 candidate/trial statements retain their capture-time scope.
The reviewed first TEN promotion subsequently passed through the guarded
retained-inode installer, root receipt
7cd9b4604d2340b9e46965a26281c921b967060909d518b8b4b31e5f42d0120c.
Its actual original source inodes remained retained outside the documentation
site; unselected source/copied inputs, directories and Git, and complete CLI
123/212 logical/physical inputs stayed unchanged.
The separately authorized canonical render then completed exactly once in
67.21 s, summary
bb0d0710294f810fb14284f7b5b0329befbd290b66c21397b9a45e8382287fb6,
qualification receipt
32d3ffeca43bc9ad4615edcca0d3cc47cc932bbc93c6576724c800e0a62405b1.
It used the exact qualified bd25f9e0…22c3d71 binary and corrected 123/212
freeze. Actual CLI production links passed 0 with one strict Hugo build.
Independent ordinary probe-free production Hugo/Markdown/links passed: 214
Markdown pages/44,691 nodes and 345 link pages/48,532 internal references/4,351
fragments. Its translation owner retained 1 solely for the existing
release/1.2.0 draft absent from production. Separate explicitly nonpublishable
draft/future/expired Hugo analysis passed Markdown (216 pages/44,997 nodes),
links (347 pages/48,908 references/4,379 fragments) and all translations 0.
Analysis did not replace production output.
Source translations passed 137/137 pairs and 1,143 headings; Chinese style
passed 137 files/181 strong spans/zero emphasis, whitespace passed and schema
SHA-256 7468c2d04cde8a368ce0ba44a1f27125b5fca364b6d4672353519b9545b3bdda
matched exactly. All 12 commands, schema and overall guards preserved 421
primary source files, 427 copied inputs, 109 directories and 36 mutable Git
files, plus all 123 runtime/212 broader CLI logical/physical inputs. The
qualification receipt binds 60 canonical inventory pairs, 15 CLI guard pairs
and six private-copy source pairs; it claims no consumer writes or deployment.
R8/A17 supported local editing scope is accepted after corrected owning,
socket, source-bound browser, exact-binary four-consumer preservation and
these guarded canonical gates. R1–R8 are accepted locally; native repository
findings and required partial-preview 2/Apply refusal remain visible. Final
A18 current Linux/runtime/archive qualification stays open. The separate
platform-authority audit
762571dab9a07651ac8e4c71764bfef292f8d5eba729a089e72d9d755b7e2d7c
confirms that the initial contract qualifies actually exercised architectures:
macOS arm64, native Linux arm64 and emulated Linux amd64. Darwin amd64 remains
an experimental archive with failed actual execution/unverified runtime; its
history is preserved, and no successful cross compilation becomes a runtime
pass. Both current Linux runtimes and final archives still require fresh proof.
This post-render status/evidence amendment has separate full-byte/full-mode and inode guards, unchanged stable IDs/command fences, paired source checks and retained-inode installer fixtures. Its new bytes were not rendered by the preceding 67.21-second run. No repeated rendering, consumer source write, public release, adoption or deployment is implied.
Required gate matrix
| Required gate | Current status |
|---|---|
| Final immutable runtime/source freeze and exact CLI binary | Corrected complete 123/212 freeze and bd25f9e0…22c3d71 bind completed owning/browser/corpus/canonical scope; first-freeze trials separate |
| Public CLI/JSON/exit, stale source/config/external-input and guarded writer tests | Corrected public R8/attachment/output-helper race, whole Go/vet/actual Hugo and canonical stage gates passed |
| Frozen whole Go/race/vet and actual Hugo/ordinary Hugo after selected application | Corrected whole Go/vet/actual Hugo and core/public race passed; 434 top-level passes, zero failures, two optional external fixture skips explicit; first trials remain separate |
| Editor browser five-view parity, text/forms/components/binary attachments, exact numeric/no-op, stale rejection and preview isolation | Corrected source-bound Editor 12 zero-violation axe runs/12 screenshots and read-only 14/zero/14 passed; bound completed corpus and canonical acceptance |
| Exact-binary four-consumer read-only qualification | Corrected all-four completed in 845.705 s; full typed native/API/CLI candidate parity, 212 per-operation source proofs plus four overall, no Apply/save/source writes; first failed trial preserved |
| Protected canonical TEN promotion, EN/ZH source/schema/style/whitespace and actual production/analysis render | Guarded first promotion and independent exact-binary 67.21 s render passed; only known draft translation omission in production; rendered and status bytes separately bound |
| R8/A17 stage decision | Supported local scope accepted after corrected whole owning/browser/corpus/canonical gates; R1–R8 accepted locally |
| Final A18/platform/archive delivery | Open; compile success alone is not runtime qualification |
Passed and pending entries are explicit; later gates are not inferred successes. Prior R1–R7 sections, whole-invocation failures and scoped acceptance receipts remain unchanged. Temporary qualification files stay outside canonical content and Git; first canonical promotion/rendering has exact receipts, while this status amendment remains a guarded proposal. No public release or deployment is claimed.
