Skip to content

CLI maintenance acceptance on 2026-10-03

Dated source and binary evidence for the R1–R8/A18 local implementation program, preserving its initial audit, failed trials, and final supported acceptance scope.
Historical source and binary evidence

This record preserves earlier R1–R8/A18 acceptance. Command changes do not rewrite those results. The reduced CLI and its Cobra/text/JSON/YAML interface on 2026-10-04 are defined by the current contract and guide. Earlier runtime qualification does not qualify a changed binary automatically.

Finite implementation locally validated

The initial audit is retained below. R1 implementation and owning checks have passed their local scope, including refreshed consumer reports and scoped rendered EN/ZH acceptance. R2’s scoped local gate is also accepted, with a separately tested numeric-equality supplement. R3’s runtime and paired documentation gates have passed and its local stage is accepted. R4 supported implementation and read-only corpus gates have passed locally; guarded canonical documentation validation is recorded separately below. R5 corrected implementation/read-only corpus and guarded canonical documentation gates have passed; its supported local scope is accepted. R6 explicit workspace and optional adapters passed frozen owning/runtime, exact-binary consumer and guarded canonical source/render gates; supported R6/A07/A15 scope is accepted locally. R7 read-only Studio/A16 also passed its browser, four-consumer and guarded canonical rendered gates. R8 reviewed editing/A17 passed its corrected frozen owning/browser, exact-binary consumer and guarded canonical source/render gates. R1–R8 supported scope is accepted locally. The 2026-10-04 supplement refreshes the changed backend and closes current A18 runtime/archive qualification for the three declared targets. Canonical lifecycle promotion/render has a separate exact-byte receipt boundary; public release, adoption and deployment have not occurred.

Scope and evidence rules

The maintenance roadmap defines the authorized R1–R8 scope. The current CLI contract defines its compatibility baseline; the original roadmap does not add Docsy migration, version lifecycle, OpenAPI, theme publication, or the conditional E1–E4 extensions to this program. Hugo remains an external renderer and generated sites remain ordinary Hugo projects.

Stages are accepted in dependency order. Every stage needs a complete usable flow, its owning tests, relevant actual Hugo integration, known limits, a reviewable diff, and accepted EN/ZH contract and guide updates. Passing an aggregate command alone does not close a case. New public behavior moves from the proposal into the owning contract only after its implementation and acceptance evidence exist.

In the tables below, existing, not rerun means code or a named test was inspected but its current runtime outcome was not established. Partial means the first candidate provides a reusable part of the required behavior. Open means new implementation or decisive acceptance evidence is missing. Passed, failed, unverified, and unsupported must describe a specific executed input and scope when later runs are recorded. No historical result is relabeled as a current pass.

Inspected inputs and tools

The initial 2026-10-03 audit read both repositories’ instructions, the documentation README and translation rules, both maintenance PRD languages, the original proposal, the current CLI contract, and existing Go packages and test names. It executed version and Git inspection commands only; it did not run the owning suites or write consumer sources.

Input Observed initial state
Host and Go darwin/arm64; go version go1.27.1 darwin/arm64
Hugo hugo v0.166.0+extended+withdeploy darwin/arm64, Homebrew build dated 2026-09-09
Node and npm v26.9.0; 11.19.1; contributor/documentation tools, not CLI consumer requirements
Git 2.54.0 (Apple Git-157)
CLI source e623d93d589c49e5c58b8fae1bd5db720fc904cb, main; clean initial tracked/untracked status; generated bin/, dist/, tmp/ ignored
Documentation source 907d873eb05cfc2e194f492462dfa94849e93474, main; 184 initial porcelain entries, including existing proposals, contracts, guides, and unrelated content changes
Embedded Starter 137843b25bacd76ddd1f7ce71330bf2e3155b954; provenance and license already recorded by internal/starter
Declared theme baseline github.com/pgsty/oink v1.1.0 in Starter and the three selected sites; effective resolved bytes still require each acceptance run

The 2026-09-29 acceptance record contains historical first-candidate checks. It supplies useful reproduction inputs, but does not prove the new maintenance scope. Existing dirty files are preserved; this initial research addition does not accept or overwrite them.

Stage requirements and implementation evidence

Stage Required complete flow and invariants Initial implementation evidence Acceptance evidence still needed
R1 Shared page identity, languages, publication state, source provenance, actual outputs, translations and observed references from Hugo; oink.yaml owns check policy only; links/translations/style share analysis; severity and exclusions cannot hide required incompletion; trustworthy locations Partial: internal/site isolated snapshots and Page.OutputFormats probe, internal/outputcheck, internal/report; no shared translation/page facts or policy commands at initial audit Real Hugo routes, aliases, mounts, unlisted/generated-source cases and language relationships; public focused-check/policy cases; required unknown/tool/build/input failures remain 2; source locations only when reliable
R2 Three language layouts; strict/manual and localized policies; duplicate, missing and draft states; explicit versioned review records bind source language and source/translation hashes; bounded native syntax rules; effective-theme coverage; visible versioned baseline; reviewed fixes validate before narrow apply Open: no translation/review/native-rule/baseline public command at initial audit; rendered-reference checks remain reusable A04–A07; valid/invalid reviewed content corpus; no mtime review inference; disabled/localized languages handled; acknowledged findings stay visible; missing required checks stay incomplete; fix preservation
R3 Preserve thin default build/dev; build --check checks and manifests one strict Hugo output, exports only to new/empty target; digest/provenance manifest and optional minimal public identity; both local CI templates upload the same tree; release diagnosis; explicit-network public verification Partial: direct wrappers, strict isolated checks and licensed workflow inputs exist; managed build/export, digest verification, CI plans and public verify are absent at initial audit A08–A10; exactly one Hugo build; stale-byte rejection; revision/dirty/input/theme/tool/settings/coverage provenance without secrets or machine paths; workflow customization/conflicts/provenance and immutable source input; example address policy; fallback/language/resource/canonical/timeout/auth/rate-limit HTTP fixtures
R4 new, snippets and editor setup create ordinary inputs without overwrite; docs/blog/book/project profiles compose one licensed Starter; upgrades provide readable diff and old/new routes, aliases and enabled outputs; unsupported migrations give manual action; existing protections survive Partial: fixed archive language profiles and hash-bound single-site module upgrade with candidate validation, backups, dirty/workspace/replacement/vendor protection A11–A12; all new profile/language combinations build with ordinary Hugo; unknown editor settings retained; upgrade route/capability regression and readable diff; source provenance and licenses retained
R5 inspect, impact --since, bounded context, preview move; shared plans include touched files, diff, base hashes, translations, attachments, output/route changes and alias advice; candidate validation and stale/concurrent-safe recovery; ambiguous references require review Partial: module-specific upgrade plan/apply primitives; no shared content plans or inspect/impact/context/move flow at initial audit A13–A15; deleting B includes unchanged inbound A; translation/attachment/derived-output impact; uncertain/global changes force full checks; no content execution; candidate/stale/failed-write preservation and ambiguous-link handling
R6 Explicit versioned site registry reuses single-site engine; per-site and aggregate completion; writes only to selected sites; configured preinstalled markdownlint/Vale/lychee adapters normalize findings and declare syntax/network coverage Open: no workspace/adapter public command at initial audit A07/A15/A18; direct/per-site parity; no sibling discovery, implicit installation or default formatting writes; required missing tool 2, optional omission visible, external network uncertainty distinct
R7 Read-only loopback Studio with overview, issues, translation comparison, page relationships and publication views; filters, known sources, actual Hugo preview, comparisons and copied actions; CLI parity; prebuilt assets; explicit allowlist, separate preview origin, Host/Origin/session protection Open: no Studio server or assets at initial audit A16; browser/keyboard/screen-reader/mobile/light/dark/long-list flows; same underlying results as CLI; unauthorized hosts/origins/sessions and preview-to-management requests rejected; Node unnecessary for consumer runtime
R8 Markdown/text and front matter forms, selected components and collision-safe attachments reuse plans; authorized allowed writes with visible diff, hashes and candidate validation; no-op bytes and unknown fields/comments/order/encoding/whitespace retained; unsupported form syntax stays text Open: editing follows accepted read-only R7; no editor API at initial audit A17/A14; byte-identical no-op, surgical YAML field updates and text fallbacks; stale external-editor saves, traversal/symlink escapes and preview requests fail safely; attachments never overwrite; no management API in static publication

R1 local validation

R1 now provides shared Hugo page/translation/source facts, rendered reference and anchor evidence, strict oink.policy/v1 input, check links, --format json, visible reviewed exclusions/external scopes and required-work precedence. Translation and style selections explicitly return required unsupported coverage; they are not implemented engines. Default build/dev remain direct Hugo operations. The following evidence accepts the tested shared-facts/policy scope without closing R2–R8 or the full A01–A18 cases.

Requirement Executed evidence Current outcome
Public result/policy and incomplete precedence make test: all packages and vet; public severity/exclusion/unimplemented-group/JSON-alias tests; TestEveryRequiredUncompletedCoverageFails Passed R1 scope; any required uncompleted status, including not_checked, remains 2
One build and shared facts TestPublicCheckSharesOneBuildAndRenderedFacts Passed; one strict Hugo build supplies page and observed target/anchor facts
Hugo authority and source mapping Actual TestPageFacts* fixtures: translationKey, actual routes/aliases, unknown generated nodes, custom mounts, excluded-page analysis and failure preservation Passed; separate analysis preserves production facts/artifact bytes and source bytes/modes
Repeatable real Hugo gate Corrected make test-hugo includes TestPageFacts* and TestHugoRendered*, alongside Starter and manifest fixtures Passed; scoped route/reference, reviewed external-scope and original-output preservation cases
Fresh Starter Bilingual init, check links, ordinary strict Hugo using isolated provisioned v1.1.0 module archives Exit 0; 223 files, 4,461 references, 66 page facts; dependency preparation remains explicit
R1 documentation source and schema Markdown style under content/docs; bilingual source checker; JSON parse and equality of CLI/docs result schemas; scoped diff whitespace check Passed: 88 Chinese docs, 137/137 source pairs and 1,085 headings; schemas remain additive oink.result/v1 with exits 0/1/2
Final candidate reports and rendered EN/ZH Refreshed current-binary consumer reports; actual rendered source/Markdown/link owning checks below R1 scoped gate passed; existing draft-release omission in production is recorded separately

Earlier offline R1 trials returned 0 without diagnostics on three consumers:

Earlier trial Source files Built files HTML files References Page facts Bytes/modes/Git inventory
OINK documentation 421 1,139 512 74,689 341 Exact before/after equality
PIG project site 858 1,392 424 64,440 248 Exact before/after equality
Repository catalog 2,294 3,287 1,635 851,535 1,572 Exact before/after equality

These earlier reports spell optional unselected coverage not_selected, outside the existing result-schema enum. The final code corrects it to not_checked and includes project.pages coverage. Their measured counts and exact inventories remain valid earlier-binary observations; final JSON conformance is established by the final reports below. Raw evidence stays in task-named local acceptance directories outside consumer sources. These trials do not prove external availability, deployment, Linux runtime or translation/style acceptance.

The final R1 binary was rebuilt from the dirty CLI working tree based on e623d93d589c49e5c58b8fae1bd5db720fc904cb. The recorded input inventory includes file hashes, modes and Git-status identity. Its SHA-256, computed over sorted JSON serialization, is 518260f07f3c916468ee3d56c4eeca03c131514155aa82539564ccd2f3c1f664. The exercised binary SHA-256 is 3deb7e357fc86f6907df60da0769d93f2d41ba5e01949b641548a67d7f459d12. This identifies local inputs and an executed binary, not a maintenance commit, public archive or published module.

Final current-binary trial Source files Built files HTML files References Page facts Acceptance
OINK documentation 421 1,139 512 74,755 341 Exit 0, valid result, complete page facts, exact source bytes/modes/Git preservation
PIG project site 858 1,392 424 64,440 248 Exit 0, valid result, complete page facts, exact source bytes/modes/Git preservation
Repository catalog 2,294 3,287 1,635 851,535 1,572 Exit 0, valid result, complete page facts, exact source bytes/modes/Git preservation

Each final result has check.links: complete and project.pages: complete, both required. Unselected translation/style coverage is not_checked, optional. The final offline make test and vet passed; the corrected actual-Hugo owning target also passed. The recorded tools remain Go 1.27.1, Hugo Extended 0.166.0, Git 2.54.0 on macOS arm64. The three exact before/after inventories were independently compared while preparing this record.

Production output passed rendered Markdown and link checks. Its global translation checker returned 1 solely because the pre-existing draft content/blog/release/1.2.0.md / .zh.md pair is correctly absent from production. The changed R1 pages rendered in both languages. A separate explicit analysis build with HUGO_BUILDDRAFTS, HUGO_BUILDFUTURE and HUGO_BUILDEXPIRED set to true passed all three owning checks: 137/137 paired sources, 1,085 headings, rendered Markdown and rendered links. That view is nonpublishable evidence for excluded sources; it never replaces production output and does not change or publish the draft. No existing draft file was modified to make the global production checker green.

R2 local validation

The local candidate now implements translation policy/status/diff/hash review, syntax-bounded native content rules, visible reviewed baselines and shared oink.plan/v1 preview/validate/apply. Default check requires links, translations and style. Production output and the explicit draft/future/expired analysis are separate; the latter is not publishable. Stable behavior and examples are in the contract and guide. The R2 local gate passed owning checks, final frozen-input consumer reports and rendered bilingual documentation. The exact exercised binary and the subsequent narrow equality fix are recorded separately below; no public release or consumer write is implied.

Requirement Executed owning evidence Outcome and limit
A04 translation relationships/policy Actual TestHugoFilenameDirectoryAndTranslationKeyLayouts; scope, duplicate/missing/disabled-language, draft, strict/localized and selected-constraint tests Passed owning tests; no universal heading/code/localization parity
A05 explicit review and diff Full byte hash/current/source/translation/both-changed, mtime-independent, unknown/unreadable/ambiguous and malformed-record tests; public status/diff/review preview/apply fixtures Passed owning tests; review state is change evidence, not semantic judgment
A06 source boundary and provenance Actual Hugo enabled/disabled canonical title/block attributes and configured passthrough fixtures; front matter/CRLF/BOM/shortcode/code/HTML tests; every public v1.1.0 source/license SHA verified Passed owning tests; unsupported syntax remains incomplete and custom hooks remain outside catalog attestation
A07 baseline scope Capture/visible acknowledgement/new finding/incomplete precedence and malformed-record tests; public baseline preview/apply fixtures Passed R2 baseline scope; external tool adapter acceptance belongs to R6
A14 shared metadata plans Stale bytes/modes/existence/guards; edits during validation; exclusive commit collision; partial restore; later editor bytes/modes/deletion; old open inode write; new-directory children; confinement/identity/diff tests Passed owning tests and vet; candidate/source overlap refused; later move/reference ambiguity remains R5 scope
Frozen runtime gates macOS arm64 make test/vet, owning actual Hugo and focused race runs Passed; logs /tmp/oink-r2-frozen-go-gate.log, /tmp/oink-r2-frozen-hugo-gate.log, /tmp/oink-r2-frozen-race-gate.log; final all-owning-package Hugo gate /tmp/oink-r2-owning-hugo-final.log explicitly includes configured passthrough
Bilingual documentation Narrow source style/pairing/IDs, equal result schemas, scoped whitespace and actual production/analysis node checks Passed scoped gate: 88 Chinese docs, 137/137 source pairs and 1,092 headings; production draft omission separately recorded below

The frozen parser corpus at /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r2-source-corpus-lqx25kwr/summary.json records parser input SHA-256 a601200ec4fe275d2bd4baf11d4db7d46a2cc6f1674900c1fd801769e55d12de. Each scope parsed completely with zero findings. The core uses actual Hugo site-source identities from the recorded configuration; supplemental Markdown includes disabled/unpublished files and does not invent routes or relationships. These captures precede the authorized R2 documentation edits.

