CLI maintenance acceptance on 2026-10-03
This record preserves earlier R1–R8/A18 acceptance. Command changes do not rewrite those results. The reduced CLI and its Cobra/text/JSON/YAML interface on 2026-10-04 are defined by the current contract and guide. Earlier runtime qualification does not qualify a changed binary automatically.
The initial audit is retained below. R1 implementation and owning checks have passed their local scope, including refreshed consumer reports and scoped rendered EN/ZH acceptance. R2’s scoped local gate is also accepted, with a separately tested numeric-equality supplement. R3’s runtime and paired documentation gates have passed and its local stage is accepted. R4 supported implementation and read-only corpus gates have passed locally; guarded canonical documentation validation is recorded separately below. R5 corrected implementation/read-only corpus and guarded canonical documentation gates have passed; its supported local scope is accepted. R6 explicit workspace and optional adapters passed frozen owning/runtime, exact-binary consumer and guarded canonical source/render gates; supported R6/A07/A15 scope is accepted locally. R7 read-only Studio/A16 also passed its browser, four-consumer and guarded canonical rendered gates. R8 reviewed editing/A17 passed its corrected frozen owning/browser, exact-binary consumer and guarded canonical source/render gates. R1–R8 supported scope is accepted locally. The 2026-10-04 supplement refreshes the changed backend and closes current A18 runtime/archive qualification for the three declared targets. Canonical lifecycle promotion/render has a separate exact-byte receipt boundary; public release, adoption and deployment have not occurred.
Scope and evidence rules
The maintenance roadmap defines the authorized R1–R8 scope. The current CLI contract defines its compatibility baseline; the original roadmap does not add Docsy migration, version lifecycle, OpenAPI, theme publication, or the conditional E1–E4 extensions to this program. Hugo remains an external renderer and generated sites remain ordinary Hugo projects.
Stages are accepted in dependency order. Every stage needs a complete usable flow, its owning tests, relevant actual Hugo integration, known limits, a reviewable diff, and accepted EN/ZH contract and guide updates. Passing an aggregate command alone does not close a case. New public behavior moves from the proposal into the owning contract only after its implementation and acceptance evidence exist.
In the tables below, existing, not rerun means code or a named test was inspected but its current runtime outcome was not established. Partial means the first candidate provides a reusable part of the required behavior. Open means new implementation or decisive acceptance evidence is missing. Passed, failed, unverified, and unsupported must describe a specific executed input and scope when later runs are recorded. No historical result is relabeled as a current pass.
Inspected inputs and tools
The initial 2026-10-03 audit read both repositories’ instructions, the documentation README and translation rules, both maintenance PRD languages, the original proposal, the current CLI contract, and existing Go packages and test names. It executed version and Git inspection commands only; it did not run the owning suites or write consumer sources.
| Input | Observed initial state |
|---|---|
| Host and Go | darwin/arm64; go version go1.27.1 darwin/arm64 |
| Hugo | hugo v0.166.0+extended+withdeploy darwin/arm64, Homebrew build dated 2026-09-09 |
| Node and npm | v26.9.0; 11.19.1; contributor/documentation tools, not CLI consumer requirements |
| Git | 2.54.0 (Apple Git-157) |
| CLI source | e623d93d589c49e5c58b8fae1bd5db720fc904cb, main; clean initial tracked/untracked status; generated bin/, dist/, tmp/ ignored |
| Documentation source | 907d873eb05cfc2e194f492462dfa94849e93474, main; 184 initial porcelain entries, including existing proposals, contracts, guides, and unrelated content changes |
| Embedded Starter | 137843b25bacd76ddd1f7ce71330bf2e3155b954; provenance and license already recorded by internal/starter |
| Declared theme baseline | github.com/pgsty/oink v1.1.0 in Starter and the three selected sites; effective resolved bytes still require each acceptance run |
The 2026-09-29 acceptance record contains historical first-candidate checks. It supplies useful reproduction inputs, but does not prove the new maintenance scope. Existing dirty files are preserved; this initial research addition does not accept or overwrite them.