Current runtime completion supplement on 2026-10-04
This supplement records the current candidate on 2026-10-04 (Asia/Shanghai). The dated page URL and all initial 2026-10-03/R1–R7 records remain unchanged. The preceding R8 stage and browser/render receipts are historical input-bound proofs; they do not qualify subsequently changed backend bytes. The three UI files retain exactly the browser-qualified bytes and full modes. Current Go, Hugo, platform, archive and four-consumer checks refresh the changed backend.
The first current ARM offline unit run exposed a real output-copy integrity gap:
adding a directory entry on ext4 could retain the parent’s allocation size and
observed timestamp. That failed run stopped before later qualification steps. The
bounded correction captures and rechecks actual sorted directory membership and
entry identity, alongside regular-file byte/full-mode proofs. Only
internal/app/studio_output.go and its owning test changed. The failed receipt
and independent audit are retained; a failure never becomes a passed run.
The preceding integrity-correction qualification freeze is 683daca0e522193c7ff1b0de6ac2fee5d2fca080811bf184a8dfd5b90a33f224:
123 runtime inputs hash to d346ad15cd4239004e32e1b9f30d727eaf156be0187dc165ca874032a7cf962a,
and 212 complete CLI inputs hash to 2abd1a044d8192b07f9bbc06b55dc8b4544d66ca17b8867971cec702ba3af088.
The 0.5.0-r8-local Darwin arm64 candidate is
74ad94e73557f6538cd64edd1766d6df92c596d98411031159d94af072c186ec.
The observed integrity-correction receipts below bind that source scope; old R2 Linux and earlier R8
binary receipts retain their historical scope. The later one-test fixture amendment has its own complete source identity and
completed formal qualification boundary, recorded below.
The current complete source freeze is now
196245a3ba09305e34b86539c8eb79f1473e4373ee47aa1f56f8933b04a42d43.
The 123 runtime inputs remain exactly
d346ad15cd4239004e32e1b9f30d727eaf156be0187dc165ca874032a7cf962a;
the 212 complete CLI inputs are
2c487bfb4c65ed40ff78356b2860de627e6ac1afa0da2df433b09345dab7f5b0.
Only the owning published-cache test changed, to source
54c10ef89310256b5f4c165c7de5de9668e1d4d2991b71751076680141dbe779.
The fixture amendment is separately guarded; production bytes and all semantic
assertions remain unchanged. Formal qualification of this complete source, including current eight owning
gates, reproduced archives and full plain-Go AMD/ARM runs, passed. Root A18
proof 2c018cb2afa3f26699a9e6b5a0971096246b12405fde5a27e43a9e213e46da60 binds all three declared supported targets and five reproduced
archives. Earlier receipts retain their captured inputs; they are not relabeled
as runs of this amended test source.
| Current proof and preserved earlier input boundary | Observed result and bound receipt |
|---|---|
| New complete-source formal qualification | Freeze 196245a3ba09305e34b86539c8eb79f1473e4373ee47aa1f56f8933b04a42d43, owning test 54c10ef89310256b5f4c165c7de5de9668e1d4d2991b71751076680141dbe779, unchanged runtime123. Current eight gates, host/archive and both full plain-Go Linux flows passed, bound by root A18 proof 2c018cb2afa3f26699a9e6b5a0971096246b12405fde5a27e43a9e213e46da60; this does not claim final document bytes were already rendered |
| Narrow integrity correction | Owning receipt 6966d768025497b45958073d4c53a2a2981065c8a95857834dcf6a4faa4f0201; independent audit 6cb5d2eabf57b41079026a38a674f46def9f56a15df17ad27e671e4f765798df |
| Prior-source six frozen owning gates | Build, full offline Go unit/vet, whole actual Hugo/pinned tools, core race and public R8/output-helper race all 0; elapsed 3.501/68.257/3.909/333.801/37.070/79.670 seconds. Summary b40b7787b3da8dc1e0763812b6dde529b4b5b69fe479d79940f1161223124e1d; independent audit 20780662b7ff35019b2c8c84e6dc763f9351ae0816f6ef7a7789f7a15be99167 |
| Eight current frozen owning gates | Selected published-cache actual Hugo and race, build, full offline unit/vet, whole actual Hugo/pinned tools, core race and public R8/output-helper race all 0. Current summary d6272fcc4dfab114aecfcdf19a7e2b78f1e931817331b460f43ff2056bf754a4; raw whole Hugo has 435 top-level passes, no failures, two optional top-level skips and the explicit long-path socket child skip. Runtime/binary bytes remain identical |
| Prior-source Darwin arm64 and archives | Current extracted candidate runs outside the checkout with no consumer Node requirement. Seventeen commands and eight actual process tests, including child signals, passed without process-test skips. Two fresh release directories contain byte-identical five archives and checksums; source/license/provenance/canonical tar checks pass. Summary bcb4d7599e965c1b3cfe7fe698ca14061ad53d45e7a194337aeebb8d37aa77c1; independent audit 60a04771365d8be15ac91fbbd8d485b019aae081598e468018861ca5734e387c |