Corpus Unique actual Hugo source files Supplemental local Markdown Source inventory files Bytes/modes/Git
Starter 52 78 97 Exact before/after equality
OINK documentation 272 274 421 Exact before/after equality
PIG 212 212 858 Exact before/after equality
Repository catalog 1,568 1,572 2,294 Exact before/after equality

Preliminary public-command reports at /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r2-final-qu_zprps/summary.json used binary c8d87e6d73d3101fefcb62c5d6845518573c02c400f474dc9f4603afafc774d5 and CLI input inventory d8a75be0e074365a4164b7aaaa27d82a1e844e04406a36c3dd6d39ff2b6e873f. They precede the final parser/doc freeze and are not final acceptance evidence. The initial Starter invocation selected the enclosing evidence folder and returned 2; it was a validation setup error. Selecting its actual site child returned 0, with evidence in /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r2-starter-27vmi0w5.

Preliminary check Exit Page facts Built files References Translation statuses Outcome
Correct Starter child 0 66 223 4,461 28 Complete; 97 source files/inventory unchanged
Documentation 0 341 1,139 74,755 144 Complete; 421 source files/inventory unchanged
PIG 0 248 1,392 64,440 120 Complete; 858 source files/inventory unchanged
Repository catalog 1 1,572 3,287 851,535 788 Completed policy check: 10,462 actual HTML_ID_DUPLICATE findings in existing merged-print output; 2,294 source files/inventory unchanged

The repository catalog result is a completed finding outcome, not a passing site or implementation failure. No policy was weakened and no consumer source was changed. Informational review states remain visible.

The final frozen-input reports at /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r2-candidate-6xzcs7fk/summary.json exercise binary SHA-256 ff88b407a6cddb9007f94275c65a80ed4c9c4fd13f5e821f9b7a4a8973abaa56 from CLI input inventory bd8c71b55250a89dc15c7534924bb82a5447d6f2628eba23c8cb3d864309ee9f. All four exact source byte/mode/Git inventories were independently compared equal before/after. These reports supersede preliminary public-command trials:

Final check Exit Source files Page facts Built files References Translation statuses
Starter 0 97 66 223 4,461 28
Documentation 0 421 341 1,139 74,825 144
PIG 0 858 248 1,392 64,440 120
Repository catalog 1 2,294 1,572 3,287 851,535 788

No final report has incomplete diagnostics. The repository catalog retains 10,462 actual merged-print HTML_ID_DUPLICATE findings and 788 informational review states; the other sites retain informational unknown review states. This accepts the tested checking behavior and source preservation, without calling that catalog a passing publication.

Kept production docs at /private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-site-2201601475/public passed rendered Markdown and links. Global translation checking returned 1 only for the existing draft release 1.2.0 pair absent from production. The separate explicitly nonpublishable draft/future/expired analysis at /private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-site-3698773232/public passed all three node checks: 137 pairs/1,092 headings, 216 content pages/41,586 text nodes, and 347 pages/48,682 internal links/4,171 fragments. Evidence logs are /tmp/oink-r2-docs-production-{translations,markdown,links}.log and /tmp/oink-r2-docs-analysis-{translations,markdown,links}.log. Neither analysis output nor authored draft replaced production or was published.

A final review identified optional equal_fields comparing JSON 7.0 with YAML/TOML numeric 7 by representation. The narrow supplement now normalizes decoded numeric values recursively to an exact rational number tag, preserving strings versus numbers, map keys and array order. Tests cover decimals/exponents, negative zero, integers beyond float64 precision, nested differences, source byte preservation and required incompletion for unrepresentable values. Actual-Hugo translation tests passed in /tmp/oink-r2-numeric-translations-gate.log; all public maintenance actual-Hugo cases passed in /tmp/oink-r2-numeric-public-gate.log; owning vet and whitespace checks passed. Supplemental source SHA-256 values are:

Source SHA-256
internal/translations/check.go 24664377e14b4ae2fc554d0d7fde2ec33cc987707250e130fd88d9a25d5e1637
internal/translations/translations_test.go f58f4a305fe9fe3f5500ddfcf85faf3cfa37d72f8c220a1cb16ce4ccfbddb74d

The frozen real-site reports and Linux qualification above/below predate this supplement. Those sites configured no numeric equality constraint, so their recorded outputs are unaffected and were not rerun for this narrow fix. Later full runtime and archive qualification must refresh the subsequent source. The evidence amendments here are authorized documentation writes after the acceptance runs; their before/after preservation scope ends before this amendment.

A18 remains open. macOS arm64 is exercised; an attempted Darwin amd64 runtime on this host failed with arch -x86_64 / posix_spawn: Bad CPU type in executable (/tmp/oink-r2-darwin-amd64-gate.log). This is unavailable host runtime support, not a code failure or Darwin amd64 acceptance. No system installation was made. Native Linux arm64 and Docker Desktop Rosetta-emulated Linux amd64 were both actually executed with the same runtime/schema/license input SHA-256 0f786df68ef3c4844c983a51595f79242d1cb1d2bf6c5b5eb7f2c6415fb8d861. Evidence is retained at /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-a18-linux-ajbbnvki in arm64-results, amd64-results, commands.json, candidate-inputs.json, preparation.json and qualify.sh. Each target passed 270 test/subtest cases, with no failures and two optional external corpus/provenance skips: full actual-Hugo go test ./..., vet, built CLI version/bilingual init/doctor/full check/translation status and missing-Hugo exit 2 smoke. JSON stdout and source byte/mode inventories were verified. Go 1.27.1 ran on Linux arm64; Hugo Extended 0.166.0 architecture assets were SHA-verified. This qualifies those source runtime paths, not final archives or hosted CI. Darwin amd64 remains open; cross compilation does not close it. Later stages and future command/adapter/browser acceptance remain open.

R3 local validation

R3 adds managed build --check, oink.artifact/v1 sealing/export/local verification, explicit-network HTTP verification, release diagnosis and guarded local CI generation. The default build/dev path remains ordinary Hugo. The executed runtime and paired contract/guide gates passed; R3 is locally accepted. Hosted CI and deployment were not executed.

Requirement Executed owning evidence Outcome and limit
A08 one checked artifact Public fake/actual Hugo one-renderer tests; exact export, manifest/marker, post-check byte/mode/missing/extra/symlink tampering, failure/concurrency and source-preservation tests Passed local scope; a failed/incomplete check cannot seal/export; local artifact verification does not rebuild
A09 both CI providers Offline deterministic generation, pinned source/Hugo archives and action revisions; safe bootstrap archives; guarded public preview/apply/stale-input cases; actual-Hugo original-input binding Passed local configuration scope; every existing generated target is refused and custom workflows remain unchanged
A09 upload identity Both local provider rehearsals and TestProviderUploadRehearsalPreservesActualSealedManifestIdentity Passed: one managed build, separate verification, then the same tree; GitHub tar includes the hidden marker, Cloudflare rehearsal receives that verified directory; no provider upload executed
A09 custom workflow diagnosis Generated-plus-other-custom and standalone-custom/no-metadata public tests, actual-Hugo preview and owning vet Passed supplement in /tmp/oink-r3-ci-custom-owning-gate.log and /tmp/oink-r3-ci-custom-vet-gate.log; each unrepresented workflow stays unknown, informational and optional release.ci: not_checked, including beside valid generated metadata
A10 deployed identity Local HTTP fixtures for all recorded files/routes/languages, marker, canonical/base/inert-template behavior, HTTP 200 fallback, wrong bytes/language/build, missing resources/Markdown/search JSON Passed local fixture scope; definite mismatches return 1; browser JavaScript is explicitly unchecked
A10 unknown network state Explicit network/credential refusal, timeout before headers/during body, authentication/rate-limit/server errors, required marker absence, bounded body/gzip and redirect/no-cookie fixtures Passed local fixture scope; incomplete states return 2 with remaining requests unknown; no public deployment was contacted
Frozen runtime gates Full tests/vet, owning actual Hugo and focused race checks Passed on macOS arm64 in /tmp/oink-r3-frozen-go-gate.log, /tmp/oink-r3-frozen-hugo-gate.log, /tmp/oink-r3-frozen-race-gate.log; the subsequent custom-CI change has the focused supplement above

The latest single-binary corpus is retained at /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r3-ci-final-ahc4csjk/summary.json. It compiled an exact captured CLI input copy, with binary SHA-256 425845c1d2db7b1cd3c3cdb5f28475cb06ba6f656054909759e2359a39925dd2, 67 runtime/schema/license inputs SHA-256 6789a3a0235ff8d81453b9bfde37824979eac7d56af3710da390e4d2ef8479dc, and 108 broader CLI inputs SHA-256 4ca473a4cb586d232baeb4cee029b281469c5bb03c831cc199b95451e6832c60. Runtime inputs remained exactly equal after all runs. Live tools were Go 1.27.1 and Hugo Extended 0.166.0 on Darwin arm64. The manifest’s normalized Hugo version excludes vendor build text and private paths.

Each run used offline build --check with fresh external destination/manifest paths, the optional marker and retained isolated work. These existing local consumer inputs were checked without --release; their configured workspaces were preserved. Every raw report records exactly one strict Hugo renderer, zero incomplete diagnostics and zero required unfinished coverage.

Final managed build Exit Source files Copied source inputs Page facts Built files References Exported files Local artifact verify
Starter 0 97 94 66 223 4,461 224 0
Documentation 0 421 427 341 1,139 74,825 1,140 0
PIG 0 858 861 248 1,392 64,440 1,393 0
Repository catalog 1 2,294 2,299 1,572 3,287 851,535 None Not exported

Both inventories compare exact bytes, modes and file types before/after; the primary inventory also compares logical Git state. Git sites include tracked and non-ignored untracked sources; the non-Git Starter includes its existing generated files and lock. The supplemental copied-source inventory also includes ignored workspace/editor metadata read by snapshots, excluding existing generated output/cache trees. Counts alone are not the proof. All four comparisons were exactly equal.

The repository catalog retains 10,462 existing merged-print HTML_ID_DUPLICATE findings, so neither destination nor manifest was created. This is a complete policy finding, not a passing publication or implementation failure. Production review states number 28/143/120/786; analysis includes unpublished pages, explaining the earlier R2 144/788 counts. Existing custom workflow information remains visible, and Starter’s example address is a warning in this non-release run.

The three fresh exports match the retained independent ordinary-Hugo trees in every original file’s SHA-256, size and mode. The sole extra file is .well-known/oink-build.json. Their original source inventories and complete manifest input hashes match the earlier capture, so reusing those ordinary trees does not substitute different inputs. The helper source SHA-256 is 13e4957a3d7847eb28c8b1eeba3588a4f4a9982c2bfca2ebc729ab2827159607; its binary SHA-256 is b2699fe7a7aa3a34c41f9e4aba4b22d39cf8d0c156a369f3dfc4ca8c8c0fbce5. Raw helper and ordinary evidence are in /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r3-candidate-wb643dhh; the temporary compilation source was removed after building the helper.

Earlier R3 captures remain historical: the first capture preceded runtime freeze; the first frozen capture at oink-r3-final-pisrr21h preceded custom-CI diagnosis. An initial /Users/vonng/pgsty/PIG selection returned 2 because that different repository is not the intended site; corrected pig.pgsty.com passed. Those setup trials are retained, not relabeled as candidate failures. This latest corpus supersedes their managed-build results. The CI templates/bootstrap are independently authored from recorded primary provider contracts; no provider implementation code was incorporated.

The scoped R3 documentation gate passed at /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r3-docs-render-pljj5aqd/summary.json. Ten paired contract/guide/roadmap/index/overview edits were installed only after matching their original bytes/modes; recorded hashes are at /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r3-doc-drafts-s0b3g48l/applied-files.json. Source style passed 88 Chinese docs; translation coverage passed 137 pairs and 1,099 headings; schemas remained equal and scoped whitespace passed. Actual production Markdown passed 214 pages/41,871 text nodes; links passed 345 pages/48,344 internal links/4,171 fragments. Production translations returned 1 only for the unchanged draft release 1.2.0 absent from production. A separate explicitly nonpublishable draft/future/expired analysis passed Hugo and all three owning checks: 137 pairs/1,099 headings, 216 pages/42,177 text nodes and 347 pages/48,720 links/4,199 fragments. All 421 canonical and 488 copied source files retained exact bytes/modes throughout these rendered checks. Analysis was not published and did not replace production. This acceptance amendment follows that frozen preservation boundary.

This gate does not claim hosted workflow execution, uploads, publication, minimum-version combinations, browser behavior or current Linux/Darwin amd64 qualification. A18 remains open; historical Linux R2 results retain their original source hash. Authorized bilingual evidence/contract/guide writes occur after these preservation inventories and are outside their no-write scope.

R4 authoring and upgrade acceptance

The supported R4 implementation and read-only corpus scope are locally accepted after frozen owning/full gates. This record covers profiles, ordinary authoring/editor/snippets and bounded upgrade views. Guarded canonical documentation promotion and fresh scoped rendered validation also passed as recorded below; R5–R8 and final A18 qualification stay open.

Executed profile evidence Outcome and limit
One fixed licensed archive Snapshot verification against commit 137843b25bacd76ddd1f7ce71330bf2e3155b954 passed without --write; archive SHA e55bde279715f6d8d19d3d88671a2cf7561b515be46915b0f12c640d0ce1d958 and MIT license unchanged; projection metadata/script match
Composition and preservation Default/explicit project byte parity; selected archived model/localized home, invalid profile, nonempty target, concurrent validation/publication and cancellation recovery tests passed; unit/vet/race gates passed
Ordinary Hugo All four profiles × three language choices × root/subpath passed 24 actual warning-strict offline builds using provisioned public OINK v1.1.0; complete source byte/mode/no-extra-file and rendered-reference checks passed
Public init workflow Four profiles with en/en,zh, actual subsequent root/subpath Hugo URL facts/checks, workflow/license preservation and default parity passed; unknown/nonempty refusals 1, missing/failed Hugo 2, empty/absent targets and pure JSON/separate logs verified
Public authoring and source identity Actual candidate/apply/ordinary Hugo, review-unknown and source preservation passed in /tmp/oink-r4-authoring-public-gate.log; fresh-directory/site guards and vet passed in /tmp/oink-r4-new-input-race.log and /tmp/oink-r4-public-core-vet.log. Actual ignored input refuses 2 without a saved plan or source writes even when source groups are disabled; selected draft peers still force analysis identity in /tmp/oink-r4-authoring-sourceproof-gate.log. Supported owning scope passed
Bounded upgrade owning gate Seven actual-Hugo synthetic pinned module-fixture cases, observed-stream digest/inventory fidelity, independent cross-page alias-retarget blocking, source/concurrency/exclusive installation and later-edit rollback protection passed under race; vet passed. Final hardening logs /tmp/oink-r4-hardening-owning-gate.log, /tmp/oink-r4-hardening-final-focused.log, /tmp/oink-r4-hardening-vet.log; final public/full frozen gates passed
Integrated authoring/editor hardening Actual-Hugo language-directory plan/apply/ordinary builds, link/never new-source refusal, external schema/license/full-mode/module identity and legacy schema reproof, shared translation/baseline/CI regression and full Starter docs→new draft peer→editor→check→ordinary Hugo flow passed. /tmp/oink-r4-app-authoring-hardening-gate.log (58.241s), focused race and vet passed; post-candidate external mutation proof /tmp/oink-r4-app-external-during-validation.log passed. Opaque saved external-input hashes and canonical workspace-origin guards passed /tmp/oink-r4-external-plan-binding-final.log, /tmp/oink-r4-workspace-origin-gate.log and their vet logs. Frozen full-stage, corpus and scoped canonical rendered documentation gates passed
Actual language mounts Standalone ordinary per-language contentDir and explicit site-matrix fixtures each passed config/mounts/strict-render with source bytes/modes unchanged; Hugo0.166 emits sites.matrix.languages and distinct physical files with reciprocal public translations. /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r4-language-mounts-lgmve1sk/summary.json; public actual language-directory plan/apply/ordinary-Hugo integration passed

Owning evidence is retained at /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r4-starter-owning-0pv41lw5/summary.json. Logs are /tmp/oink-r4-starter-{unit,hugo,vet,snapshot,race}-gate.log and /tmp/oink-r4-public-init-gate.log, /tmp/oink-r4-public-init-vet-gate.log. Generated source counts are project 94, docs 58, blog 40 and book 34. No Starter checkout edits, release, consumer adoption or deployment occurred.