Stage requirements and implementation evidence
| Stage | Required complete flow and invariants | Initial implementation evidence | Acceptance evidence still needed |
|---|---|---|---|
| R1 | Shared page identity, languages, publication state, source provenance, actual outputs, translations and observed references from Hugo; oink.yaml owns check policy only; links/translations/style share analysis; severity and exclusions cannot hide required incompletion; trustworthy locations |
Partial: internal/site isolated snapshots and Page.OutputFormats probe, internal/outputcheck, internal/report; no shared translation/page facts or policy commands at initial audit |
Real Hugo routes, aliases, mounts, unlisted/generated-source cases and language relationships; public focused-check/policy cases; required unknown/tool/build/input failures remain 2; source locations only when reliable |
| R2 | Three language layouts; strict/manual and localized policies; duplicate, missing and draft states; explicit versioned review records bind source language and source/translation hashes; bounded native syntax rules; effective-theme coverage; visible versioned baseline; reviewed fixes validate before narrow apply | Open: no translation/review/native-rule/baseline public command at initial audit; rendered-reference checks remain reusable | A04–A07; valid/invalid reviewed content corpus; no mtime review inference; disabled/localized languages handled; acknowledged findings stay visible; missing required checks stay incomplete; fix preservation |
| R3 | Preserve thin default build/dev; build --check checks and manifests one strict Hugo output, exports only to new/empty target; digest/provenance manifest and optional minimal public identity; both local CI templates upload the same tree; release diagnosis; explicit-network public verification |
Partial: direct wrappers, strict isolated checks and licensed workflow inputs exist; managed build/export, digest verification, CI plans and public verify are absent at initial audit | A08–A10; exactly one Hugo build; stale-byte rejection; revision/dirty/input/theme/tool/settings/coverage provenance without secrets or machine paths; workflow customization/conflicts/provenance and immutable source input; example address policy; fallback/language/resource/canonical/timeout/auth/rate-limit HTTP fixtures |
| R4 | new, snippets and editor setup create ordinary inputs without overwrite; docs/blog/book/project profiles compose one licensed Starter; upgrades provide readable diff and old/new routes, aliases and enabled outputs; unsupported migrations give manual action; existing protections survive |
Partial: fixed archive language profiles and hash-bound single-site module upgrade with candidate validation, backups, dirty/workspace/replacement/vendor protection | A11–A12; all new profile/language combinations build with ordinary Hugo; unknown editor settings retained; upgrade route/capability regression and readable diff; source provenance and licenses retained |
| R5 | inspect, impact --since, bounded context, preview move; shared plans include touched files, diff, base hashes, translations, attachments, output/route changes and alias advice; candidate validation and stale/concurrent-safe recovery; ambiguous references require review |
Partial: module-specific upgrade plan/apply primitives; no shared content plans or inspect/impact/context/move flow at initial audit | A13–A15; deleting B includes unchanged inbound A; translation/attachment/derived-output impact; uncertain/global changes force full checks; no content execution; candidate/stale/failed-write preservation and ambiguous-link handling |
| R6 | Explicit versioned site registry reuses single-site engine; per-site and aggregate completion; writes only to selected sites; configured preinstalled markdownlint/Vale/lychee adapters normalize findings and declare syntax/network coverage | Open: no workspace/adapter public command at initial audit | A07/A15/A18; direct/per-site parity; no sibling discovery, implicit installation or default formatting writes; required missing tool 2, optional omission visible, external network uncertainty distinct |
| R7 | Read-only loopback Studio with overview, issues, translation comparison, page relationships and publication views; filters, known sources, actual Hugo preview, comparisons and copied actions; CLI parity; prebuilt assets; explicit allowlist, separate preview origin, Host/Origin/session protection | Open: no Studio server or assets at initial audit | A16; browser/keyboard/screen-reader/mobile/light/dark/long-list flows; same underlying results as CLI; unauthorized hosts/origins/sessions and preview-to-management requests rejected; Node unnecessary for consumer runtime |
| R8 | Markdown/text and front matter forms, selected components and collision-safe attachments reuse plans; authorized allowed writes with visible diff, hashes and candidate validation; no-op bytes and unknown fields/comments/order/encoding/whitespace retained; unsupported form syntax stays text | Open: editing follows accepted read-only R7; no editor API at initial audit | A17/A14; byte-identical no-op, surgical YAML field updates and text fallbacks; stale external-editor saves, traversal/symlink escapes and preview requests fail safely; attachments never overwrite; no management API in static publication |
R1 local validation
R1 now provides shared Hugo page/translation/source facts, rendered reference
and anchor evidence, strict oink.policy/v1 input, check links,
--format json, visible reviewed exclusions/external scopes and required-work
precedence. Translation and style selections explicitly return required
unsupported coverage; they are not implemented engines. Default build/dev
remain direct Hugo operations. The following evidence accepts the tested
shared-facts/policy scope without closing R2–R8 or the full A01–A18 cases.