| Current Darwin arm64 and deterministic archives | Seventeen extracted-archive/ordinary-Hugo/process commands passed expected exits, with missing Hugo explicitly 2; eight actual signal/process cases ran without skips. Two independent fresh builds reproduced five byte-identical archives from current complete source. Summary 3890fd8468b6bce5271bb32ffa1a18bd5daf99c19c43becac0be8e3b908a5d57; source, tools, module-cache and smoke-source guards remained equal |
| Prior-source Linux arm64 | Actual nonroot Linux arm64 on ext4 with Go 1.27.1, Hugo Extended 0.166.0 and Git 2.47.3: full offline Go unit/vet, all 13 required pure top-level pass records and the membership case plus its four children without skips, 10 selected actual-Hugo cases without skips, native rebuilt archive identity, installed bilingual/offline/ordinary-Hugo/missing-Hugo 2 JSON and signal/source-mode checks passed. Guest summary 409990bc1425f4bf219f8911a71581af6e68729865580121dbeb6d85a06d2ea7; outer receipt a022e40f068703cd59ce6d6a7fb6530cce6907681baa26eb1dfc77c09f0c8898; exported-record audit 24afc50f6f860394d1ebfa7a8b754ddd9cb97f9e88a0dcfcbcb659193ecbfe5f |
| Current Linux arm64 | Current nonroot Linux arm64 on ext4, native ARM through QEMU HVF, Go1.27.1/HugoExtended0.166.0/Git2.47.3: full offline unit/vet (370 top-level passes), all13 decisive pure cases and4 membership children without skips,10 selected actual-Hugo cases without skips, exact native/installed current archive identity and bilingual/offline/ordinary-Hugo/signal flows passed. 24 commands reach expected exits including missingHugo2. Guest 268102f69c0950f9d2994d22cd2fd290fc11e24bd6d6f916fd70a93ca4946c74; outer f3c066fdc9b97feff92160346185a1af978a5172eed5c81904ac7c0e5fc6c982; source/SDK/borrowed/old-task guards equal and owned VM reaped. Default optional unit skips retain their named gating reasons; no full Linux Hugo-suite/browser/linter claim |
| Prior-source Linux amd64 failed trial | Unqualified after the preserved current TCG trial failed: outer receipt 3543664ba5590f2ba5a8f676b196bb636b72bc819913289f415d0a8a841c1bdb, guest summary 16075204d287713c7f7650c0a65dd289dd4bd83db07c9ba4b85b3f21244d5240. Full offline units (370 top-level passes), vet and the first three selected Hugo cases passed. The published-cache candidate request hit the test HTTP client’s 90-second deadline; candidate parity, the remaining six selected Hugo cases, native rebuilt archive and installed archive smokes were not reached. Deadline review 12917b9eb89e3abc5893e08da3b6b6e20743dcb4c14e6f7ba8561628e3566934. A18 stays open; no future preflight or full qualification result is inferred |
| Current Linux amd64 | Current nonroot Linux amd64 on ext4, QEMU TCG emulation, Go1.27.1/HugoExtended0.166.0/Git2.47.3: full offline unit/vet (370 top-level passes), all13 decisive pure cases and4 membership children without skips,10 selected actual-Hugo cases without skips, exact native/installed current archive identity and bilingual/offline/ordinary-Hugo/signal flows passed. 49 commands reach expected exits including missingHugo2. Guest 3a1a32979efc843de8b95b7c13824026e17f71c06d4c458b738c0b9583fb4723; outer 30cf4950cc83fa0732047d9a0f89bb59e68779ee2e8f5c755724c9679be265e3; source/SDK/borrowed/old-task guards equal and owned VM reaped. Default optional unit skips retain their named gating reasons; no full Linux Hugo-suite/browser/linter claim |
| Runtime-equivalent preceding four-consumer candidate corpus | Source epoch 683daca0…33f224; runtime123/binary74ad is byte-identical to current 196245a3…42d43. The corpus was not rerun after the test-only amendment. 853.249 seconds; native/candidate-native 0/0/0/1, API/view 0/0/0/2; diagnostics 28/144/120/11250, coverage 29/34/41/29. Summary a1e98ca3e10095a1134381666bacf256f8e8827cd3900c9e811b7120de4c2974, receipt 05c4562a50d9f83ba2c99879ec841870c5e753199e41792bd5bc718cf8046e7b, independent audit 3a1b0b6e3a8c6b1a0d82c5f82b46c84b1e44d6c30bab655610cb9e86e6a30b47; final TEN bytes have their own render boundary |
| Final canonical lifecycle and rendered checks | The exact promoted TEN bytes require independent canonical rendering and navigation/URL receipts; earlier rendered proofs do not qualify these amended bytes |
The preceding six-gate b40b7787b3da8dc1e0763812b6dde529b4b5b69fe479d79940f1161223124e1d, host/archive bcb4d7599e965c1b3cfe7fe698ca14061ad53d45e7a194337aeebb8d37aa77c1, and ARM outer a022e40f068703cd59ce6d6a7fb6530cce6907681baa26eb1dfc77c09f0c8898 / guest 409990bc1425f4bf219f8911a71581af6e68729865580121dbeb6d85a06d2ea7 / audit 24afc50f6f860394d1ebfa7a8b754ddd9cb97f9e88a0dcfcbcb659193ecbfe5f remain passed only for their captured source. They are retained alongside the new exact-source proof, not overwritten or relabeled. Historical 26 axe checks/screenshots and 22 codec cases are carried with unchanged UI/codec/runtime inputs, not claimed re-executed.