Final frozen gates all returned 0: make test/vet /tmp/oink-r4-frozen-go-gate.log, make test-hugo /tmp/oink-r4-frozen-hugo-gate.log and actual-Hugo core race /tmp/oink-r4-frozen-core-race-gate.log. The final public flow includes Starter docs → primary/translation draft → editor → check → ordinary Hugo; post-candidate external schema mutation still refuses before source writes. Seventeen owning and three final gate logs are retained verbatim with hashes in the final corpus’s owning-gates.json.

The exact four-site evidence is /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r4-corpus-lw2cjyq6/summary.json with bounded summary.compact.json, raw JSON/logs and per-command inventories. Binary SHA is c169b3d4d046c811dca80867068b86fb66ada5c8ce6910dd5cda7353c406f377; 82 runtime-input files bind SHA fdff7f50d49b44f03fa1db79eec6b6c9b9bd5e52f8967a88aed84b3207a7b3c6, which equals the final root inventory with no runtime changes. The broader 139 CLI inputs bind SHA 562e838d9eccb628eac86ae59b9b9587c1e23ad52991ec50eafb1e604e3924da. Driver SHA is d3ac41dc2e18295bfb26134d1a696935c8174913e2801a5766dbf7a1139d89f8. Actual tools were Go 1.27.1 and Hugo 0.166.0 Extended on macOS arm64.

Frozen consumer Primary/copied source files Pages; output files; references Managed build / artifact verify Read-only upgrade / new / editor
Starter 97 / 94 66; 223; 4,461 0 / 0; 224 exported files including marker 0 / 0 / 0
Documentation 421 / 427 341; 1,139; 74,937 0 / 0; 1,140 exported files including marker 0 / 0 / 0
PIG 858 / 861 248; 1,392; 64,440 0 / 0; 1,393 exported files including marker 0 / 0 / 0
Repository 2,294 / 2,299 1,572; 3,287; 851,535 Completed finding 1; no export/manifest Completed finding 1; new/editor not attempted after blockers

Each managed build used exactly one strict production Hugo render and had no required incompletion or uncompleted required coverage. Primary Git-visible source bytes/full modes/logical Git state, supplemental copied inputs and source directory modes matched exactly before/after every command and each complete site flow. Repo’s 10,462 existing merged_print duplicate HTML IDs remain visible; its completed finding is neither a passing artifact nor an implementation failure. No policy or consumer inputs were adjusted.

Consumer upgrade previews selected the available public v1.1.0 pin and did not apply writes. Cross-version route/alias/output regressions use explicit synthetic fixture pins, not an invented published theme release. New/editor plans were validated previews; no consumer plan was saved or applied. Multi-host and unknown relative-alias identities stay incomplete. Nondeterministic output may require a fresh v2 plan preview; browser/universal compatibility, configuration migration and current cross-platform/archive qualification remain outside this scoped result. The prior Linux R2 source hash remains historical; Darwin amd64 and final A18 refresh are still unverified. Authorized bilingual canonical writes occur only after this frozen no-write evidence boundary.

Fresh canonical documentation acceptance passed after the parent applied the ten guarded files. Evidence is /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r4-docs-render-v01eima0/summary.json; the promotion manifest is /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r4-doc-drafts-3i8bw994/applied-files.json. The frozen c169b3… CLI performed one strict production render and its focused link check returned 0.

Fresh canonical documentation gate Executed result
Source owners Translations 0: 137/137 pairs and 1,104 headings; complete canonical style 0: 137 Chinese files, 181 strong spans, no emphasis; ten-file whitespace check and public JSON schema equality passed
Production rendered Markdown/links Both 0: 214 content pages / 42,214 text nodes; 345 pages / 48,360 internal links / 4,187 fragments
Production translations 1 solely for the pre-existing draft content/blog/release/1.2.0.md absent from production; no new pairing/heading finding
Separate nonpublishable analysis Fresh ordinary Hugo with the actual original snapshot environment/rebased paths and explicit draft/future/expired flags returned 0; all three owners 0: Markdown 216 pages / 42,520 nodes, links 347 pages / 48,736 links / 4,215 fragments, translations 137/137 pairs / 1,104 headings
Source preservation Canonical 421 Git-inventoried files and 427 copied inputs retained exact bytes, modes, Git state and directory modes; production copied 428 and analysis copied 427 files remained unchanged through their checks; analysis build also retained copied full modes

Production output remained separate and was never replaced by the analysis tree; the analysis is not publishable. The temporary helper copied the frozen core without modifying it: helper source SHA 7faea7e726a6c6fb2e0747be1a4428f4c5fb5734fa52b6f981157a5fe37d9989 and helper binary SHA 532638e76f96f8b173c122e512b3bf5fc2c4d4a7130f59c99c2c69e135e87073 are retained with raw logs. This authorized bilingual research amendment occurs after the exact no-write capture boundary and receives narrow source checks separately. R4’s scoped local documentation gate is accepted; this result does not claim publication, deployment, R5–R8 completion or final A18 qualification.

R5 implementation and documentation acceptance

R5’s supported local scope is accepted after focused public/core, corrected frozen full-stage, exact-binary read-only consumer and guarded canonical source/rendered documentation gates. The bounded outcomes remain explicit below. R6–R8, workspace A15 and final A18 qualification stay open. The first promotion and separately authorized post-render status/evidence amendment retain distinct preservation boundaries.

The actual public Git/Hugo flow at /tmp/oink-r5-public-final-flow.log passed in 53.963 seconds. Its committed synthetic site owns its local theme, bilingual pages and binary attachment; ordinary modes 0640 and 0600 remain full current facts while historic Git comparison uses executable bits only. Deleting B selects unchanged inbound A, the remaining translation, removed attachment and actual RSS output. Actual alias-inbound uncertainty, global configuration/template/data and unknown-input changes expand full scope.

Completed inspect/impact/context returns 0 with separate current-check findings 1; check-since retains current quality 1 and full validation scope. Missing/unborn/foreign history returns 2, retaining every known current page/attachment/reference/output with no fabricated prior identity or change. Malformed selectors/limits, missing tools and failed renderer logs are tested. Bounded context gives reasons/versions/source and excerpt hashes, visible omission/truncation and no execution of literal document instructions.

Saved move preview/apply and subsequent ordinary Hugo passed, retaining binary bytes, raw full modes, unrelated files and Git index/revision. Actual opaque HTML/shortcode references remain manual; inline/fenced/opaque spans stay unchanged. Their broken final candidate returns 1, with no saved plan or source writes. Source/config/attachment/mode/fresh-target drift returns 2 and preserves the later edit. A deterministic mutation after the actual candidate renderer also refuses before writes and preserves editor bytes/mode. Focused actual move race passed in 8.286 seconds at /tmp/oink-r5-public-move-race.log; app vet passed at /tmp/oink-r5-public-vet.log.

Before the cached-module supplement, frozen parent make test/vet and make test-hugo both passed at /tmp/oink-r5-frozen-go-gate.log and /tmp/oink-r5-frozen-hugo-gate.log (actual app fixtures 185.709 seconds). Actual move/source race and vet passed /tmp/oink-r5-move-hugo-gate.log, /tmp/oink-r5-source-move-race-gate.log and its vet counterpart; full inventory/mode/selector plan safety passed /tmp/oink-r5-plan-owning-final.log.

A first frozen consumer trial exposed an actual cached-public-module guard gap: resolved module inputs present in the original graph were absent from a fresh outer candidate hash. It returned false incomplete 2, without source writes. Content plans now resolve/capture the same module inputs before comparison, retaining legacy metadata/authoring plan scopes. The separate checksum-verified public OINK v1.1.0 regression passed preview, fresh saved apply and ordinary bilingual Hugo in 27.42 seconds (package 28.220) at /tmp/oink-r5-public-cached-module-move.log, including raw modes, binary bytes, unrelated inputs and Git preservation. Corrected current-binary corpus and supplemental race evidence remain separate from the earlier unaccepted trial.

The corrected current candidate passed full make test/vet at /tmp/oink-r5-corrected-frozen-go-gate.log and actual make test-hugo at /tmp/oink-r5-corrected-frozen-hugo-gate.log (app 278.787 seconds). The cached/public and committed/in-site move safety race passed in 38.578 seconds at /tmp/oink-r5-public-cached-seam-race.log; its app vet also passed.

/tmp/oink-r5-corrected-runtime-freeze.json records 96 runtime inputs with SHA-256 e5b6e0eda972116dbb94a8086668e6ef34bfaa56138cf31f1f71f4832c477842 and 165 broader CLI inputs with SHA-256 4965a0c92cb6126f67a6dabd548c7c25ee5d7c9c57e14cce5e55ebb7a22fca2d. The corrected binary SHA-256 is d7675aecca2f77b1eb37bb4f664c3314cf5207149e6abbb86523686c5c50bff0. These are local working-input/executable identities, not a new commit or published archive. The corrected four-consumer capture completed 16 commands in 831.825 seconds at /private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r5-corpus-corrected-y2eue81h. Its bounded final-receipt.json has SHA-256 b86e0e6c7dbfbaed62c845c03a55d963068f7d9a16771de5ff3b0974e76fce3b; the receipt retains 12 copied owning gate logs, all 20 observed move routes and links to the complete raw JSON/logs and per-move classifications.

Site Primary/copied inputs/directories Inspect/context Current check Impact Move preview
Starter 97/94/21 0/0 0 2: no Git baseline 0: validated, unapplied
Documentation 421/427/109 0/0 0 0: complete historical comparison 1: six candidate missing references
PIG 858/861/52 0/0 0 2: historical foreign-input provenance incomplete 1: 32 candidate missing references
Repository 2294/2299/48 0/0 1: 10,462 existing duplicate HTML IDs 2: unborn HEAD baseline unavailable 1: the same existing duplicate IDs

Starter and Repository impact retain known current facts without inventing prior pages or changes. PIG’s actual baseline is complete (theme v1.0.0 versus current v1.1.0), but required foreign-input provenance is incomplete, so the comparison expands full scope and returns 2. These are distinct outcomes. Documentation impact completes with 192 captured input changes, 343 affected prior/current pages and full scope. All completed fact queries expose current quality findings separately; Repository inspect/context remain 0.

Documentation move proves 18 rewrites and four routes. Two ordinary literal /docs/admin/comments/ occurrences in content/docs/customize/repository.md at lines 216 and 313 remain manual because repeated source/output occurrences cannot be attributed precisely across ordinary and print outputs. Their six missing candidate references block validation. PIG moves two Markdown files and four binary attachments, with eight proven page/processed-resource routes. Equal-byte paired outputs prove processed featured_hu_* resources, but not new URLs for the four original absolute image references /article/pgext-day/{featured,topic,venue,schedule}.webp. Their 32 candidate missing references block validation; no guessed original-asset rewrites occur. These ordinary Markdown limits are separate from opaque HTML/shortcode limits.

Repository move proves ten rewrites and four routes; its candidate has only the same 10,462 existing duplicate-ID findings, with no new missing reference or required incomplete finding. Starter’s zero-link bilingual move is validated. All four moves remain unapplied, no consumer plans were saved and no consumer source writes occurred. Failed candidates have validated: false. All JSON stdout is pure. Primary/copied inputs, full modes, directory inventories and logical Git/index state are unchanged; ignored copied inputs are included. The Git metadata inventory excludes immutable object storage. The runtime and broader CLI inventories still match the captured identities. The receipt does not qualify another platform, browser runtime or deployment.

The first ten-file guarded canonical promotion was qualified in 62.37 seconds with the corrected frozen binary and runtime hashes above. The separate rendered receipt is /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r5-docs-render-ks2tw82c/summary.json, SHA-256 06ae844a4b3f1c01bb5faa8a21091d5461c28aab592d12c4310fb34bc176c5d4.

Canonical documentation gate Executed result
Source owners Translation 0: 137/137 pairs, 1,109 headings; style 0: 137 Chinese files, 181 strong spans, no emphasis; scoped whitespace and public JSON schema equality passed
Frozen CLI Production check links returned 0 using the exact corrected binary
Fresh ordinary production Hugo Build 0; Markdown 0: 214 pages/42,571 nodes; links 0: 345 pages/48,376 links/4,203 fragments
Production translation owner 1 only for the pre-existing draft release-1.2 omission from ordinary production output; no new R5 discrepancy
Separate ordinary analysis Hugo Fresh nonpublishable -DFE build 0, without the CLI probe; Markdown 0: 216 pages/42,877 nodes; links 0: 347 pages/48,752 links/4,231 fragments; translations 0: 137 pairs/1,109 headings
Input preservation All per-command and overall guards passed: 421 primary files, 427 copied inputs, 109 directories and 36 mutable Git files retained bytes/full modes/logical Git state; both isolated source copies remained unchanged

The analysis tree did not replace production output and is not publishable. The permanent first-promotion applied-files.json in /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r5-doc-drafts-t3_klnck retains the ten authorized files and their original modes. This separately authorized post-render amendment touches only six paired proposal/index/research files, after the recorded no-write boundary; the qualified contract and guide bytes remain frozen. Its guarded originals, prepared diff and focused source checks are retained separately. It does not retroactively claim these later evidence bytes were in the earlier rendered capture, and no full corpus or rendered rerun is inferred from the amendment.

Core owning logs /tmp/oink-r5-frozen-core-hugo.log, /tmp/oink-r5-owning-race.log and /tmp/oink-r5-owning-vet.log passed. A13 impact and A14 move safety passed their required supported CLI scope; A15 bounded context passed, while workspace/direct parity remains R6 scope. No consumer source write, commit, publication, network deployment, remote model integration or incremental speed claim is made.

R6 workspace and adapter acceptance evidence

R6 supported scope is accepted locally after frozen owning/runtime, exact-binary consumer parity/preservation and guarded canonical source/render gates. The supported registry/tool fields belong in the contract and guide. R1–R6 are accepted locally; historical receipts remain intact. A07 adapter and A15 workspace/direct/context supported scope passed the gates below; R7/R8 and final A18 remain open.

The registry is independently versioned oink.workspace/v1: strict one-document regular YAML, 1–64 entries, at most 256 KiB, exact ASCII names, literal relative/absolute directories, proven canonical identities and overlap refusal. Missing-site results stay per-site incomplete while later selected sites run. Selection preserves registry order; no default named site, sibling discovery, Hugo settings duplication or automatic multi-site apply is provided. Optional tools extend oink.policy/v1, with pinned protocol versions, configuration/full-mode provenance and typed omissions/coverage.