| Requirement | Executed evidence | Current outcome |
|---|---|---|
| Public result/policy and incomplete precedence | make test: all packages and vet; public severity/exclusion/unimplemented-group/JSON-alias tests; TestEveryRequiredUncompletedCoverageFails |
Passed R1 scope; any required uncompleted status, including not_checked, remains 2 |
| One build and shared facts | TestPublicCheckSharesOneBuildAndRenderedFacts |
Passed; one strict Hugo build supplies page and observed target/anchor facts |
| Hugo authority and source mapping | Actual TestPageFacts* fixtures: translationKey, actual routes/aliases, unknown generated nodes, custom mounts, excluded-page analysis and failure preservation |
Passed; separate analysis preserves production facts/artifact bytes and source bytes/modes |
| Repeatable real Hugo gate | Corrected make test-hugo includes TestPageFacts* and TestHugoRendered*, alongside Starter and manifest fixtures |
Passed; scoped route/reference, reviewed external-scope and original-output preservation cases |
| Fresh Starter | Bilingual init, check links, ordinary strict Hugo using isolated provisioned v1.1.0 module archives |
Exit 0; 223 files, 4,461 references, 66 page facts; dependency preparation remains explicit |
| R1 documentation source and schema | Markdown style under content/docs; bilingual source checker; JSON parse and equality of CLI/docs result schemas; scoped diff whitespace check |
Passed: 88 Chinese docs, 137/137 source pairs and 1,085 headings; schemas remain additive oink.result/v1 with exits 0/1/2 |
| Final candidate reports and rendered EN/ZH | Refreshed current-binary consumer reports; actual rendered source/Markdown/link owning checks below | R1 scoped gate passed; existing draft-release omission in production is recorded separately |
Earlier offline R1 trials returned 0 without diagnostics on three consumers:
| Earlier trial | Source files | Built files | HTML files | References | Page facts | Bytes/modes/Git inventory |
|---|---|---|---|---|---|---|
| OINK documentation | 421 | 1,139 | 512 | 74,689 | 341 | Exact before/after equality |
| PIG project site | 858 | 1,392 | 424 | 64,440 | 248 | Exact before/after equality |
| Repository catalog | 2,294 | 3,287 | 1,635 | 851,535 | 1,572 | Exact before/after equality |
These earlier reports spell optional unselected coverage not_selected,
outside the existing result-schema enum. The final code corrects it to
not_checked and includes project.pages coverage. Their measured counts and
exact inventories remain valid earlier-binary observations; final JSON
conformance is established by the final reports below. Raw evidence stays in task-named local
acceptance directories outside consumer sources. These trials do not prove
external availability, deployment, Linux runtime or translation/style acceptance.
The final R1 binary was rebuilt from the dirty CLI working tree based on
e623d93d589c49e5c58b8fae1bd5db720fc904cb. The recorded input inventory includes
file hashes, modes and Git-status identity. Its SHA-256, computed over sorted
JSON serialization, is
518260f07f3c916468ee3d56c4eeca03c131514155aa82539564ccd2f3c1f664.
The exercised binary SHA-256 is
3deb7e357fc86f6907df60da0769d93f2d41ba5e01949b641548a67d7f459d12.