The initial max-CPU AMD trial stays failed: receipt 3543664ba5590f2ba5a8f676b196bb636b72bc819913289f415d0a8a841c1bdb, guest summary 16075204d287713c7f7650c0a65dd289dd4bd83db07c9ba4b85b3f21244d5240. The test client timed out after 90 seconds awaiting candidate headers; candidate parity and the remaining six selected Hugo cases/native rebuild/installed smokes were not reached. Guest inputs stayed exact; the host guard recorded only a .git directory timestamp change, whose cause was not proven. The separate qemu64 one-test preflight also failed at the unchanged 90-second HTTP client deadline: outer receipt fc68173ccdfd8ce263ecdf082a533d9da666a4cc2e1e5e29880ee827286132ac, guest summary e350ff65feeee166ffac1d337db9bbd70d3895b1fb6d93df0a30ca4de09019fc. The named case took 177.71 seconds, compared with 176.64 seconds in the first trial; no CPU-model speedup is inferred. Its inputs remained exact and its VM was reaped. Neither failed trial is relabeled as a pass.
A later, explicitly nonqualifying Go-overlay diagnostic preserved the same
production source and every original semantic assertion. Outer receipt
0bc6d563b7cd9ca862717c2123ee0836d83b6b927d00204a0b031049c38e93f0
and raw-bound classification
66a1422cdb79ab9f1cf683f441ade0ce4adb4a7a666d524c4b9ed98ebee28708
record a passed named case in 352.40 seconds. Original capture took 26.254 seconds,
Studio capture 26.211, candidate HTTP 94.312, direct preview 94.318 and CLI
preview 81.962. Both graphs retained 1,256 unique inputs, including 1,198 module
inputs. The old original-capture context was expired by the HTTP result; fresh
independent direct/CLI contexts completed normally. All 20,564 host guards and
five guest command guard pairs stayed exact; the owned VM was cleanly reaped.
This diagnostic altered test budgets and is not exact-source or full A18
qualification. The scoped owning-fixture amendment now uses a 300-second budget
for that candidate request and fresh direct/CLI operations, about 3.18 times the
slowest observed operation. General/original-capture 90-second limits, restoration
of the shared client, shutdown 15 seconds and Go’s default ten-minute cap remain
unchanged. These are test fixture limits, not a product performance SLA. Formal plain-Go AMD/ARM and current archive qualification is recorded in the
current table above; the diagnostic itself remains nonqualifying.
This preceding corpus qualifies the unchanged runtime CLI against its captured, unchanged pre-final-TEN consumer inputs. It does not qualify subsequently amended canonical document bytes; the final TEN has a separate rendered receipt boundary.
The consumer driver compared complete typed diagnostics, coverage, native exit, PlanID, selected Base/After/full modes, unified diff and selected source between API and CLI. It separately verified the complete literal API review and its hash. For attachments and no-ops the selected page retains reviewed Base; page-file edits match reviewed After. Nonissue views are bounded samples; all issues and pages are paginated. The 53 protected operations have 212 all-four per-operation source proofs plus four overall proofs (864 raw inventory pairs across four categories) and 53 root pairs. Seventy-one retained artifacts are bound. No Apply, saved plan or consumer write occurred. The completed corpus’s file-only collector needed two preserved metadata corrections for absent historical trial/self-test files; no CLI/Hugo operation was rerun. The existing 22 negative codec cases are historical checks of unchanged codec bytes, not a newly executed self-test.
The repository retains its 10,462 pre-existing duplicate-ID findings and 788
review-info records. Its selected actual DFE HTML is available, while four
oversized actual PRINT files stay unserved (413, zero response body):
_print/pkg/index.html 73,976,221 bytes, _print/pkg/pgsql/index.html 69,903,999,
zh/_print/pkg/index.html 73,086,240 and zh/_print/pkg/pgsql/index.html 69,052,754.
The 64 MiB per-file preview bound is unchanged: required partial-preview
incompletion remains 2, native findings remain 1, and Apply is refused.
This is an expected diagnostic outcome, not a failed preservation check.
Linux prerequisites were prepared in exclusively owned guests from signed Debian metadata: exactly ten new packages and three approved existing-package updates, verified before and after installation. SDK/Hugo/module caches were provisioned separately and reused offline. Qualification runs as an ordinary user on ext4; cached inputs and all 212 source files’ bytes/full modes stay guarded. Optional tools/browser tests are not silently claimed on guests without those prerequisites: default unit skips retain their actual gating/not-applicable reasons, while all required pure top-level cases, the no-skip membership children, selected Hugo and signal cases must execute. Linux amd64 uses QEMU TCG on the ARM host and is explicitly emulated. Darwin amd64 remains an experimental archive: actual execution returned Bad CPU type (errno 86), with no Rosetta installation or claimed supported runtime. Windows is outside the declared scope.
The current Linux archive digests are ac883e54a1df0b820696279c63881ba75a00d279f507330128fe8d5aff59c52e
(arm64, 4,552,687 bytes) and 2dde43bf94ef35aac2111b07dcb9b2766fbf9f883fe39ccd646d14a98b94d734
(amd64, 5,034,668 bytes). The preceding 683daca0…33f224
archive digests c191383af21913be6940ec41be11755b3d985344bbc0f65cc3f5de16424a96a4
and 6531b27d889260afe804c1f49f37541fbae46e57b5d17a20178c28cb51968794
remain historical. Cross-compilation alone does not establish runtime
support. SDK/guest preparation failures, the first ext4 membership failure,
and earlier private host metadata/resources trials remain immutable evidence.