Workspace owning receipts

Focused gate Executed local evidence
Registry core Strict fields/document/bounds/names/literal paths, existing aliases/case-inode ancestry, duplicate/overlap refusal, missing-directory listing and exact subset order; go test -race ./internal/workspace -count=1 passed in 1.414 seconds, /tmp/oink-r6-workspace-core-race.log
Public actual Hugo OINK_TEST_HUGO=1 go test ./internal/app -run '^TestPublicR6Workspace' -count=1 -v passed in 10.498 seconds, /tmp/oink-r6-workspace-public-hugo.log
Public race The same workspace public suite with -race passed in 12.426 seconds, /tmp/oink-r6-workspace-public-race.log; excluded commands specifically reject registry selection
Vet go vet ./internal/workspace ./internal/app completed with exit 0, /tmp/oink-r6-workspace-vet.log
Public outcomes Actual bilingual committed fixture sites retain direct diagnostics/coverage/exit parity for links and full checks. A missing first site yields 2 while later clean/finding sites yield 0/1; explicit subsets preserve registry order, invalid unregistered siblings remain untouched and human output retains findings
Selected application Saved translation-review preview is validated but unapplied; a different registered name is refused before writes and preserves plan/source bytes/full modes/Git. Explicit matching-name apply writes only its planned review file; other registered and unregistered sites remain unchanged

These are owning fixture outcomes, not consumer adoption or permission to apply plans to actual consumers. The inspected core workspace.go SHA-256 is cf2cbc9509e8c83eedf6d8833c9eb0ea6492de9a85c959798112fa3f105213f4; its owning test is 9070a8e2c3e58680f6567f2394160ec682bf0457c068c2addf354921e7612d6b; the public test is 3e57a6417ae2e7604f7cb06933759bb06a2f40758ff7059848593cedbaa6570a. All three inspected files retain mode 0600. These owning source captures are covered by the frozen all-runtime inventory below; their individual hashes do not identify the exercised binary.

Corrected protocols and stage gates

Protocol or gate Recorded status
Actual markdownlint-cli 0.49.1 and Vale 3.24.0 Corrected public trial passed: exactly one finding mapped to the original UTF-8/BOM/CRLF line; excluded front matter/shortcode/math/raw HTML/enabled attributes/code produced no false original attribution
Actual lychee 0.24.2 Corrected trial actually reached the local HTTP fixture: 200 → 0, 404 → 1, 401/403/429/503/timeout → required 2. Optional offline → 0, required offline → 2, both with zero HTTP requests
Final focused actual-tool receipt /tmp/oink-r6-public-actual-tools-final.log passed in 15.192 seconds; the earlier corrected 14.686-second run is retained as prior evidence. Node preload and discovered JS configuration did not execute; source full modes/Git were preserved
Fake/protocol failure receipt /tmp/oink-r6-public-fake-tools-final.log passed in 13.089 seconds: malformed output, version mismatch, timeout, unsafe configs, required missing/optional/group omissions and raw stderr normalization
Focused public race/vet /tmp/oink-r6-public-tools-race.log passed in 30.273 seconds across fake and actual cases; /tmp/oink-r6-public-tools-vet.log completed with exit 0
Frozen runtime inputs Parent freeze at 2026-10-03T10:58:01.807947Z, /tmp/oink-r6-runtime-freeze.json: 103 runtime inputs bind b85affd96378b45bfc56a996b0c5672d02ee4c6cc9bc95335fa5072f6c42a03b; 179 broader CLI inputs bind fbb8176ebc58f1aa26336f4e6036cf9bd5f7a0d62b142f16532b50a8071e9fbe. The exercised 0.3.0-r6-local binary SHA-256 is aa8b347fbe01071f9da729f4d98aa2f50d7264456be6c5f05771bcfadadc371f
Frozen owning suites Full Go/vet completed with exit 0, /tmp/oink-r6-frozen-go-gate.log; full actual Hugo plus pinned tools completed with exit 0, /tmp/oink-r6-frozen-hugo-gate.log (app 382.832 seconds). Workspace/core/protocol/source-mask/policy/report race and vet receipts passed and are copied into the final receipt
Four consumer sites Qualified: exact-binary direct/aggregate diagnostics, coverage, exit, identity and registry-order parity for all four sites; per-command/overall source byte/full-mode/type/logical and mutable Git/ignored-input/directory guards passed. Aggregate completed 4, finding 1, incomplete 0, exit 1
Canonical EN/ZH Passed: guarded first ten-file promotion, source owners and fresh ordinary production/nonpublishable rendered evidence; only the known production draft-release omission remains
Stage decision Supported R6/A07/A15 scope accepted locally after the required receipts; R7/R8/final A18 open; no public release, consumer source write, adoption or deployment

The durable focused-tool receipt is /private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r6-tools-6bf67ltv/r6-public-tools-acceptance.json, SHA-256 16b6e47fc0618c76d2f9e3680a4112b6e47b478af8aabd3f2fc84821f840cc8a. It binds the provision record, executable/configuration evidence and 1,422 resolved Node package files. Markdownlint reports original content/tools.md line 7, bytes[80:92] (ppears here.); Vale reports the same line, bytes[71:78] (BADTERM). Each of the seven network cases actually makes one HTTP request. These records do not certify every transitive interpreter, another runtime target or the full consumer corpus.

The exact-binary consumer receipt is /private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r6-corpus-59_asiyr/final-receipt.json, 42,212 bytes, SHA-256 0ad86afaf235bdcff0c474e76b08e0591591a7b22c7992b02e20fb17975d029e; the completed summary binds 467b66eb6d178829508115050d4243909313acf1b4d59317ecda37ab7383ca55. It retains 14 copied owning/completion gate logs. The six original operations sum to 314.912887 seconds, excluding candidate compilation and receipt-only correction. workspace list returns 0; four direct full checks return 0/0/0/1; the aggregate returns 1 with all four sites completed.

Site Preserved source files Direct/aggregate child exit Diagnostics/coverage Recorded finding boundary
Starter 97 0/0 28/29 Translation review information only
Documentation 421 0/0 144/34 Translation review information only
PIG 858 0/0 120/41 Translation review information only
Repository 2,294 1/1 11,250/29 Existing 10,462 duplicate-ID findings and 788 translation review information items

Direct and aggregate child identities, order, every diagnostic and coverage record match. All four consumer sources retain full modes/types, logical and mutable Git metadata, ignored copied inputs and directory inventories after every operation and overall; the complete root CLI inventory also still equals its frozen capture. The 478,603,149-byte direct repository JSON and 635,470,795-byte aggregate JSON were validated streamingly rather than truncated. Optional-tool protocols are qualified by their separate pinned-tool fixtures; the consumer registry is task-local and writes no consumer policy.

The initial acceptance driver overwrote a summarized result’s command string with invocation argv, producing a false parity exception after all six CLI operations and their per-operation guards had completed. The failed driver and summary remain preserved as pre-correction.r6_qualify.py and pre-correction.summary.json. Receipt completion corrected only invocation metadata, verified unchanged raw-result SHA-256 values and header commands, retained all original full-stream diagnostic/coverage digests, and rechecked overall consumer/root guards. No CLI runtime correction or Hugo/CLI rerun was needed. The receipt-only completion took 2.002 seconds and exited 0 in /tmp/oink-r6-corpus-receipt-completion.log.

The executed driver SHA-256 is 4d2a360c6f7f6f96c38698bd189bc4d4b2cb02a7509858920d752897fdd85988; the corrected driver is 4870f5c0374fcc11ad1a6b2e3aefe36f493b6f9f4666c293993dc6a59df8a11b; the receipt-completion driver is cd50d3fe704370f73fa4e7d94ce8e4bc925d11ec8ef04d463aacec37c2053daf. The streaming helper binds 144f778cdb7907372797b47b97f817f340e70423701a2a958dee589281a9a11c, and the inventory helper binds d3ac41dc2e18295bfb26134d1a696935c8174913e2801a5766dbf7a1139d89f8. This receipt qualifies local darwin/arm64 with Go 1.27.1, Hugo Extended 0.166.0, Node 26.9.0 and Apple Git 2.54.0. It does not refresh final A18, qualify Darwin amd64 or another platform, apply a consumer plan, publish or deploy. At corpus capture, canonical promotion and actual rendered EN/ZH owning gates were separate pending work. The later receipt below closes that boundary; the first-promotion bytes do not claim this post-render amendment retrospectively.

The initial actual-tool trial was preparation evidence, not a passed qualification. It exposed Darwin /var versus /private/var staging identity, actual loopback proxy routing, and an invalid inline-block-attribute/line assertion in the Vale fixture. Staging is now canonical; the Vale fixture uses a real standalone block attribute without changing the source-mask boundary. The qualified child environment forwards literal NO_PROXY/no_proxy host-list data while omitting proxy URLs/credentials and Node preload settings. Neither an empty proxy environment nor NO_PROXY=* established the tested Darwin loopback path; no universal operating-system proxy bypass is claimed.

Supported source diagnostics require proven original ranges; rendered lychee locations remain output file/DOM pointers, with no inferred Markdown line. Offline lychee is not invoked. Authentication/rate-limit/server/transport uncertainty cannot become required success through severity, exclusions or baseline acknowledgement. External fragments, browser execution and remote content identity are not proven. The declarations, output envelope and required-incomplete precedence remain independent from final platform/archive qualification; Darwin amd64 and final A18 are still open.

The first guarded ten-file promotion and its fresh rendered qualification are now complete. The receipt is /private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r6-docs-render-dcwtcmyl/summary.json, 555,297 bytes, SHA-256 ee153932900dc6f1ec62beef1a75927fc60b857efccfbcc558bf0e2c2b12cc04. The 64.17-second run used the exact qualified aa8b347f…371f binary and unchanged 103-input b85affd9…a03b runtime inventory recorded above.

First-promotion documentation owner Actual result
CLI production links 0; one strict production Hugo renderer, no analysis build
Ordinary production Hugo / Markdown / links 0 / 0 / 0; 214 content pages and 43,376 text nodes; 345 HTML pages, 48,438 internal references and 4,259 fragments
Ordinary production translations 1 only for the existing draft content/blog/release/1.2.0.md absent from production; not a new R6 failure
Independent ordinary nonpublishable Hugo / Markdown / links / translations All 0; 216 content pages and 43,682 text nodes; 347 HTML pages, 48,814 internal references and 4,287 fragments; 137/137 pairs and 1,118 headings
Source owners / schema Translation, style and whitespace all 0; 137/137 pairs, 1,118 headings; 137 Chinese files, 181 strong marks, zero emphasis marks; CLI/documented result schema both bind 7468c2d04cde8a368ce0ba44a1f27125b5fca364b6d4672353519b9545b3bdda
Preservation All 12 owner commands, CLI/schema checks and overall comparison preserve 421 primary files, 427 copied inputs, 109 directories and 36 mutable Git files with full modes/types/bytes and logical Git; both private ordinary source copies and all 103 runtime inputs unchanged

The first-promotion installer receipt, oink-r6-doc-drafts-ymjop499/applied-files.json, binds 13c965592d64056d8365aed1927d2d422fadec8adc54ee7050b22e2ea0ad6270. It retains captured actual original inodes in private temporary storage, preserving later old-open-handle writes; recovery also preserves later target edits or deletion. The subsequent paired status/evidence amendment has its own full-byte/full-mode guards and source-owner receipt. It updates current notes, command status and this ledger, preserving earlier receipts and configuration examples. Its new bytes were not inputs to the 64.17-second rendered run, and that run is not claimed as their rerender. Supported R6/A07/A15 is accepted locally after these gates; R7/R8 and final A18 remain open. No duplicate corpus, public release, consumer plan application/adoption or deployment is claimed.

R7 read-only Studio candidate evidence

R7 implements the embedded five-view browser and authenticated loopback API candidate described in the contract and guide. R1–R6 historical sections and their exact receipts remain unchanged. Frozen core/browser and exact-binary four-consumer qualification and guarded canonical rendered gates passed within the declared scope. R7/A16 supported read-only scope is accepted locally; R1–R7 are accepted. R8 editing and final A18 remain open.

Focused native and browser evidence

Owning boundary Evidence status
Native/public parity Actual shared check reports preserve diagnostic/coverage/exit identity for 0/1/2; explicit selected workspace startup, cleanup/signal and no-source-write proofs are recorded separately by the owning test receipts
HTTP management/source/preview Literal-loopback selection; exact Host/origin/Bearer checks; no arbitrary request paths/writes; captured source/diff bounds and source-mode/output inventory guards; focused core/new browser and current corpus receipts below bind this supported scope
Initial held browser 14 axe checks with zero violations and 14 screenshots; five desktop light views, captured BOM/CRLF source/diff, desktop dark, mobile dark and all five 320-pixel light views plus capture changes. Synthetic actual-Hugo fixture retains 228 native diagnostics and coverage parity; copied suggestions use a private test clipboard, leaving the host clipboard unchanged
Browser preview attack Actual attack script executes in the isolated preview, but parent access, management fetch and popup are blocked; token query refused. Actual draft-only page remains production 404. This proves the tested browser/CSP scope, not an OS network sandbox
Snapshot preservation Captured source instructions/HTML stay literal data; the initial capture retains its old bytes before refresh after an explicit task-fixture external edit. Source full modes/Git/directories preserved except that declared fixture edit; changes show the actual modified captured input
Preceding held browser Passed refreshed held UI/backend receipt: all 14 axe checks zero violations and 14 screenshots, including declared/captured theme rows. This predates the partial-preview runtime correction and does not qualify that new runtime
New partial-preview browser Passed new frozen partial-preview runtime: 14 axe checks with zero violations and 14 screenshots; actual Hugo normal HTML 200 and 67,108,865-byte output 413; native 1/228 diagnostics and coverage retained, required partial coverage visible and Studio/refresh 2

Initial browser receipt: /private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-studio-browser-AfwaYi/summary.json, SHA-256 930fbd1ab86806069b963bff2e3e95aaa07e3634400cec65e2b8c7922e2a1707. Its exact binary binds 92e5b962e40fbe828a0b006f3ae76a2bddf4ad7e8b1c5b6967e365b8f1827879; the subsequent declared/captured theme metadata row is not claimed tested by that preceding binary. The qualified local versions are Node 26.9.0, Playwright 1.62.1, @axe-core/playwright 4.13.0 and Chromium 151.0.7922.34. These are explicitly prepared contributor dependencies, not consumer runtime requirements or automatic installations. Clipboard evidence covers the actual UI click with a private clipboard implementation, not the whole host clipboard.

The refreshed held UI/backend browser receipt is /private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-studio-browser-vn0ofb/summary.json, SHA-256 520603779f712539865c6e9ef7a9ad3ad21ec1906adfb067ec607cc69d071b7e, with exact binary 73bf90c69dce84849ee20ddfbfe825b9f2dd46f0cd37a228ce1b041a83afa33f. All 14 axe runs and 14 screenshots passed, including declared/captured theme metadata and all five views at 320 pixels. It retains the same bounded synthetic-fixture/source/preview/clipboard claims above for that preceding runtime. It does not qualify the later partial-preview correction; new browser, full-stage, consumer and rendered-documentation qualification remains separate.

The initial parallel whole-suite trials in /tmp/oink-r7-frozen-go-gate.log and /tmp/oink-r7-frozen-hugo-gate.log failed and are not qualification receipts. The failures were existing ten-second CI-test deadlines under parallel package load and a graph test observer refreshing its own Git index. The isolated CI target sets then passed in 12.149 and 2.291 seconds; the controlled Git-observer graph run passed in 1.354 seconds. Only internal/projectgraph/hugo_test.go changed: its read-only observer disables Git optional locks, filesystem monitoring and the untracked cache. The ordinary actual-Hugo graph run passed in 1.562 seconds after that test-only correction. No runtime or embedded UI bytes changed.