This identifies local inputs and an executed binary, not a maintenance commit,
public archive or published module.
| Final current-binary trial | Source files | Built files | HTML files | References | Page facts | Acceptance |
|---|---|---|---|---|---|---|
| OINK documentation | 421 | 1,139 | 512 | 74,755 | 341 | Exit 0, valid result, complete page facts, exact source bytes/modes/Git preservation |
| PIG project site | 858 | 1,392 | 424 | 64,440 | 248 | Exit 0, valid result, complete page facts, exact source bytes/modes/Git preservation |
| Repository catalog | 2,294 | 3,287 | 1,635 | 851,535 | 1,572 | Exit 0, valid result, complete page facts, exact source bytes/modes/Git preservation |
Each final result has check.links: complete and project.pages: complete,
both required. Unselected translation/style coverage is not_checked, optional.
The final offline make test and vet passed; the corrected actual-Hugo owning
target also passed. The recorded tools remain Go 1.27.1, Hugo Extended 0.166.0,
Git 2.54.0 on macOS arm64. The three exact before/after inventories were
independently compared while preparing this record.
Production output passed rendered Markdown and link checks. Its global
translation checker returned 1 solely because the pre-existing draft
content/blog/release/1.2.0.md / .zh.md pair is correctly absent from
production. The changed R1 pages rendered in both languages. A separate explicit
analysis build with HUGO_BUILDDRAFTS, HUGO_BUILDFUTURE and
HUGO_BUILDEXPIRED set to true passed all three owning checks: 137/137 paired
sources, 1,085 headings, rendered Markdown and rendered links. That view is
nonpublishable evidence for excluded sources; it never replaces production
output and does not change or publish the draft. No existing draft file was
modified to make the global production checker green.
R2 local validation
The local candidate now implements translation policy/status/diff/hash review,
syntax-bounded native content rules, visible reviewed baselines and shared
oink.plan/v1 preview/validate/apply. Default check requires links,
translations and style. Production output and the explicit draft/future/expired
analysis are separate; the latter is not publishable. Stable behavior and
examples are in the contract and
guide. The R2 local gate passed owning checks,
final frozen-input consumer reports and rendered bilingual documentation.
The exact exercised binary and the subsequent narrow equality fix are recorded
separately below; no public release or consumer write is implied.
| Requirement | Executed owning evidence | Outcome and limit |
|---|---|---|
| A04 translation relationships/policy | Actual TestHugoFilenameDirectoryAndTranslationKeyLayouts; scope, duplicate/missing/disabled-language, draft, strict/localized and selected-constraint tests |
Passed owning tests; no universal heading/code/localization parity |
| A05 explicit review and diff | Full byte hash/current/source/translation/both-changed, mtime-independent, unknown/unreadable/ambiguous and malformed-record tests; public status/diff/review preview/apply fixtures | Passed owning tests; review state is change evidence, not semantic judgment |
| A06 source boundary and provenance | Actual Hugo enabled/disabled canonical title/block attributes and configured passthrough fixtures; front matter/CRLF/BOM/shortcode/code/HTML tests; every public v1.1.0 source/license SHA verified |
Passed owning tests; unsupported syntax remains incomplete and custom hooks remain outside catalog attestation |
| A07 baseline scope | Capture/visible acknowledgement/new finding/incomplete precedence and malformed-record tests; public baseline preview/apply fixtures | Passed R2 baseline scope; external tool adapter acceptance belongs to R6 |
| A14 shared metadata plans | Stale bytes/modes/existence/guards; edits during validation; exclusive commit collision; partial restore; later editor bytes/modes/deletion; old open inode write; new-directory children; confinement/identity/diff tests | Passed owning tests and vet; candidate/source overlap refused; later move/reference ambiguity remains R5 scope |
| Frozen runtime gates | macOS arm64 make test/vet, owning actual Hugo and focused race runs |
Passed; logs /tmp/oink-r2-frozen-go-gate.log, /tmp/oink-r2-frozen-hugo-gate.log, /tmp/oink-r2-frozen-race-gate.log; final all-owning-package Hugo gate /tmp/oink-r2-owning-hugo-final.log explicitly includes configured passthrough |
| Bilingual documentation | Narrow source style/pairing/IDs, equal result schemas, scoped whitespace and actual production/analysis node checks | Passed scoped gate: 88 Chinese docs, 137/137 source pairs and 1,092 headings; production draft omission separately recorded below |
The frozen parser corpus at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r2-source-corpus-lqx25kwr/summary.json
records parser input SHA-256
a601200ec4fe275d2bd4baf11d4db7d46a2cc6f1674900c1fd801769e55d12de.