Local completion does not establish a commit, public release, consumer adoption,
hosted CI execution, deployment or public-site verification. Uninvoked E1–E4
extensions are separate inactive scope and do not hold finite R1–R8 completion
open.
Acceptance case ledger
This ledger combines the initial audit with accepted R1–R7 evidence and the qualified R8 candidate gates. Each full case stays open until its entire outcome is recorded; an accepted stage does not close later-stage scope.
| Case | Required outcome | Code or checker evidence | Status and missing decisive evidence |
|---|---|---|---|
| A01 | One oink.result/v1 JSON result; stderr logs; policy 1, required incompletion 2 |
Protocol/public R1–R8 commands, frozen owning tests and exact-binary CLI/API reports; unchanged result schema; current eight owning gates/Linux qualification plus unchanged-runtime carry-forward of the preceding corpus in #a18 | Passed supported current command scope; future added commands require their own evidence |
| A02 | Hugo resolves slug/url/permalinks/aliases, mounts, unlisted pages and language roots | Real PageFacts/manifest/custom-mount/translationKey fixtures; preserved ordinary artifacts; final consumer facts | R1 scope passed; later stage-specific use of those facts requires its own acceptance |
| A03 | Definite local missing routes fail; outside origin/path and declared external scope classified honestly | Actual rendered-reference fixture plus subpath/policy regressions and final real sites | Passed the required A03 scope; external availability remains explicitly unchecked |
| A04 | Filename, directory and translationKey; duplicate/missing/draft cases; strict/localized policy |
R2 translation engine, actual Hugo/public commands, final reports and numeric supplement | Passed R2 required scope |
| A05 | Absent record unknown; changed source/translation hash visible; no mtime inference | R2 hash/status/diff, public preview/apply and final reports | Passed R2 required scope |
| A06 | Real fences, inline code, shortcodes, HTML, attributes, unknown fields and protected text boundaries | R2 actual syntax/provenance fixtures, reviewed corpus and final reports | Passed R2 required scope; catalog and unsupported-source limits remain explicit |
| A07 | Acknowledged findings visible; new findings block per policy; required unavailable tools cannot pass | R2 baseline/public plans; R6 fake/actual protocol, missing/unsafe/offline/network-uncertainty and required-precedence fixtures passed | Supported scope passed; required unavailable/uncertain tools remain 2 |
| A08 | Post-check bytes invalidate manifest; provider uploads verified tree without another build | R3 manifest/export/tampering/public one-build tests; final ordinary-Hugo comparison and provider rehearsal | Passed R3 required local scope; provider upload not executed |
| A09 | Both CI templates; custom workflows preserved; permissions/variables/provenance and stale plan protection | R3 offline generation/bootstrap, public preview/apply/stale-input tests, custom workflow supplement and local rehearsal | Passed R3 required local scope; custom workflows remain unknown and unchanged; hosted CI not executed |
| A10 | Reject HTTP 200 fallback, wrong language/build, missing resource/canonical mismatch; incomplete timeout/auth/rate-limit | R3 explicit-network local HTTP and public result fixtures, including required identity absence | Passed R3 required fixture scope; public deployment and browser runtime not verified |
| A11 | All declared profiles/languages; target protection; ordinary Hugo; unknown editor settings retained | R4 24 ordinary Hugo/public profiles, full Starter authoring/editor flow, snippets, actual mounts, source identities, JSONC preservation and external schema reproof | Required supported R4 local implementation/corpus scope passed; documented unsupported editor inputs remain explicit |
| A12 | Readable diff and route comparison; dirty/workspaces/replacement/vendor; recovery/concurrency | Frozen actual-Hugo seven synthetic pinned cases, public upgrade, source/external guards, observed alias retarget and guarded partial rollback | Required bounded R4 local implementation/corpus scope passed; unknown redirects/multihost remain incomplete and no automatic config migration is claimed |
| A13 | Deleted B finds unchanged inbound A; translations/attachments/derived outputs; global full scope | R5 committed Git/actual Hugo deletion, alias-inbound, global/uncertain input and unavailable-baseline fixtures; exact-binary consumer reports | Passed required supported R5 scope; unavailable or unproven historical inputs stay explicit 2 |
| A14 | Candidate before apply; stale/hash/write failures preserve later edits; ambiguous references unchanged | R2/R4 shared safety, R5 full-mode/inventory moves and R8 regenerated intent/fresh-input candidate validation, guarded writer and stale/late-editor/attachment tests; current eight owning gates/Linux qualification plus unchanged-runtime carry-forward of the preceding corpus in #a18 | Passed supported R5 CLI and R8 CLI/Studio editing scope; ambiguous or unavailable required inputs still block |
| A15 | Workspace/direct parity; selected writes only; bounded context with paths/versions/reasons; no content execution | R5 bounded captured-source/context fixtures and four-site queries; R6 registry/direct/aggregate parity and explicit-name saved apply with other sites preserved | Supported context/workspace scope passed; no implicit batch writes |
| A16 | Five useful CLI-parity views; keyboard/mobile/light/dark; source/preview isolation | Accepted R7 evidence retained; historical source-bound R8 read-only 14 axe/screenshots and Editor 12 axe/screenshots with unchanged UI bytes; current backend gates, ARM and corpus separately verified, native/API parity, preview isolation, four consumers and canonical render passed; current eight owning gates/Linux qualification plus unchanged-runtime carry-forward of the preceding corpus in #a18 | Passed supported local views; required partial-preview incompletion/native findings remain visible; no universal browser/platform claim |