The corrected freeze is recorded in /tmp/oink-r7-corrected-runtime-freeze.json: the 113 runtime inputs retain 15a7de85a1ae9e6a73d8ea6570aa4f97bdd0ad5677ad7ca996fdd081ad43f7b5; the 193 broader inputs now bind 67c6d36cf91d175f208f79cdd4d337aab6d2ef71e43453b20394b677678725e8, with only the test-observer file changed from the preceding 85ad60d24c93e899020fbdcd34f8252c578253ce5afaf8652e561a432ecc8067 freeze. Corrected serial Go tests and vet passed in /tmp/oink-r7-corrected-go-gate.log. The corrected serial actual-Hugo/pinned-tool suite also passed in /tmp/oink-r7-corrected-hugo-gate.log, SHA-256 2aed822ff6fc8be04919aa74ca6ada721789232c14c1d77f1d44113bc0d235a7; the application package took 220.782 seconds. The independent post-Go source-preservation audit is /private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r7-postgo-audit-qygh7bcc/receipt.json, SHA-256 5ee45fe041536243bc1229054516835c61b27909a4f296ac226b1a138e4bc8dc. It verifies the full physical/logical input guards, not Hugo or consumer results.

The durable corrected owning-gate receipt is /tmp/oink-r7-corrected-owning-gates.json, SHA-256 c7f94a740e33a7349886b3f3689419719f857f39031375e80ca384a3dac36e67. It binds both successful serial runs to the corrected freeze and preserves the failed trials as unqualified. The prepared documentation renderer now requires the completed consumer receipt to prove a private captured-source rebuild byte-identical to the final browser binary. Its source-only independent audit, oink-r7-docdriver-audit-ig_r8ud1/receipt.json, binds SHA-256 858cc48bf602fbdb26fcbda03c78ca485338b1295d64257d32cfb14b24f1ade3 and prepared driver f25d9ac4bf1a7ef43d5526b7b3cbadf84dd64ad8a57fd82d1c82e76fdb2b3435. That audit did not execute or qualify canonical rendering.

The first consumer driver trial, oink-r7-corpus-h1lOFl, stopped with KeyError('preview_base_path'): it indexed a field legitimately omitted when the actual preview base path is empty. Its private rebuild was byte-identical to the final browser binary 73bf90c69dce84849ee20ddfbfe825b9f2dd46f0cd37a228ce1b041a83afa33f, and all four consumer source inventories and the root inventory were preserved. That failed driver run does not qualify the four-consumer gate. The fresh oink-r7-corpus-corrected-cByXTa driver changes only those two accesses to get(..., ''), with SHA-256 4c409acacbb9b82e658e6705eddefd9a3541def5c63c340b65678a6c9a8354e4. That fresh run subsequently failed when the repository produced an inventoried file larger than 64 MiB: the preceding runtime refused all production preview. Its native check retained outcome 1, while required unavailable preview made Studio outcome 2. Starter, docs and PIG completed that run with outcome 0; all four source inventories and the root inventory stayed preserved. The failed cByXTa trial is retained and does not qualify the four-consumer gate. Neither empty-base-path driver correction changed runtime or consumer sources.

The parent then authorized a narrow runtime/test correction for partial preview. It keeps the 64 MiB limit, exposes guarded production files within the limit, returns 413 for the exact skipped oversized paths and keeps required studio.preview coverage incomplete. Native check outcome remains unchanged; Studio still returns 2 for required incomplete preview. The embedded UI is held unchanged. All preceding browser/owning/binary/corpus receipts describe their earlier runtime boundaries, not this new runtime. The new owning/browser gates are recorded separately below rather than inferred from those earlier receipts; exact-binary four-consumer qualification remains separate. The old failed capture proved that an output exceeded 64 MiB but did not expose its captured path/size; ignored repository output is not evidence for that capture’s identity. The new bounded coverage detail will record actual omitted relative paths, sizes and count. A prepared real-Hugo browser fixture adds static/oversized.bin at 64 MiB plus one byte to exercise an available guarded HTML preview, an exact skipped-file 413, native outcome 1 and required partial-view outcome 2. That fixture preparation alone was not browser qualification; the subsequent completed browser proof is recorded below.

The new partial-preview freeze is /tmp/oink-r7-partial-preview-runtime-freeze.json, SHA-256 c426ce3e641ed7b39bb711a26006306cab22e761c5062f2164f10deb4bea8765. Its 113 runtime inputs bind 4900ae05abbdf4409b0be54f276fb4135269cf0a49e9071013ccf42544d35c84; 193 broader inputs bind 8b172cef2b228e2642f0139d6cc569136e86843f818e52e412fa4a2d56add25d. Only internal/studio/preview.go changed among runtime inputs; the broader changes also include its test and scripts/test-studio.mjs. All three UI files retain their exact bytes and modes. Focused core final race passed in 1.748 seconds, with vet and scoped whitespace checks also passing. Its receipt, oink-r7-partial-preview-owning-a56dunn4/receipt.json, binds SHA-256 7b6ecb491f283d04fe54347e564dba426b1a84d152040a1d945af54bc67756ac. The initial sparse-fixture mode trial is excluded: host umask 0077 made a requested 0640 file actually 0600; explicit fixture chmod to 0640 corrected that setup without changing production behavior. Focused proof covers normal 200, oversized GET/HEAD 413, changed identity 409, private path 404 and refusal for other unknown output errors. It does not substitute for the subsequent independent broader browser/owning/corpus/render gates.

Whole serial Go tests for the new partial-preview freeze then passed in 61.481 seconds, and vet passed in 0.571 seconds. Completed logs are /tmp/oink-r7-partial-preview-go-gate.log, SHA-256 be7d6eccf99a6f4c1b8f09d1fb782455c7cbd3bad4a2f37e2f0e9da916bcb313, and /tmp/oink-r7-partial-preview-vet-gate.log, the empty SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. The independent held-input audit oink-r7-partial-held-audit-o6p98i1l/receipt.json, SHA-256 e567efc5f580db9395afab8ad36c4db842c3db95db442eb1cb1c740dbd43ec31, verified all 113/193 inputs and physical/logical identities during that parent Go/vet run. It is not a post-suite or browser/corpus/render completion claim. The new whole actual-Hugo/pinned-tool invocation subsequently completed with exit 1 after 285.649 seconds. Its sole failure was the parent’s unavailable Markdownlint preparation path /md/node_modules; all other actual cases passed. The log remains a failed invocation: /tmp/oink-r7-partial-preview-hugo-gate.log, SHA-256 1ab6b8cfd399d484e08a1d1f05d25475754caa731991dd1eec1cca03cf6ce970. The sole owning case was rerun with the exact provisioned /markdownlint/node_modules executable, with no source/runtime change, and passed: application package 2.317 seconds, wall 3.265 seconds. Its receipt is /tmp/oink-r7-partial-preview-corrected-tools-gate.json, SHA-256 62b75e563e8074995ed9dd354434e653b2f5f2c6d20767226286d0c08d4c667c; log SHA-256 is e9bddac210654d219d9c5d6ebabaa3b91a0f5f4de4daf228b3ae21aeaac7673a. The executable comes from provision receipt 268e601e81bc03a263296d57257b85635371bda642d0632532a7d9318c981461. The independent case-matrix/held-source audit verifies cumulative executed actual-owning-case coverage 0 from the failed whole invocation plus that corrected case. Its receipt, oink-r7-partial-case-matrix-audit-16_bl9hr/receipt.json, binds SHA-256 0a9e4a1a1e1a08f597becb2f27e743c9f23df672c713c2757241704edb16b51e. All 113/193 physical/logical inputs remain frozen. Optional TestArtifactCorpus and TestPublishedRuleSourceProvenance cases were explicitly skipped. This never relabels the whole invocation as exit 0, nor claims those skipped cases executed.

The new post-Go input audit, oink-r7-partial-postgo-audit-g1hcqdtl/receipt.json, SHA-256 b369737ec48456f673c850ea702cb3cb7efffb8ecc129d87e00dc03af82b2e3b, then confirmed the complete held 113/193 physical/logical inputs after Go/vet. That scope does not claim whole Hugo, browser or consumer completion.

The new partial-preview browser passed against exact binary f39d6754f7ad13599e4e849394e0f470b2c6f26edf96ce40f199d27b65a8030e, version 0.4.0-r7-local, 16,000,578 bytes and mode 0700. Its summary is /private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-studio-browser-cE9be3/summary.json, SHA-256 9099e6c407fd0f9de3c29ce80e03f034a4223d7d7a7c1f1378052e8b9084e0ae; provenance SHA-256 is 85b9f537fb09eecbb09d133b53a297c78184c11200ab0938734c0d10f3449095. The private oink-r7-browser-partial-ZZIqzZ/source-binding.build.json, SHA-256 7a89ab8318c3a38455ab6ce12bcdbc53ae5ce0674fb5aaaa1df0fcf68a093399, binds all 113 runtime and 193 broader source inputs plus physical identities before capture/build/after to the new freeze; root inputs stayed unchanged. All 14 axe checks had zero violations and all 14 screenshots passed, retaining the keyboard/mobile/light-dark/source/clipboard/security checks described above. Actual Hugo emitted oversized.bin at 67,108,865 bytes, reached through its rendered /sub/oversized.bin link and returning 413; ordinary actual HTML returned 200. Required partial preview coverage stayed visible; 228 typed native diagnostics and native coverage/outcome 1 matched the CLI/API/UI, while Studio and the subsequent refresh returned 2. Source preservation still excludes only the declared task-fixture external edit. This is the bounded synthetic browser proof, not a completed four-consumer or canonical render gate.

Another prepared, unexecuted corpus driver had assumed that an available normal preview always appends a studio.preview coverage row. Actual normal Starter/docs/PIG Overviews do not emit that row; the preparation assumption was corrected without changing native coverage. The repaired fresh oink-r7-corpus-partial-pZLwY0 driver, SHA-256 47778df62505beeb7432985be927f1b001e03824e9dee3a6dbed9d9b2dbe049c, was reviewed against those three retained actual Overviews and the current partial browser capture. Normal availability still requires its actual preview URL and independent HTML 200; a partial capture retains its actual required row, omitted count/identities and 413. The preparation audit is oink-r7-partial-driver-correction-audit-sa98cm6k/receipt.json, SHA-256 a519a5bc6ae83438146ff4710d53f5edb0e656a05d0532c02123e5771416f07e. Its earlier f762 preparation was not executed or qualified. The parent has released the corrected driver for a fresh all-four run; its completed qualification is recorded next.

The fresh four-consumer qualification completed with driver outcome 0 in 234.6425 seconds. Its current summary is /private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r7-corpus-partial-pZLwY0/summary.json, SHA-256 d7b5a4f1607b6f75ae6a596c19cbab28685fb67dac750096173060ed097c8bf5; log /tmp/oink-r7-partial-corpus-gate.log binds SHA-256 a7b724500569bd594d8e01502ec1956eb089cc9153b04b693992a9322013c811. The durable current corpus qualification.receipt.json binds SHA-256 4e5df7c3fda9f0b763091af3e6cb85c68c736c319a1de68030b81d5cd5b384bc; primary source inventories contain 97/421/858/2,294 files respectively. The private captured-source rebuild is byte-identical to the new browser binary f39d6754f7ad13599e4e849394e0f470b2c6f26edf96ce40f199d27b65a8030e. Runtime 113/broader 193 inputs and root physical identities stayed frozen; every operation and the overall boundary preserve all four consumer bytes, full modes/types, logical/mutable Git, ignored copied inputs and directories.

Consumer Native outcome Typed diagnostics Studio outcome Actual captured pages
Starter 0 28 review-info records 0 66
docs 0 144 review-info records 0 343
PIG 0 120 review-info records 0 248
repo 1 10,462 existing duplicate-ID findings plus 788 review-info records 2 1,576

Nested native headers, typed diagnostics, coverage and exit match direct CLI checks exactly for all four sites. Issues were fully paginated; other views were bounded samples, with captured physical source and translation diff available on all four. The first three actual production previews returned HTML 200; they emit no studio.preview omission row, and the driver invents none. The repository normal HTML returned 200 with 60,100 bytes. Its current capture exposes exactly four oversized print paths; each actual HEAD returned 413 with zero response-body bytes:

Captured omitted relative path Captured byte size
_print/pkg/index.html 73,976,221
_print/pkg/pgsql/index.html 69,903,999
zh/_print/pkg/index.html 73,086,240
zh/_print/pkg/pgsql/index.html 69,052,754

These identities come from current bounded capture detail and live requests, not the earlier ignored-output clues. Required studio.preview remains incomplete, so repository Studio 2 retains native 1. Actual analysis-only draft routes returned production 404 in docs and repo; that test was explicitly not applicable in Starter/PIG without a unique captured draft route. Workspace subset/full/healthy-subset sessions selected only registered sites and closed listeners without captures; unknown or selected missing sites returned 2 before startup. This is local Darwin/arm64 CLI/API evidence with Hugo 0.166.0 Extended, Go 1.27.1 and Git 2.54.0; browser scope remains the separate synthetic fixture. No source writes, install, publication, adoption or deployment occurred. Independent final corpus audit oink-r7-final-corpus-audit-xr3_u5dt/receipt.json, SHA-256 b8a8eedf5c899fe5830bdde959783c46b3f191ab144c0d3798077555d55238fc, verifies raw typed native/API/shutdown parity, all 132 operation preservation comparisons and four overall guards without rerendering or new HTTP requests. Only guarded canonical promotion/render and the explicit R7/A16 stage decision remain pending; R8 and final A18 remain open.

For temporary disk capacity, the parent retired only three explicitly created private Go build caches, totaling 366,184,826 bytes, as recorded in /tmp/oink-r7-private-cache-retirement.json. Sources, binaries and qualification evidence were retained; no global, user or system cache was removed. This preparation action is not a runtime correction or a qualification gate.

Remaining stage gates and promotion boundary

Required gate Current status
Frozen runtime input/binary identity New partial-preview freeze binds 113 runtime inputs 4900ae05abbdf4409b0be54f276fb4135269cf0a49e9071013ccf42544d35c84 and 193 broader inputs 8b172cef2b228e2642f0139d6cc569136e86843f818e52e412fa4a2d56add25d; all UI bytes/modes unchanged. Source-bound browser binary f39d6754f7ad13599e4e849394e0f470b2c6f26edf96ce40f199d27b65a8030e passed; fresh private consumer rebuild is byte-identical
Full Go/vet and actual Hugo New whole serial Go/vet and browser passed. New actual-Hugo/pinned-tool whole invocation remains exit 1 for a preparation path; sole corrected owning case passed 0, yielding independently verified cumulative executed actual-case coverage 0; two optional cases explicitly skipped
Four consumers Completed exact-binary CLI/API qualification; native 0/0/0/1, Studio 0/0/0/2, exact nested native parity and source byte/full-mode/type/Git/ignored-input/directory guards; repository partial preview remains required incomplete
Canonical paired sources/render First guarded TEN promotion and scoped actual render passed; the post-render status amendment has separate fresh source checks and is not claimed rerendered
Stage decision R7/A16 supported local scope accepted; R1–R7 accepted locally, R8 and final A18 remain open

The next prepared documentation installer retains the actual captured old inode outside canonical source storage on both success and recovery, without unlinking its last name after an earlier target identity check. This private helper hardening and its new recovery fixture are a new preparation boundary; executed R6 installers/hashes/receipts remain immutable and are not retroactively claimed to contain it. R6’s successful promotions already retained originals. No consumer plan writes, release, adoption or deployment are implied by this candidate documentation or the local browser fixtures.