Each scope parsed completely with zero findings. The core uses actual Hugo
site-source identities from the recorded configuration; supplemental Markdown
includes disabled/unpublished files and does not invent routes or relationships.
These captures precede the authorized R2 documentation edits.
| Corpus | Unique actual Hugo source files | Supplemental local Markdown | Source inventory files | Bytes/modes/Git |
|---|---|---|---|---|
| Starter | 52 | 78 | 97 | Exact before/after equality |
| OINK documentation | 272 | 274 | 421 | Exact before/after equality |
| PIG | 212 | 212 | 858 | Exact before/after equality |
| Repository catalog | 1,568 | 1,572 | 2,294 | Exact before/after equality |
Preliminary public-command reports at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r2-final-qu_zprps/summary.json
used binary c8d87e6d73d3101fefcb62c5d6845518573c02c400f474dc9f4603afafc774d5
and CLI input inventory d8a75be0e074365a4164b7aaaa27d82a1e844e04406a36c3dd6d39ff2b6e873f.
They precede the final parser/doc freeze and are not final acceptance evidence.
The initial Starter invocation selected the enclosing evidence folder and
returned 2; it was a validation setup error. Selecting its actual site child
returned 0, with evidence in
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r2-starter-27vmi0w5.
| Preliminary check | Exit | Page facts | Built files | References | Translation statuses | Outcome |
|---|---|---|---|---|---|---|
| Correct Starter child | 0 | 66 | 223 | 4,461 | 28 | Complete; 97 source files/inventory unchanged |
| Documentation | 0 | 341 | 1,139 | 74,755 | 144 | Complete; 421 source files/inventory unchanged |
| PIG | 0 | 248 | 1,392 | 64,440 | 120 | Complete; 858 source files/inventory unchanged |
| Repository catalog | 1 | 1,572 | 3,287 | 851,535 | 788 | Completed policy check: 10,462 actual HTML_ID_DUPLICATE findings in existing merged-print output; 2,294 source files/inventory unchanged |
The repository catalog result is a completed finding outcome, not a passing site or implementation failure. No policy was weakened and no consumer source was changed. Informational review states remain visible.
The final frozen-input reports at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r2-candidate-6xzcs7fk/summary.json
exercise binary SHA-256
ff88b407a6cddb9007f94275c65a80ed4c9c4fd13f5e821f9b7a4a8973abaa56
from CLI input inventory
bd8c71b55250a89dc15c7534924bb82a5447d6f2628eba23c8cb3d864309ee9f.
All four exact source byte/mode/Git inventories were independently compared
equal before/after. These reports supersede preliminary public-command trials:
| Final check | Exit | Source files | Page facts | Built files | References | Translation statuses |
|---|---|---|---|---|---|---|
| Starter | 0 | 97 | 66 | 223 | 4,461 | 28 |
| Documentation | 0 | 421 | 341 | 1,139 | 74,825 | 144 |
| PIG | 0 | 858 | 248 | 1,392 | 64,440 | 120 |
| Repository catalog | 1 | 2,294 | 1,572 | 3,287 | 851,535 | 788 |
No final report has incomplete diagnostics. The repository catalog retains
10,462 actual merged-print HTML_ID_DUPLICATE findings and 788 informational
review states; the other sites retain informational unknown review states.
This accepts the tested checking behavior and source preservation, without
calling that catalog a passing publication.
Kept production docs at
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-site-2201601475/public
passed rendered Markdown and links. Global translation checking returned 1
only for the existing draft release 1.2.0 pair absent from production. The
separate explicitly nonpublishable draft/future/expired analysis at
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-site-3698773232/public
passed all three node checks: 137 pairs/1,092 headings, 216 content pages/41,586
text nodes, and 347 pages/48,682 internal links/4,171 fragments. Evidence logs
are /tmp/oink-r2-docs-production-{translations,markdown,links}.log and
/tmp/oink-r2-docs-analysis-{translations,markdown,links}.log. Neither analysis
output nor authored draft replaced production or was published.