| A17 | No-op bytes; YAML unknown/comment/order preservation; stale-save and attachment collisions rejected | Corrected frozen core/public/guarded-writer race, actual Hugo/tools, source-bound Editor/read-only browsers, exact-binary four-consumer proposal parity/preservation and guarded canonical source/render passed in #r8; current eight owning gates/Linux qualification plus unchanged-runtime carry-forward of the preceding corpus in #a18 | Passed supported local editing scope; required partial preview/native findings still block Apply; final A18 separate |
| A18 | Actual declared macOS/Linux runtimes; child signals; provisioned offline runs; honest unsupported inputs | Current freeze/source and repeated five-archive reproduction; Darwin arm64, native Linux arm64 and emulated Linux amd64 nonroot ext4/full offline unit-vet/selected Hugo/native archive/signal smokes passed in #a18 | Passed current declared runtime/archive scope; optional guest prerequisites remain explicit skips; Darwin amd64 is experimental/unverified and Windows outside scope |
Candidate sites and source preservation
The selected acceptance inputs are the embedded Starter plus three distinct maintained consumer sites. They reuse the historical corpus without writing consumer sources. The Starter source checkout is provenance input; generated profile trials use disposable directories.
| Input in the sibling checkout layout | Initial observed identity and purpose | Current candidate acceptance |
|---|---|---|
oink-starter / generated Starter |
Source 137843b, two initial status entries; licensed fixed archive, language/profile/root/subpath trials |
R1 bilingual init/check and R4 all-profile ordinary/public authoring flows passed; archive/license unchanged |
oink.pgsty.com |
Source 907d873 with existing changes; bilingual documentation/regression and explicit local-theme trial |
Final R1 check and source preservation passed; local-theme evidence remains distinct from public-pin evidence |
pig.pgsty.com |
Source 75050c0, five initial status entries; root Docs/Blog rewrites and nonrendering sidebar entries; declared v1.1.0 |
Final R1 check and source preservation passed |
repo.pgsty.com |
Unborn main, no HEAD revision; materialized untracked sources, generated catalog and declared v1.1.0 |
Final R1 check and source preservation passed; revision remains unknown |
For each run, record effective module source and versions, flags/network policy, exit/result/coverage, raw evidence location, and preservation outcome. Before/after inventories must include all tracked and non-ignored untracked source bytes and modes, Git status/index state, workspace/replacement files, and effective vendor inputs. Compare exact inventories; unchanged file counts alone do not prove preservation. Keep reports, isolated candidates, output and caches outside consumer sources and outside Git. Full-build timing comparisons must use the same current input baseline before any incremental speed claim.
Owning checks and documentation gate
Start with the smallest affected Go packages and public behavior tests. The
existing repository gates are make test (offline tests and vet) and
make test-hugo (actual Hugo Starter, snapshot, manifest and public command
fixtures). The owning Hugo gate now runs all owning packages without the old
narrow test-name filter; new fixtures must remain in that gate.
Use a race run for concurrent plan/server changes when the focused tests justify
it. Unit fixtures remain offline; networking requires explicit invocation.
For documentation, preserve EN/ZH heading number, order and stable explicit IDs. The narrow source checks are:
Both source checks passed after adding this record and its Chinese peer: eight Chinese research files passed the style checker; translation source coverage was 137/137 pairs with 1,082 source headings. These checks establish source style, pairing and explicit translated IDs only. Rendered acceptance was not run by this documentation audit.
After building the relevant site, complete the rendered documentation gate:
make build validates the declared published pin. make check selects the
sibling theme for the complete non-browser regression suite; these inputs
cannot substitute for one another. Studio requires its own actual browser and
accessibility acceptance. A passing prose source check does not prove rendered
bilingual output or Studio interaction.
Delivery state and remaining limits
| State | Current completion evidence; history retained above |
|---|---|
| Local implementation | Finite R1–R8 supported implementation completed locally, including Studio/read-only and opt-in reviewed editing; current A18 runtime/archive scope passed. Canonical lifecycle rendering is bound separately to these exact bytes |
| Local validation | Historical R1–R8 owning/browser/corpus/render records retained; current 2026-10-04 backend correction and eight current owning gates, actual three-target runtime/archive checks and unchanged-runtime carry-forward of the preceding four-consumer preservation/parity passed in #a18. Required repository findings/partial preview remain visible. Rendered navigation/URL checks have a separate exact-byte receipt boundary |
| Commits | Baseline CLI commit identified; no maintenance commit established by this record |
| Archive and runtime qualification | Current corrected source: Darwin arm64, native Linux arm64 and QEMU-TCG-emulated Linux amd64 passed installed archive/offline/signal/filesystem flows; two fresh builds reproduce all five archives. Darwin amd64 remains experimental/unverified after actual failed execution |
| Public distribution and consumer adoption | Not performed by this work |
| Deployment and public-content verification | Not performed by this work; local HTTP fixtures can prove the verifier without cloud credentials |
The finite R1–R8 implementation and required current A01–A18 runtime/archive scope have decisive local evidence. Canonical lifecycle rendering requires a separate receipt for these exact new documentation bytes; preceding rendered evidence does not qualify them. Uninvoked E1–E4 and experimental/unsupported platforms do not add unfinished core requirements. Publication, pushing, deployment, hosted CI and consumer writes remain separate unperformed actions; known repository findings and required preview incompletion remain diagnostic limitations, not hidden successes.