The completed first-promotion rendered gate is /private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r7-docs-render-n8tw2tbw/summary.json, SHA-256 35e79f51d39803b3e4cdf134ed277957dd627acba42e0e0dc785e4745ec3c481, with log SHA-256 de3a07eac661c15805070e0ed2e364a71ebbd38e15d8907aab3bdf716e95131d and elapsed 63.33 seconds. Exact qualified binary f39d6754f7ad13599e4e849394e0f470b2c6f26edf96ce40f199d27b65a8030e passed production CLI links with one strict Hugo build. Ordinary production Hugo without a probe passed rendered Markdown (214 pages/44,075 text nodes) and links (345 pages/48,482 internal links/4,303 fragments). Its translation owner retained exit 1 only for the existing nonpublished release 1.2.0 draft. Independent draft/future/expired analysis passed Markdown (216 pages/44,381 nodes), links (347 pages/48,858 internal links/4,331 fragments) and translations (137 pairs/1,129 headings); it did not replace production output. Source translation/style/whitespace checks passed and CLI/docs schema 7468c2d04cde8a368ce0ba44a1f27125b5fca364b6d4672353519b9545b3bdda remained identical. All twelve operations, schema and overall guards preserved 421 primary files, 427 copied inputs, 109 directories, 36 mutable Git files and 113 runtime inputs.

The first guarded promotion receipt oink-r7-root-promotion-p9g1u7pz/summary.json, SHA-256 323a5ce267e39aaf8f97dc4a12cccbdde83730155a199efb5f3815e29b334e4a, verifies actual original inodes retained outside canonical source. Its post-apply receipt lookup initially used 0 instead of 00; that metadata-only driver failure is preserved, followed by receipt finalization with unchanged raw guards. The successful source installation was not reapplied. Executed R6/R7 helpers and first-promotion receipts remain immutable.

R7/A16 supported read-only local scope is accepted after the frozen cumulative owning-case/browser/corpus and canonical gates above. The original whole-Hugo invocation still has exit 1; the corrected sole tool case plus independent matrix establishes cumulative executed-case coverage. Repository native 1 and required partial preview/Studio 2 remain visible. R1–R7 are accepted locally; R8 editing and final A18 remain open. This post-render status/evidence amendment has its own byte/full-mode guards, unchanged headings/command fences, paired source checks and retained-inode installer fixtures. Its new bytes are not claimed tested by the preceding 63.33-second render; no additional rendering, consumer write, public release, adoption or deployment is implied.

R8 accepted reviewed editing evidence

R8/A17 supported editing scope is accepted locally after the corrected frozen owning/browser/corpus and guarded canonical rendered gates recorded below. CLI edit text, field, snippet and attachment preview the same bound oink.edit/v1 intent used by explicit studio --edit. Saved-plan apply or explicit acknowledged Editor Apply owns selected source writes. The default Studio session remains read-only. This section retains capture-time candidate facts and trials, followed by the completed current qualification; it does not extend earlier R1–R7 evidence to changed code.

Candidate scope and preservation

Known site-owned UTF-8 Markdown is bounded to 1 MiB. Full text and supported ordinary top-level YAML scalar forms retain the declared BOM/line-ending and source-span preservation boundaries; unsupported form shapes remain text. Exact value_json numeric tokens avoid browser Number rounding. Scalar forms bound numeric literals to 4,096 bytes and absolute decimal exponent 10,000; larger/nonfinite constructs remain manual text. Field JSON is at most 1 MiB; escaped lone surrogates refuse, valid Unicode pairs are supported. Catalog components use original UTF-8 body byte offsets; attachments require actual leaf-bundle identity, at most 4 MiB and an exclusive new clean basename. Source hashes, full modes, all site/external inputs, regenerated intent and fresh actual Hugo validation bind the same shared guarded application path.

The Editor displays the complete UTF-8 review, selected-file base/after identity and native candidate result; the review is capped at 2 MiB and its literal bytes are hash-checked before acknowledgement. The actual selected candidate HTML is draft/future/expired analysis, visibly nonpublishable and separate from the original production preview. Required candidate-view incompletion may raise the proposal/session to 2 without changing native findings. For page-file edits, the selected candidate source hash/full mode matches its reviewed After state; attachment/no-op proposals retain the selected page’s reviewed Base state. Stale/replayed plans, attachment collisions and untrusted preview requests are refused; applied-with-refresh-error remains explicitly applied.

Focused preparation receipts

Candidate evidence Current observation and boundary
Pure editing core Owner’s focused exact-numeric tests passed for 18446744073709551615 and 7.12345678901234567890123456789, exact no-op raw bytes and changed final decimal digit; broader frozen receipt pending
Actual DFE output ownership Live ordinary output is copied through a confined os.Root, exclusive target files and guarded streaming reads; files over 64 MiB can be captured while serving limits remain unchanged
Copy cancellation/race Context-aware helper focused 0 in 0.703 s, race 0 in 1.856 s, vet/whitespace 0; actual first-chunk cancellation retains partial output, source bytes/modes/identity unchanged; source FIFO replacement cannot block before descriptor proof
Helper log identities Focused c227a88210ab0dc46b24eaff50a347d5c494e9ce23f5bdef5d5b822efab4976f; race 13f0616d55fd4df791ecded0712a18096392c88cb9b849383414c305e50b6779; vet is empty SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
Read-only candidate integration review Selected actual HTML URI/base prefix and inventory, retained private DFE lifetime, source SHA/full-mode equality, native versus view coverage and cancellation reviewed; no new material defect found within this code review scope
First Editor browser trial Harness stopped on ambiguous global Open editor selector; retained as failed trial, no UI qualification claim
Corrected-selector Editor trial Desktop field/component/binary apply checks and axe checks passed before 320 px draft-review horizontal overflow failed; retained original trial, not a final browser pass
Narrow layout correction Editor review hashes/receipt text wrap and intrinsic widths are bounded; prior CSS and failure evidence retained separately. Development rerun passed 12 axe checks/screenshots, including real 320 px dark review and light receipts/refusals; final frozen-source/binary rerun pending

The helper evidence is focused file-copy/cancellation qualification, not the whole editing application or all platform support. Browser trials describe their actual stopped scope. They do not establish final A17, consumer adoption, deployment or a successful current frozen browser binary.

The preceding preparation rows were captured before the first complete R8 freeze. They remain development history. The first whole frozen gates later passed for binary 84b804d3246a5be581e44884ed910fa3f45d8be29734b8babdeeb763a11fa882 (0.5.0-r8-local), runtime 123/58517b8e98b80df6642be4ee6275a0074ec187768b20e009f41da2607b635d46 and broader 212/d81335c78413acc60e27adee0ac794862285e41cb2a3a7687ec820c1065ba003. The whole-gate summary is b49f4a3272af3e3dcc92e7e9b38d4289bb49cb19aa3e9354ea148d2d8cb2cea8: Go tests 0/56.523 s, vet 0/0.904 s, whole actual Hugo plus all three pinned tools 0/320.044 s, core race 0/16.610 s and public R8/helper race 0/48.319 s. Its source guards passed. These receipts qualify those earlier bytes only.

The first frozen browser receipt eb6977235ef9ae6cec28651b5654eb101685af67abe0cbed0acb0f8375458d9c binds that same binary and source freeze. Editor had 12 axe runs with zero violations and 12 screenshots; retained read-only Studio had 14/zero/14. The actual form preserved the literal 1e400, its planned after hash and diff, then discarded it; exponent ±10,001 and a 4,097-byte numeric literal refused locally without an API request. Four acknowledged field/component/binary/draft applications occurred only in disposable fixtures. Default read-only refusal, stale preservation, no-op source bytes, preview isolation and native-result independence passed. This is development browser evidence for the first freeze, not a four-consumer or current corrected-runtime acceptance.

The first exact-binary consumer trial then stopped at Starter after 37.533 s. Its immutable failed-trial receipt is 853a8397ba4c527c03aa3cc9ac7cacc41c0ab0379549d145b874f1d1ecc3901c. Two failures are recorded separately. A driver event hash depended on JSON object-key order even though recursive comparison proved API/CLI arrays equal: 28 diagnostics, 29 coverage rows and native exits 0/0. Separately, repeated resolved cache capture produced a genuine duplicate module input .gitattributes; required candidate graph capture became incomplete, mutation outcome 2, with native check still 0, no actual selected DFE HTML and no applicable lease. The public published-cache fixture reproduced that defect; its retained failing log is 50ab704e715665096e0f36391bb1364841c3a2b2ac88dd262915ce53fb66afa6. All 48 recorded per-operation source proofs and four overall consumer guards preserved bytes, full modes, types, Git, ignored copied inputs and directories; root inputs stayed exact. No Apply or saved plan was performed. This stopped trial has no completed four-consumer qualification claim.

The narrow runtime correction gathers complete resolved-module rows before committing additions. Identical repeated or reordered captures retain the original inventory. Changed hashes/full modes, added or removed paths within an existing scope, missing scopes, conflicting identities or capture errors refuse without refreshing prior evidence or appending partial additions; non-module rows remain exact. Site owning receipt e7b284b9dece1c5f2b696cd76166d2286fcbec69e6c48912ab9a78204bdb980b records focused 0/0.746 s, site 0/2.123 s, focused race 0/1.958 s and vet 0/0.167 s. This compares reobserved complete rows; it does not lock module files against concurrent writers.

The corrected published-cache receipt 6358dc81f06e34b789cb47a0f4442d6d036d2e33423a06f5dbe85b3064766da6 records actual github.com/pgsty/[email protected] from a task-local copied checksummed archive, with no downloads or replacement. Original and candidate graphs each have 1,256 unique inputs, including 1,198 module inputs. Full API/CLI typed diagnostics, coverage, exits and plan identity match; actual selected DFE HTML returns 200, with source bytes/full modes/Git unchanged and no Apply or saved plan. Owning race passed in 30.255 s; vet passed. Its corrected race log is c7d21a30b8af141d9d9604a80ddf9cf3f608320b97a441a06a742376e2119551.

The current complete corrected freeze is fb276500a3d2643bd0aa220f8bebb380fce2c98493d62b0502b6497b2f02949f, runtime 123/cdf629eeb4bbef6d4d88ee27fe3fb0a73b07b6bf6438336e033a18fb7feb1c17 and broader 212/f6e305e792733a550814eb841615d12fa14a9a6bb2a97c4ada85f7275183e579. Only source_inputs.go, its owning test and the public published-cache test differ from the first freeze; held UI/helper bytes and all full modes remain unchanged. The rebuilt candidate is bd25f9e0b35ec10e227aabf9582ae40b0b367390f64b93668de6ae85222c3d71 (0.5.0-r8-local). Its observed corrected source-bound browser receipt 33a698985a55c14c3e64e981da1f8e74c686497083dc0edb241406f185e3eeb8 again reports Editor 12/zero/12 and read-only 14/zero/14 with complete 123/212 pre/post source preservation. Corrected whole owning gates, the fresh four-consumer corpus and protected canonical rendering are still pending at this evidence amendment. R8/A17 is not stage accepted; final A18 stays open.

At the next evidence observation, the corrected whole gates completed for that held bd25f9e0…22c3d71 binary and fb276500…02949f freeze. Summary 208f156c0954e803eccbada678a4689683dc1576c543c379e5cc04b3497ef772 records Go tests 0/57.826 s, vet 0/0.521 s, whole actual Hugo plus all three pinned tools 0/378.847 s, core/site/Studio race 0/17.937 s and public R8/attachment/output-helper race 0/85.159 s. Every gate’s source pre/post guard passed. The actual-Hugo log has 434 top-level passes and zero failures; the two optional external fixtures TestArtifactCorpus and TestPublishedRuleSourceProvenance remained explicitly skipped. Those skips are not claimed as executed corpus or provenance qualification.

The corrected whole actual-Hugo log is 4eb1a2afdce2adbe570b10922fd53b6d8954f7c95747370c3c661e94d2f71a05; Go log ea59463e9649ffe2f8aff9da66c91cf6895c86fde96a524db23c89cd4eb35925, core race cdd3d761b5ca7b5e986b25aee3129d65663e3e5ebb83eecb6fbb080387298a58 and public race bb610bdcd7a299cb9b66f4c69e30e246c20546efae47653c01d350b1026ea2de. The corrected browser-only evidence above remains bound to the same current source and binary. The separately authorized fresh four-consumer trial is in progress; no completed corpus, canonical render, R8/A17 acceptance or final A18 qualification is inferred from these owning gates.

The 434 passes and two optional skips above are top-level counts. The same whole invocation also skipped the nested Unix-socket refusal fixture because the Darwin temporary pathname exceeded the socket limit. A first shorter private-path trial still skipped: receipt 93106854ca890b497d3c74522b895f597ac60cec55ced42cad7b187d334da200 retains process exit 0 but explicitly records no actual socket execution and failed qualification. It is not relabeled as a passing fixture.

A subsequent nonresolved short private TMPDIR executed the same frozen socket fixture under race detection without a skip: 0/2.954 s. Receipt 531a503b3b91e1b423c2be61b92ed806d3a813738c38d57e5ec122577b4337f9 and log 236c84f1842ffce76174c834f3888718a109cec6377ada6f3242b02f551f00b3 bind fb276500…02949f and all 123/212 logical/physical/Git inputs unchanged before/after. This supplies the actual socket-refusal case without changing source or the original whole invocation’s skip history. Corpus, canonical render, R8/A17 stage acceptance and final A18 remain pending.

The preceding pending-corpus statements record their observation times. The corrected four-consumer trial subsequently completed in 845.705 s. Summary af4fc53326163c4a03aa2982c1f01363fbbdd5a447c9baed3639bd8599d46370 and qualification receipt 4d6fd02543c1920497e1a1bb0a68fcf89b0546130fd9cc12c1df391b7e673e75 bind a byte-identical private rebuild of bd25f9e0…22c3d71, the complete held 123/cdf629ee…feb1c17 runtime and 212/f6e305e7…5183e579 inputs. Original failed corpus, published-cache regression and first frozen browser/gate bytes remain separate historical evidence; all 2,383 entries of the first failed trial retained their exact bytes/full modes/types.

Corrected consumer Native/current and native candidate exit API candidate outcome Full diagnostics/coverage Actual selected analysis HTML
Starter 0 / 0 0 28 / 29 200, 48,149 bytes, /blog/design/content-model/
Documentation 0 / 0 0 144 / 34 200, 61,738 bytes, /blog/oink/immersive-reading/
PIG 0 / 0 0 120 / 41 200, 55,641 bytes, /404/
Repository 1 / 1 2 11,250 / 29 200, 92,352 bytes, /blog/infra/2020-12/

These are actual selected Hugo HTML routes in the separate, visibly nonpublishable draft/future/expired candidate view; each expected candidate marker was present. API and CLI matched full typed diagnostics/coverage, native exits, plan ID, Base/After hashes and full modes, unified diff and the selected page’s proposed source. The complete literal API review and its hash were independently validated. No consumer Apply or saved plan occurred, and no listeners remained. The repository retained 10,462 existing duplicate-ID findings and 788 information records. Its four actual PRINT outputs remained required partial-preview incompletion: _print/pkg/index.html 73,976,221 bytes, _print/pkg/pgsql/index.html 69,903,999 bytes, zh/_print/pkg/index.html 73,086,240 bytes and zh/_print/pkg/pgsql/index.html 69,052,754 bytes. Each bounded HEAD request returned 413 with zero body; selected in-limit HTML remained 200. Native 1 remained unchanged, proposal/session 2 and Apply refusal stayed visible. The other three complete previews had no invented explicit complete-coverage row: actual guarded HTML 200 supplied that evidence.

Exactly 53 protected operations each checked all four sources: 212 per-operation source proofs plus four overall proofs, with source bytes/full modes/types, copied ignored inputs, directories and logical/mutable Git unchanged. Each source proof compared four inventory categories, yielding 864 raw inventory pairs including the overall comparisons. All 53 root guards and the final complete 123/212 logical/physical inputs also matched. All issues and pages were paginated; the other five view endpoints were sampled to their first 50 records, with one known source and one bounded diff per site. Full native/CLI record parity used the declared bounded complete-record codec; object order was canonicalized while array order, types, null and field presence remained significant. This does not claim every relationship was visually reviewed or every source was edited.