A final review identified optional equal_fields comparing JSON 7.0 with
YAML/TOML numeric 7 by representation. The narrow supplement now normalizes
decoded numeric values recursively to an exact rational number tag, preserving
strings versus numbers, map keys and array order. Tests cover decimals/exponents,
negative zero, integers beyond float64 precision, nested differences, source
byte preservation and required incompletion for unrepresentable values.
Actual-Hugo translation tests passed in /tmp/oink-r2-numeric-translations-gate.log;
all public maintenance actual-Hugo cases passed in
/tmp/oink-r2-numeric-public-gate.log; owning vet and whitespace checks passed.
Supplemental source SHA-256 values are:
| Source | SHA-256 |
|---|---|
internal/translations/check.go |
24664377e14b4ae2fc554d0d7fde2ec33cc987707250e130fd88d9a25d5e1637 |
internal/translations/translations_test.go |
f58f4a305fe9fe3f5500ddfcf85faf3cfa37d72f8c220a1cb16ce4ccfbddb74d |
The frozen real-site reports and Linux qualification above/below predate this supplement. Those sites configured no numeric equality constraint, so their recorded outputs are unaffected and were not rerun for this narrow fix. Later full runtime and archive qualification must refresh the subsequent source. The evidence amendments here are authorized documentation writes after the acceptance runs; their before/after preservation scope ends before this amendment.
A18 remains open. macOS arm64 is exercised; an attempted Darwin amd64 runtime
on this host failed with arch -x86_64 / posix_spawn: Bad CPU type in executable
(/tmp/oink-r2-darwin-amd64-gate.log). This is unavailable host runtime support,
not a code failure or Darwin amd64 acceptance. No system installation was made.
Native Linux arm64 and Docker Desktop Rosetta-emulated Linux amd64 were both
actually executed with the same runtime/schema/license input SHA-256
0f786df68ef3c4844c983a51595f79242d1cb1d2bf6c5b5eb7f2c6415fb8d861.
Evidence is retained at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-a18-linux-ajbbnvki
in arm64-results, amd64-results, commands.json, candidate-inputs.json,
preparation.json and qualify.sh. Each target passed 270 test/subtest cases,
with no failures and two optional external corpus/provenance skips: full
actual-Hugo go test ./..., vet, built CLI version/bilingual init/doctor/full
check/translation status and missing-Hugo exit 2 smoke. JSON stdout and source
byte/mode inventories were verified. Go 1.27.1 ran on Linux arm64; Hugo Extended
0.166.0 architecture assets were SHA-verified. This qualifies those source
runtime paths, not final archives or hosted CI. Darwin amd64 remains open;
cross compilation does not close it. Later stages and future command/adapter/browser
acceptance remain open.
R3 local validation
R3 adds managed build --check, oink.artifact/v1 sealing/export/local
verification, explicit-network HTTP verification, release diagnosis and
guarded local CI generation. The default build/dev path remains ordinary Hugo.
The executed runtime and paired contract/guide gates passed; R3 is locally
accepted. Hosted CI and deployment were not executed.