10 - CLI acceptance snapshot, 2026-09-29
The local 0.1.0-dev implementation passed the checks recorded here. The CLI
source is committed as e623d93; public publication, downstream adoption,
and production deployment remain separate and have not been performed.
Inputs and method
The CLI lives in the independent oink-cli Go repository. Its accepted
boundary is the CLI and result contract, with
reproducible user steps in the usage guide. Hugo remains an
external renderer; generated sites contain normal Hugo inputs.
| Input | Observed baseline |
|---|---|
| Host | macOS, darwin/arm64 |
| Go | go1.27.1 |
| Hugo | 0.166.0+extended+withdeploy |
| CLI | 0.1.0-dev, local commit e623d93d589c49e5c58b8fae1bd5db720fc904cb |
| Embedded Starter | Commit 137843b25bacd76ddd1f7ce71330bf2e3155b954, complete licensed Git archive |
| Generated theme pin | Public github.com/pgsty/oink v1.1.0, with recorded Go checksums |
| Documentation-site theme | Local theme HEAD b0af631 plus uncommitted changes; this is not the public module’s byte identity |
The Starter archive hash is
e55bde279715f6d8d19d3d88671a2cf7561b515be46915b0f12c640d0ce1d958.
Its recorded projections select an existing language profile, pin OINK v1.1.0,
and set enableGitInfo: false for a new directory. The last projection was
required by an observed failure: the original enableGitInfo: true caused a
warning-strict build to fail before the site’s first Git commit. No Git
repository or commit was created to hide that failure.
Checks used disposable source copies, module/render caches, and output directories. Original Starter and consumer source trees were not written by the CLI checks. Existing unrelated theme and documentation edits were retained. Counts below are snapshots of those inputs and CLI revisions, not thresholds that later documentation edits must preserve.
Starter and ordinary Hugo
All six ordinary-Hugo cases passed --environment production --panicOnWarning, with provisioned modules and isolated caches:
| Language profile | Root URL | /manual/ subpath |
Reported Hugo pages |
|---|---|---|---|
en |
Passed | Passed | EN 90 |
en,zh |
Passed | Passed | EN 91, ZH 89 |
all |
Passed | Passed | EN 91, ZH 89, FR 89 |
The tests checked expected language roots and representative Docs, Blog, and
Book outputs, and compared generated source bytes before and after Hugo.
The public CLI’s init command also passed separately for all three profiles,
with zero diagnostics and 94 generated source files per profile. The three
profiles differ in the selected root configuration; untranslated sample files
remain in the snapshot and are disabled through the existing profiles.
Starter package unit, race, and vet checks passed. Its failure cases exercise nonempty and symlink targets, validation failure, target replacement after planning, cancellation rollback, concurrent modification/deletion, and archive path rejection. The regeneration script reproduced the fixed archive, provenance, and license exactly.
Real-site inspection snapshot
Each run below returned CLI exit 0 with zero recorded diagnostics. Counts
describe rendered artifacts and inspected references; they are not counts of
authored pages or independent users.
| Site shape and theme source | Files | HTML files | References | Machine artifacts |
|---|---|---|---|---|
Three-language Starter, public v1.1.0, release check at /manual/ |
316 | 142 | 7,042 | 6 |
OINK documentation/regression site, local theme HEAD b0af631 plus dirty changes |
1,127 | 506 | 72,562 | 8 |
| PIG project site, root Docs/Blog route rewrites, public v1.1.0 | 1,392 | 424 | 64,440 | 4 |
| Repository documentation with generated catalog, public v1.1.0 | 3,287 | 1,635 | 851,535 | 12 |
The last three are distinct local consumer repositories. PIG and the catalog site validate published-pin resolution. The OINK documentation run validates the explicitly selected local theme changes; it cannot be substituted for a public-pin or deployed-site acceptance result. Source instructions were read before these read-only pilots.
The inspection covered the implemented HTML link/anchor/resource and emitted machine-artifact checks. It did not execute JavaScript, check external URLs, inspect hosting redirects, or perform browser, accessibility, and visual acceptance. The completed Hugo manifest enumerated 261, 766, 662, and 3,192 output declarations respectively. Every supported enabled machine output was required by its actual language and URL. Before/after manifests compared all tracked and non-ignored untracked source bytes, modes, and Git status: unchanged for all four sites (94, 415, 858, and 2,294 source files respectively).