Independent audit receipt 6b72ca06d8392a5271fc40757f176f26e1144c21eec93dbd035e0a1bd645657b verified 69 artifact hashes, complete bounded API/spool/shutdown typed records and the large native/CLI raw-file digest bindings. It did not separately repeat multi-gigabyte native semantic scans. Its additive receipt 335f137663d4ec0b2a0d3e49c8d70b9918f86078ab6264855171a2644d8aa6c6 also verified the fresh current root’s complete logical Git inventory against the freeze; the original audit stayed immutable. Corrected owning, socket, browser and four-consumer supported scopes are qualified. Canonical TEN promotion/rendering, the R8/A17 stage decision and final A18 remain pending.

The preceding R8 candidate/trial statements retain their capture-time scope. The reviewed first TEN promotion subsequently passed through the guarded retained-inode installer, root receipt 7cd9b4604d2340b9e46965a26281c921b967060909d518b8b4b31e5f42d0120c. Its actual original source inodes remained retained outside the documentation site; unselected source/copied inputs, directories and Git, and complete CLI 123/212 logical/physical inputs stayed unchanged.

The separately authorized canonical render then completed exactly once in 67.21 s, summary bb0d0710294f810fb14284f7b5b0329befbd290b66c21397b9a45e8382287fb6, qualification receipt 32d3ffeca43bc9ad4615edcca0d3cc47cc932bbc93c6576724c800e0a62405b1. It used the exact qualified bd25f9e0…22c3d71 binary and corrected 123/212 freeze. Actual CLI production links passed 0 with one strict Hugo build. Independent ordinary probe-free production Hugo/Markdown/links passed: 214 Markdown pages/44,691 nodes and 345 link pages/48,532 internal references/4,351 fragments. Its translation owner retained 1 solely for the existing release/1.2.0 draft absent from production. Separate explicitly nonpublishable draft/future/expired Hugo analysis passed Markdown (216 pages/44,997 nodes), links (347 pages/48,908 references/4,379 fragments) and all translations 0. Analysis did not replace production output.

Source translations passed 137/137 pairs and 1,143 headings; Chinese style passed 137 files/181 strong spans/zero emphasis, whitespace passed and schema SHA-256 7468c2d04cde8a368ce0ba44a1f27125b5fca364b6d4672353519b9545b3bdda matched exactly. All 12 commands, schema and overall guards preserved 421 primary source files, 427 copied inputs, 109 directories and 36 mutable Git files, plus all 123 runtime/212 broader CLI logical/physical inputs. The qualification receipt binds 60 canonical inventory pairs, 15 CLI guard pairs and six private-copy source pairs; it claims no consumer writes or deployment.

R8/A17 supported local editing scope is accepted after corrected owning, socket, source-bound browser, exact-binary four-consumer preservation and these guarded canonical gates. R1–R8 are accepted locally; native repository findings and required partial-preview 2/Apply refusal remain visible. Final A18 current Linux/runtime/archive qualification stays open. The separate platform-authority audit 762571dab9a07651ac8e4c71764bfef292f8d5eba729a089e72d9d755b7e2d7c confirms that the initial contract qualifies actually exercised architectures: macOS arm64, native Linux arm64 and emulated Linux amd64. Darwin amd64 remains an experimental archive with failed actual execution/unverified runtime; its history is preserved, and no successful cross compilation becomes a runtime pass. Both current Linux runtimes and final archives still require fresh proof.

This post-render status/evidence amendment has separate full-byte/full-mode and inode guards, unchanged stable IDs/command fences, paired source checks and retained-inode installer fixtures. Its new bytes were not rendered by the preceding 67.21-second run. No repeated rendering, consumer source write, public release, adoption or deployment is implied.

Required gate matrix

Required gate Current status
Final immutable runtime/source freeze and exact CLI binary Corrected complete 123/212 freeze and bd25f9e0…22c3d71 bind completed owning/browser/corpus/canonical scope; first-freeze trials separate
Public CLI/JSON/exit, stale source/config/external-input and guarded writer tests Corrected public R8/attachment/output-helper race, whole Go/vet/actual Hugo and canonical stage gates passed
Frozen whole Go/race/vet and actual Hugo/ordinary Hugo after selected application Corrected whole Go/vet/actual Hugo and core/public race passed; 434 top-level passes, zero failures, two optional external fixture skips explicit; first trials remain separate
Editor browser five-view parity, text/forms/components/binary attachments, exact numeric/no-op, stale rejection and preview isolation Corrected source-bound Editor 12 zero-violation axe runs/12 screenshots and read-only 14/zero/14 passed; bound completed corpus and canonical acceptance
Exact-binary four-consumer read-only qualification Corrected all-four completed in 845.705 s; full typed native/API/CLI candidate parity, 212 per-operation source proofs plus four overall, no Apply/save/source writes; first failed trial preserved
Protected canonical TEN promotion, EN/ZH source/schema/style/whitespace and actual production/analysis render Guarded first promotion and independent exact-binary 67.21 s render passed; only known draft translation omission in production; rendered and status bytes separately bound
R8/A17 stage decision Supported local scope accepted after corrected whole owning/browser/corpus/canonical gates; R1–R8 accepted locally
Final A18/platform/archive delivery Open; compile success alone is not runtime qualification

Passed and pending entries are explicit; later gates are not inferred successes. Prior R1–R7 sections, whole-invocation failures and scoped acceptance receipts remain unchanged. Temporary qualification files stay outside canonical content and Git; first canonical promotion/rendering has exact receipts, while this status amendment remains a guarded proposal. No public release or deployment is claimed.

Current runtime completion supplement on 2026-10-04

This supplement records the current candidate on 2026-10-04 (Asia/Shanghai). The dated page URL and all initial 2026-10-03/R1–R7 records remain unchanged. The preceding R8 stage and browser/render receipts are historical input-bound proofs; they do not qualify subsequently changed backend bytes. The three UI files retain exactly the browser-qualified bytes and full modes. Current Go, Hugo, platform, archive and four-consumer checks refresh the changed backend.

The first current ARM offline unit run exposed a real output-copy integrity gap: adding a directory entry on ext4 could retain the parent’s allocation size and observed timestamp. That failed run stopped before later qualification steps. The bounded correction captures and rechecks actual sorted directory membership and entry identity, alongside regular-file byte/full-mode proofs. Only internal/app/studio_output.go and its owning test changed. The failed receipt and independent audit are retained; a failure never becomes a passed run.

The preceding integrity-correction qualification freeze is 683daca0e522193c7ff1b0de6ac2fee5d2fca080811bf184a8dfd5b90a33f224: 123 runtime inputs hash to d346ad15cd4239004e32e1b9f30d727eaf156be0187dc165ca874032a7cf962a, and 212 complete CLI inputs hash to 2abd1a044d8192b07f9bbc06b55dc8b4544d66ca17b8867971cec702ba3af088. The 0.5.0-r8-local Darwin arm64 candidate is 74ad94e73557f6538cd64edd1766d6df92c596d98411031159d94af072c186ec. The observed integrity-correction receipts below bind that source scope; old R2 Linux and earlier R8 binary receipts retain their historical scope. The later one-test fixture amendment has its own complete source identity and completed formal qualification boundary, recorded below.

The current complete source freeze is now 196245a3ba09305e34b86539c8eb79f1473e4373ee47aa1f56f8933b04a42d43. The 123 runtime inputs remain exactly d346ad15cd4239004e32e1b9f30d727eaf156be0187dc165ca874032a7cf962a; the 212 complete CLI inputs are 2c487bfb4c65ed40ff78356b2860de627e6ac1afa0da2df433b09345dab7f5b0. Only the owning published-cache test changed, to source 54c10ef89310256b5f4c165c7de5de9668e1d4d2991b71751076680141dbe779. The fixture amendment is separately guarded; production bytes and all semantic assertions remain unchanged. Formal qualification of this complete source, including current eight owning gates, reproduced archives and full plain-Go AMD/ARM runs, passed. Root A18 proof 2c018cb2afa3f26699a9e6b5a0971096246b12405fde5a27e43a9e213e46da60 binds all three declared supported targets and five reproduced archives. Earlier receipts retain their captured inputs; they are not relabeled as runs of this amended test source.

Current proof and preserved earlier input boundary Observed result and bound receipt
New complete-source formal qualification Freeze 196245a3ba09305e34b86539c8eb79f1473e4373ee47aa1f56f8933b04a42d43, owning test 54c10ef89310256b5f4c165c7de5de9668e1d4d2991b71751076680141dbe779, unchanged runtime123. Current eight gates, host/archive and both full plain-Go Linux flows passed, bound by root A18 proof 2c018cb2afa3f26699a9e6b5a0971096246b12405fde5a27e43a9e213e46da60; this does not claim final document bytes were already rendered
Narrow integrity correction Owning receipt 6966d768025497b45958073d4c53a2a2981065c8a95857834dcf6a4faa4f0201; independent audit 6cb5d2eabf57b41079026a38a674f46def9f56a15df17ad27e671e4f765798df
Prior-source six frozen owning gates Build, full offline Go unit/vet, whole actual Hugo/pinned tools, core race and public R8/output-helper race all 0; elapsed 3.501/68.257/3.909/333.801/37.070/79.670 seconds. Summary b40b7787b3da8dc1e0763812b6dde529b4b5b69fe479d79940f1161223124e1d; independent audit 20780662b7ff35019b2c8c84e6dc763f9351ae0816f6ef7a7789f7a15be99167
Eight current frozen owning gates Selected published-cache actual Hugo and race, build, full offline unit/vet, whole actual Hugo/pinned tools, core race and public R8/output-helper race all 0. Current summary d6272fcc4dfab114aecfcdf19a7e2b78f1e931817331b460f43ff2056bf754a4; raw whole Hugo has 435 top-level passes, no failures, two optional top-level skips and the explicit long-path socket child skip. Runtime/binary bytes remain identical
Prior-source Darwin arm64 and archives Current extracted candidate runs outside the checkout with no consumer Node requirement. Seventeen commands and eight actual process tests, including child signals, passed without process-test skips. Two fresh release directories contain byte-identical five archives and checksums; source/license/provenance/canonical tar checks pass. Summary bcb4d7599e965c1b3cfe7fe698ca14061ad53d45e7a194337aeebb8d37aa77c1; independent audit 60a04771365d8be15ac91fbbd8d485b019aae081598e468018861ca5734e387c
Current Darwin arm64 and deterministic archives Seventeen extracted-archive/ordinary-Hugo/process commands passed expected exits, with missing Hugo explicitly 2; eight actual signal/process cases ran without skips. Two independent fresh builds reproduced five byte-identical archives from current complete source. Summary 3890fd8468b6bce5271bb32ffa1a18bd5daf99c19c43becac0be8e3b908a5d57; source, tools, module-cache and smoke-source guards remained equal
Prior-source Linux arm64 Actual nonroot Linux arm64 on ext4 with Go 1.27.1, Hugo Extended 0.166.0 and Git 2.47.3: full offline Go unit/vet, all 13 required pure top-level pass records and the membership case plus its four children without skips, 10 selected actual-Hugo cases without skips, native rebuilt archive identity, installed bilingual/offline/ordinary-Hugo/missing-Hugo 2 JSON and signal/source-mode checks passed. Guest summary 409990bc1425f4bf219f8911a71581af6e68729865580121dbeb6d85a06d2ea7; outer receipt a022e40f068703cd59ce6d6a7fb6530cce6907681baa26eb1dfc77c09f0c8898; exported-record audit 24afc50f6f860394d1ebfa7a8b754ddd9cb97f9e88a0dcfcbcb659193ecbfe5f
Current Linux arm64 Current nonroot Linux arm64 on ext4, native ARM through QEMU HVF, Go1.27.1/HugoExtended0.166.0/Git2.47.3: full offline unit/vet (370 top-level passes), all13 decisive pure cases and4 membership children without skips,10 selected actual-Hugo cases without skips, exact native/installed current archive identity and bilingual/offline/ordinary-Hugo/signal flows passed. 24 commands reach expected exits including missingHugo2. Guest 268102f69c0950f9d2994d22cd2fd290fc11e24bd6d6f916fd70a93ca4946c74; outer f3c066fdc9b97feff92160346185a1af978a5172eed5c81904ac7c0e5fc6c982; source/SDK/borrowed/old-task guards equal and owned VM reaped. Default optional unit skips retain their named gating reasons; no full Linux Hugo-suite/browser/linter claim
Prior-source Linux amd64 failed trial Unqualified after the preserved current TCG trial failed: outer receipt 3543664ba5590f2ba5a8f676b196bb636b72bc819913289f415d0a8a841c1bdb, guest summary 16075204d287713c7f7650c0a65dd289dd4bd83db07c9ba4b85b3f21244d5240. Full offline units (370 top-level passes), vet and the first three selected Hugo cases passed. The published-cache candidate request hit the test HTTP client’s 90-second deadline; candidate parity, the remaining six selected Hugo cases, native rebuilt archive and installed archive smokes were not reached. Deadline review 12917b9eb89e3abc5893e08da3b6b6e20743dcb4c14e6f7ba8561628e3566934. A18 stays open; no future preflight or full qualification result is inferred
Current Linux amd64 Current nonroot Linux amd64 on ext4, QEMU TCG emulation, Go1.27.1/HugoExtended0.166.0/Git2.47.3: full offline unit/vet (370 top-level passes), all13 decisive pure cases and4 membership children without skips,10 selected actual-Hugo cases without skips, exact native/installed current archive identity and bilingual/offline/ordinary-Hugo/signal flows passed. 49 commands reach expected exits including missingHugo2. Guest 3a1a32979efc843de8b95b7c13824026e17f71c06d4c458b738c0b9583fb4723; outer 30cf4950cc83fa0732047d9a0f89bb59e68779ee2e8f5c755724c9679be265e3; source/SDK/borrowed/old-task guards equal and owned VM reaped. Default optional unit skips retain their named gating reasons; no full Linux Hugo-suite/browser/linter claim
Runtime-equivalent preceding four-consumer candidate corpus Source epoch 683daca0…33f224; runtime123/binary74ad is byte-identical to current 196245a3…42d43. The corpus was not rerun after the test-only amendment. 853.249 seconds; native/candidate-native 0/0/0/1, API/view 0/0/0/2; diagnostics 28/144/120/11250, coverage 29/34/41/29. Summary a1e98ca3e10095a1134381666bacf256f8e8827cd3900c9e811b7120de4c2974, receipt 05c4562a50d9f83ba2c99879ec841870c5e753199e41792bd5bc718cf8046e7b, independent audit 3a1b0b6e3a8c6b1a0d82c5f82b46c84b1e44d6c30bab655610cb9e86e6a30b47; final TEN bytes have their own render boundary
Final canonical lifecycle and rendered checks The exact promoted TEN bytes require independent canonical rendering and navigation/URL receipts; earlier rendered proofs do not qualify these amended bytes

The preceding six-gate b40b7787b3da8dc1e0763812b6dde529b4b5b69fe479d79940f1161223124e1d, host/archive bcb4d7599e965c1b3cfe7fe698ca14061ad53d45e7a194337aeebb8d37aa77c1, and ARM outer a022e40f068703cd59ce6d6a7fb6530cce6907681baa26eb1dfc77c09f0c8898 / guest 409990bc1425f4bf219f8911a71581af6e68729865580121dbeb6d85a06d2ea7 / audit 24afc50f6f860394d1ebfa7a8b754ddd9cb97f9e88a0dcfcbcb659193ecbfe5f remain passed only for their captured source. They are retained alongside the new exact-source proof, not overwritten or relabeled. Historical 26 axe checks/screenshots and 22 codec cases are carried with unchanged UI/codec/runtime inputs, not claimed re-executed.

The initial max-CPU AMD trial stays failed: receipt 3543664ba5590f2ba5a8f676b196bb636b72bc819913289f415d0a8a841c1bdb, guest summary 16075204d287713c7f7650c0a65dd289dd4bd83db07c9ba4b85b3f21244d5240. The test client timed out after 90 seconds awaiting candidate headers; candidate parity and the remaining six selected Hugo cases/native rebuild/installed smokes were not reached. Guest inputs stayed exact; the host guard recorded only a .git directory timestamp change, whose cause was not proven. The separate qemu64 one-test preflight also failed at the unchanged 90-second HTTP client deadline: outer receipt fc68173ccdfd8ce263ecdf082a533d9da666a4cc2e1e5e29880ee827286132ac, guest summary e350ff65feeee166ffac1d337db9bbd70d3895b1fb6d93df0a30ca4de09019fc. The named case took 177.71 seconds, compared with 176.64 seconds in the first trial; no CPU-model speedup is inferred. Its inputs remained exact and its VM was reaped. Neither failed trial is relabeled as a pass.

A later, explicitly nonqualifying Go-overlay diagnostic preserved the same production source and every original semantic assertion. Outer receipt 0bc6d563b7cd9ca862717c2123ee0836d83b6b927d00204a0b031049c38e93f0 and raw-bound classification 66a1422cdb79ab9f1cf683f441ade0ce4adb4a7a666d524c4b9ed98ebee28708 record a passed named case in 352.40 seconds. Original capture took 26.254 seconds, Studio capture 26.211, candidate HTTP 94.312, direct preview 94.318 and CLI preview 81.962. Both graphs retained 1,256 unique inputs, including 1,198 module inputs. The old original-capture context was expired by the HTTP result; fresh independent direct/CLI contexts completed normally. All 20,564 host guards and five guest command guard pairs stayed exact; the owned VM was cleanly reaped. This diagnostic altered test budgets and is not exact-source or full A18 qualification. The scoped owning-fixture amendment now uses a 300-second budget for that candidate request and fresh direct/CLI operations, about 3.18 times the slowest observed operation. General/original-capture 90-second limits, restoration of the shared client, shutdown 15 seconds and Go’s default ten-minute cap remain unchanged. These are test fixture limits, not a product performance SLA. Formal plain-Go AMD/ARM and current archive qualification is recorded in the current table above; the diagnostic itself remains nonqualifying.

This preceding corpus qualifies the unchanged runtime CLI against its captured, unchanged pre-final-TEN consumer inputs. It does not qualify subsequently amended canonical document bytes; the final TEN has a separate rendered receipt boundary.

The consumer driver compared complete typed diagnostics, coverage, native exit, PlanID, selected Base/After/full modes, unified diff and selected source between API and CLI. It separately verified the complete literal API review and its hash. For attachments and no-ops the selected page retains reviewed Base; page-file edits match reviewed After. Nonissue views are bounded samples; all issues and pages are paginated. The 53 protected operations have 212 all-four per-operation source proofs plus four overall proofs (864 raw inventory pairs across four categories) and 53 root pairs. Seventy-one retained artifacts are bound. No Apply, saved plan or consumer write occurred. The completed corpus’s file-only collector needed two preserved metadata corrections for absent historical trial/self-test files; no CLI/Hugo operation was rerun. The existing 22 negative codec cases are historical checks of unchanged codec bytes, not a newly executed self-test.

The repository retains its 10,462 pre-existing duplicate-ID findings and 788 review-info records. Its selected actual DFE HTML is available, while four oversized actual PRINT files stay unserved (413, zero response body): _print/pkg/index.html 73,976,221 bytes, _print/pkg/pgsql/index.html 69,903,999, zh/_print/pkg/index.html 73,086,240 and zh/_print/pkg/pgsql/index.html 69,052,754. The 64 MiB per-file preview bound is unchanged: required partial-preview incompletion remains 2, native findings remain 1, and Apply is refused. This is an expected diagnostic outcome, not a failed preservation check.

Linux prerequisites were prepared in exclusively owned guests from signed Debian metadata: exactly ten new packages and three approved existing-package updates, verified before and after installation. SDK/Hugo/module caches were provisioned separately and reused offline. Qualification runs as an ordinary user on ext4; cached inputs and all 212 source files’ bytes/full modes stay guarded. Optional tools/browser tests are not silently claimed on guests without those prerequisites: default unit skips retain their actual gating/not-applicable reasons, while all required pure top-level cases, the no-skip membership children, selected Hugo and signal cases must execute. Linux amd64 uses QEMU TCG on the ARM host and is explicitly emulated. Darwin amd64 remains an experimental archive: actual execution returned Bad CPU type (errno 86), with no Rosetta installation or claimed supported runtime. Windows is outside the declared scope.

The current Linux archive digests are ac883e54a1df0b820696279c63881ba75a00d279f507330128fe8d5aff59c52e (arm64, 4,552,687 bytes) and 2dde43bf94ef35aac2111b07dcb9b2766fbf9f883fe39ccd646d14a98b94d734 (amd64, 5,034,668 bytes). The preceding 683daca0…33f224 archive digests c191383af21913be6940ec41be11755b3d985344bbc0f65cc3f5de16424a96a4 and 6531b27d889260afe804c1f49f37541fbae46e57b5d17a20178c28cb51968794 remain historical. Cross-compilation alone does not establish runtime support. SDK/guest preparation failures, the first ext4 membership failure, and earlier private host metadata/resources trials remain immutable evidence. Local completion does not establish a commit, public release, consumer adoption, hosted CI execution, deployment or public-site verification. Uninvoked E1–E4 extensions are separate inactive scope and do not hold finite R1–R8 completion open.

Acceptance case ledger

This ledger combines the initial audit with accepted R1–R7 evidence and the qualified R8 candidate gates. Each full case stays open until its entire outcome is recorded; an accepted stage does not close later-stage scope.

Case Required outcome Code or checker evidence Status and missing decisive evidence
A01 One oink.result/v1 JSON result; stderr logs; policy 1, required incompletion 2 Protocol/public R1–R8 commands, frozen owning tests and exact-binary CLI/API reports; unchanged result schema; current eight owning gates/Linux qualification plus unchanged-runtime carry-forward of the preceding corpus in #a18 Passed supported current command scope; future added commands require their own evidence
A02 Hugo resolves slug/url/permalinks/aliases, mounts, unlisted pages and language roots Real PageFacts/manifest/custom-mount/translationKey fixtures; preserved ordinary artifacts; final consumer facts R1 scope passed; later stage-specific use of those facts requires its own acceptance
A03 Definite local missing routes fail; outside origin/path and declared external scope classified honestly Actual rendered-reference fixture plus subpath/policy regressions and final real sites Passed the required A03 scope; external availability remains explicitly unchecked
A04 Filename, directory and translationKey; duplicate/missing/draft cases; strict/localized policy R2 translation engine, actual Hugo/public commands, final reports and numeric supplement Passed R2 required scope
A05 Absent record unknown; changed source/translation hash visible; no mtime inference R2 hash/status/diff, public preview/apply and final reports Passed R2 required scope
A06 Real fences, inline code, shortcodes, HTML, attributes, unknown fields and protected text boundaries R2 actual syntax/provenance fixtures, reviewed corpus and final reports Passed R2 required scope; catalog and unsupported-source limits remain explicit
A07 Acknowledged findings visible; new findings block per policy; required unavailable tools cannot pass R2 baseline/public plans; R6 fake/actual protocol, missing/unsafe/offline/network-uncertainty and required-precedence fixtures passed Supported scope passed; required unavailable/uncertain tools remain 2
A08 Post-check bytes invalidate manifest; provider uploads verified tree without another build R3 manifest/export/tampering/public one-build tests; final ordinary-Hugo comparison and provider rehearsal Passed R3 required local scope; provider upload not executed
A09 Both CI templates; custom workflows preserved; permissions/variables/provenance and stale plan protection R3 offline generation/bootstrap, public preview/apply/stale-input tests, custom workflow supplement and local rehearsal Passed R3 required local scope; custom workflows remain unknown and unchanged; hosted CI not executed
A10 Reject HTTP 200 fallback, wrong language/build, missing resource/canonical mismatch; incomplete timeout/auth/rate-limit R3 explicit-network local HTTP and public result fixtures, including required identity absence Passed R3 required fixture scope; public deployment and browser runtime not verified
A11 All declared profiles/languages; target protection; ordinary Hugo; unknown editor settings retained R4 24 ordinary Hugo/public profiles, full Starter authoring/editor flow, snippets, actual mounts, source identities, JSONC preservation and external schema reproof Required supported R4 local implementation/corpus scope passed; documented unsupported editor inputs remain explicit
A12 Readable diff and route comparison; dirty/workspaces/replacement/vendor; recovery/concurrency Frozen actual-Hugo seven synthetic pinned cases, public upgrade, source/external guards, observed alias retarget and guarded partial rollback Required bounded R4 local implementation/corpus scope passed; unknown redirects/multihost remain incomplete and no automatic config migration is claimed
A13 Deleted B finds unchanged inbound A; translations/attachments/derived outputs; global full scope R5 committed Git/actual Hugo deletion, alias-inbound, global/uncertain input and unavailable-baseline fixtures; exact-binary consumer reports Passed required supported R5 scope; unavailable or unproven historical inputs stay explicit 2
A14 Candidate before apply; stale/hash/write failures preserve later edits; ambiguous references unchanged R2/R4 shared safety, R5 full-mode/inventory moves and R8 regenerated intent/fresh-input candidate validation, guarded writer and stale/late-editor/attachment tests; current eight owning gates/Linux qualification plus unchanged-runtime carry-forward of the preceding corpus in #a18 Passed supported R5 CLI and R8 CLI/Studio editing scope; ambiguous or unavailable required inputs still block
A15 Workspace/direct parity; selected writes only; bounded context with paths/versions/reasons; no content execution R5 bounded captured-source/context fixtures and four-site queries; R6 registry/direct/aggregate parity and explicit-name saved apply with other sites preserved Supported context/workspace scope passed; no implicit batch writes
A16 Five useful CLI-parity views; keyboard/mobile/light/dark; source/preview isolation Accepted R7 evidence retained; historical source-bound R8 read-only 14 axe/screenshots and Editor 12 axe/screenshots with unchanged UI bytes; current backend gates, ARM and corpus separately verified, native/API parity, preview isolation, four consumers and canonical render passed; current eight owning gates/Linux qualification plus unchanged-runtime carry-forward of the preceding corpus in #a18 Passed supported local views; required partial-preview incompletion/native findings remain visible; no universal browser/platform claim
A17 No-op bytes; YAML unknown/comment/order preservation; stale-save and attachment collisions rejected Corrected frozen core/public/guarded-writer race, actual Hugo/tools, source-bound Editor/read-only browsers, exact-binary four-consumer proposal parity/preservation and guarded canonical source/render passed in #r8; current eight owning gates/Linux qualification plus unchanged-runtime carry-forward of the preceding corpus in #a18 Passed supported local editing scope; required partial preview/native findings still block Apply; final A18 separate
A18 Actual declared macOS/Linux runtimes; child signals; provisioned offline runs; honest unsupported inputs Current freeze/source and repeated five-archive reproduction; Darwin arm64, native Linux arm64 and emulated Linux amd64 nonroot ext4/full offline unit-vet/selected Hugo/native archive/signal smokes passed in #a18 Passed current declared runtime/archive scope; optional guest prerequisites remain explicit skips; Darwin amd64 is experimental/unverified and Windows outside scope

Candidate sites and source preservation

The selected acceptance inputs are the embedded Starter plus three distinct maintained consumer sites. They reuse the historical corpus without writing consumer sources. The Starter source checkout is provenance input; generated profile trials use disposable directories.

Input in the sibling checkout layout Initial observed identity and purpose Current candidate acceptance
oink-starter / generated Starter Source 137843b, two initial status entries; licensed fixed archive, language/profile/root/subpath trials R1 bilingual init/check and R4 all-profile ordinary/public authoring flows passed; archive/license unchanged
oink.pgsty.com Source 907d873 with existing changes; bilingual documentation/regression and explicit local-theme trial Final R1 check and source preservation passed; local-theme evidence remains distinct from public-pin evidence
pig.pgsty.com Source 75050c0, five initial status entries; root Docs/Blog rewrites and nonrendering sidebar entries; declared v1.1.0 Final R1 check and source preservation passed
repo.pgsty.com Unborn main, no HEAD revision; materialized untracked sources, generated catalog and declared v1.1.0 Final R1 check and source preservation passed; revision remains unknown

For each run, record effective module source and versions, flags/network policy, exit/result/coverage, raw evidence location, and preservation outcome. Before/after inventories must include all tracked and non-ignored untracked source bytes and modes, Git status/index state, workspace/replacement files, and effective vendor inputs. Compare exact inventories; unchanged file counts alone do not prove preservation. Keep reports, isolated candidates, output and caches outside consumer sources and outside Git. Full-build timing comparisons must use the same current input baseline before any incremental speed claim.

Owning checks and documentation gate

Start with the smallest affected Go packages and public behavior tests. The existing repository gates are make test (offline tests and vet) and make test-hugo (actual Hugo Starter, snapshot, manifest and public command fixtures). The owning Hugo gate now runs all owning packages without the old narrow test-name filter; new fixtures must remain in that gate. Use a race run for concurrent plan/server changes when the focused tests justify it. Unit fixtures remain offline; networking requires explicit invocation.

For documentation, preserve EN/ZH heading number, order and stable explicit IDs. The narrow source checks are:

node scripts/check-markdown-style.mjs content/docs/design/research
node scripts/check-doc-translations.mjs

Both source checks passed after adding this record and its Chinese peer: eight Chinese research files passed the style checker; translation source coverage was 137/137 pairs with 1,082 source headings. These checks establish source style, pairing and explicit translated IDs only. Rendered acceptance was not run by this documentation audit.

After building the relevant site, complete the rendered documentation gate:

npm run _check:markdown-style
npm run _check:translations
npm run _check:rendered-markdown
npm run _check:rendered-links

make build validates the declared published pin. make check selects the sibling theme for the complete non-browser regression suite; these inputs cannot substitute for one another. Studio requires its own actual browser and accessibility acceptance. A passing prose source check does not prove rendered bilingual output or Studio interaction.

Delivery state and remaining limits

State Current completion evidence; history retained above
Local implementation Finite R1–R8 supported implementation completed locally, including Studio/read-only and opt-in reviewed editing; current A18 runtime/archive scope passed. Canonical lifecycle rendering is bound separately to these exact bytes
Local validation Historical R1–R8 owning/browser/corpus/render records retained; current 2026-10-04 backend correction and eight current owning gates, actual three-target runtime/archive checks and unchanged-runtime carry-forward of the preceding four-consumer preservation/parity passed in #a18. Required repository findings/partial preview remain visible. Rendered navigation/URL checks have a separate exact-byte receipt boundary
Commits Baseline CLI commit identified; no maintenance commit established by this record
Archive and runtime qualification Current corrected source: Darwin arm64, native Linux arm64 and QEMU-TCG-emulated Linux amd64 passed installed archive/offline/signal/filesystem flows; two fresh builds reproduce all five archives. Darwin amd64 remains experimental/unverified after actual failed execution
Public distribution and consumer adoption Not performed by this work
Deployment and public-content verification Not performed by this work; local HTTP fixtures can prove the verifier without cloud credentials

The finite R1–R8 implementation and required current A01–A18 runtime/archive scope have decisive local evidence. Canonical lifecycle rendering requires a separate receipt for these exact new documentation bytes; preceding rendered evidence does not qualify them. Uninvoked E1–E4 and experimental/unsupported platforms do not add unfinished core requirements. Publication, pushing, deployment, hosted CI and consumer writes remain separate unperformed actions; known repository findings and required preview incompletion remain diagnostic limitations, not hidden successes.