Two real regressions were fixed during this work. A NAVJSON template that
rendered only English had previously hidden the missing Chinese output; it now
returns policy exit 1 with the missing output location. PIG’s intentional
build.render: link sidebar entries were initially mistaken for missing pages;
Hugo’s effective build parameters now exclude them, with direct and cascaded
regression cases. A paired build of the bilingual Starter also proved all 223
ordinary artifacts byte-identical before and after adding the isolated probe.
Offline execution and upgrade
On macOS, a full check of an initialized bilingual Starter passed under
sandbox-exec with (deny network*), after dependency provisioning. The
result was exit 0, zero diagnostics, 223 files, 95 HTML files, 4,461
references, and four machine artifacts. A separate English init also passed
under the same OS-level network denial, returning exit 0, zero diagnostics,
and the expected 94 generated files. These are executed network denial tests
for those operations, not Linux firewall tests or evidence for every possible
consumer’s remote-resource workflow.
A cold-cache fixture requiring example.invalid/[email protected]
returned CLI exit 2 and retained Hugo’s original
module lookup disabled by GOPROXY=off evidence. A missing dependency was
therefore reported as incomplete work, without silently enabling resolution.
A separate temporary site exercised a real public-module upgrade from v1.0.0 to v1.1.0. The original consumer was not used as a write target:
| Operation | Observed result |
|---|---|
| Preview | Exit 0; candidate validated; applied: false; plan named only go.mod and go.sum |
--write --expect-plan |
Exit 0; the matching plan was validated and applied |
| Repeat the same target version | Exit 0; candidate validated; no proposed changes and applied: false |
Unrelated dirty README.md content and untracked user-note.txt survived all three operations. The preview and
write shared the same plan ID and before/after module-file hashes. This proves
the exercised single-site path; it does not establish vendor refresh or an
upgrade performed by an independent user. Replacement, workspace, dirty-file,
rollback, and failure-protection cases passed the final focused Go tests and
race run. Only go.mod and go.sum changed on write; backup manifests retained
original bytes. Preview and repeat executions preserved all source bytes.
Real thin-wrapper smoke tests also passed in a disposable initialized site.
build --json returned 0 and produced index.html. dev --json served HTTP
200, forwarded SIGINT to Hugo, and closed the listener. Hugo exited 0; the
cancelled wrapper reported 2 under the documented cancellation semantics.
These runs used provisioned local caches without --network.
Final make test (all packages plus vet), make test-hugo (ordinary Hugo,
workspace/config precedence, output manifest, missing-language regressions),
and go test -race ./... passed. All three public init profiles were rerun
under OS-denied networking; the cold dependency fixture again returned 2.
Archive and installation preparation
One frozen CLI source snapshot produced four binary archives and one source
archive, plus SHA256SUMS. Rebuilding independently from the source archive
produced the same SHA-256 values for all five archives. The tested packaging
input hash was:
This final snapshot supersedes the intermediate archive experiments. All five
archive checksums were verified and reproduced from the extracted source
archive. Both source and binary archives include the versioned JSON schema,
licenses, dependency pins, and Starter provenance. Local make install into
a temporary prefix and the installed binary’s --version succeeded.
| Target | Evidence |
|---|---|
darwin/arm64 |
Compiled; host binary executed; local installation path exercised |
darwin/amd64 |
Cross compiled only; not executed on that architecture |
linux/amd64 |
Cross compiled only; not executed on Linux |
linux/arm64 |
Cross compiled only; not executed on Linux |
The archive builder records toolchain, flags, source-input hash, and platform limits. It prepares local files only. There is no public download URL or published installation tag established by this test.
Reproduce the relevant checks
From a CLI checkout with dependencies already provisioned:
To repeat rendered-site checks in the sibling layout, keep JSON and logs outside each consumer’s source tree:
On a macOS host providing sandbox-exec, after initializing a bilingual site:
The upgrade guide describes preview, plan review, and explicit application. Use a separate review copy for write-path testing. For the archive experiment, keep the same Go toolchain and release version:
Limits and delivery state
| State | At this snapshot |
|---|---|
| Local implementation | Six first-stage commands and versioned result format exist |
| Executed validation | The runs described above passed for their recorded inputs |
Owning checks and documentation-site make check |
Passed after implementation and bilingual-document updates |
| Commit, tag, push | CLI committed locally as e623d93; no tag, remote, or push. Documentation changes remain local alongside existing work |
| Public CLI release or distribution | Not performed |
| Consumer source adoption or production deployment | Not performed by these checks |
| Independent-user study or adoption | No measured 4-of-5 / 15-minute study, retention, or independent-team adoption data |
Raw JSON, logs, source-preservation manifests, upgrade recovery evidence, and
archive-verification results are retained locally under the CLI checkout’s
ignored tmp/acceptance/; archives are in dist/first/. They are local evidence,
not published downloads. No browser suite was run because this delivery changes
CLI behavior and prose, not theme presentation or interaction.
No Docsy conversion is implemented in this first-stage candidate. The pilots above already use OINK and cannot validate arbitrary Docsy or MDX migration. The roadmap retains bounded Docsy assessment and later migration, theme descriptor, version lifecycle, OpenAPI, MCP, and Studio as separate proposals. No future capability is accepted or counted complete by this local evidence record.