| Requirement | Executed owning evidence | Outcome and limit |
|---|---|---|
| A08 one checked artifact | Public fake/actual Hugo one-renderer tests; exact export, manifest/marker, post-check byte/mode/missing/extra/symlink tampering, failure/concurrency and source-preservation tests | Passed local scope; a failed/incomplete check cannot seal/export; local artifact verification does not rebuild |
| A09 both CI providers | Offline deterministic generation, pinned source/Hugo archives and action revisions; safe bootstrap archives; guarded public preview/apply/stale-input cases; actual-Hugo original-input binding | Passed local configuration scope; every existing generated target is refused and custom workflows remain unchanged |
| A09 upload identity | Both local provider rehearsals and TestProviderUploadRehearsalPreservesActualSealedManifestIdentity |
Passed: one managed build, separate verification, then the same tree; GitHub tar includes the hidden marker, Cloudflare rehearsal receives that verified directory; no provider upload executed |
| A09 custom workflow diagnosis | Generated-plus-other-custom and standalone-custom/no-metadata public tests, actual-Hugo preview and owning vet | Passed supplement in /tmp/oink-r3-ci-custom-owning-gate.log and /tmp/oink-r3-ci-custom-vet-gate.log; each unrepresented workflow stays unknown, informational and optional release.ci: not_checked, including beside valid generated metadata |
| A10 deployed identity | Local HTTP fixtures for all recorded files/routes/languages, marker, canonical/base/inert-template behavior, HTTP 200 fallback, wrong bytes/language/build, missing resources/Markdown/search JSON | Passed local fixture scope; definite mismatches return 1; browser JavaScript is explicitly unchecked |
| A10 unknown network state | Explicit network/credential refusal, timeout before headers/during body, authentication/rate-limit/server errors, required marker absence, bounded body/gzip and redirect/no-cookie fixtures | Passed local fixture scope; incomplete states return 2 with remaining requests unknown; no public deployment was contacted |
| Frozen runtime gates | Full tests/vet, owning actual Hugo and focused race checks | Passed on macOS arm64 in /tmp/oink-r3-frozen-go-gate.log, /tmp/oink-r3-frozen-hugo-gate.log, /tmp/oink-r3-frozen-race-gate.log; the subsequent custom-CI change has the focused supplement above |
The latest single-binary corpus is retained at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r3-ci-final-ahc4csjk/summary.json.
It compiled an exact captured CLI input copy, with binary SHA-256
425845c1d2db7b1cd3c3cdb5f28475cb06ba6f656054909759e2359a39925dd2,
67 runtime/schema/license inputs SHA-256
6789a3a0235ff8d81453b9bfde37824979eac7d56af3710da390e4d2ef8479dc,
and 108 broader CLI inputs SHA-256
4ca473a4cb586d232baeb4cee029b281469c5bb03c831cc199b95451e6832c60.
Runtime inputs remained exactly equal after all runs. Live tools were Go
1.27.1 and Hugo Extended 0.166.0 on Darwin arm64. The manifest’s normalized
Hugo version excludes vendor build text and private paths.
Each run used offline build --check with fresh external destination/manifest
paths, the optional marker and retained isolated work. These existing local
consumer inputs were checked without --release; their configured workspaces
were preserved. Every raw report records exactly one strict Hugo renderer,
zero incomplete diagnostics and zero required unfinished coverage.
| Final managed build | Exit | Source files | Copied source inputs | Page facts | Built files | References | Exported files | Local artifact verify |
|---|---|---|---|---|---|---|---|---|
| Starter | 0 | 97 | 94 | 66 | 223 | 4,461 | 224 | 0 |
| Documentation | 0 | 421 | 427 | 341 | 1,139 | 74,825 | 1,140 | 0 |
| PIG | 0 | 858 | 861 | 248 | 1,392 | 64,440 | 1,393 | 0 |
| Repository catalog | 1 | 2,294 | 2,299 | 1,572 | 3,287 | 851,535 | None | Not exported |
Both inventories compare exact bytes, modes and file types before/after; the primary inventory also compares logical Git state. Git sites include tracked and non-ignored untracked sources; the non-Git Starter includes its existing generated files and lock. The supplemental copied-source inventory also includes ignored workspace/editor metadata read by snapshots, excluding existing generated output/cache trees. Counts alone are not the proof. All four comparisons were exactly equal.
The repository catalog retains 10,462 existing merged-print
HTML_ID_DUPLICATE findings, so neither destination nor manifest was created.
This is a complete policy finding, not a passing publication or implementation
failure. Production review states number 28/143/120/786; analysis includes
unpublished pages, explaining the earlier R2 144/788 counts. Existing custom
workflow information remains visible, and Starter’s example address is a
warning in this non-release run.
The three fresh exports match the retained independent ordinary-Hugo trees
in every original file’s SHA-256, size and mode. The sole extra file is
.well-known/oink-build.json. Their original source inventories and complete
manifest input hashes match the earlier capture, so reusing those ordinary
trees does not substitute different inputs. The helper source SHA-256 is
13e4957a3d7847eb28c8b1eeba3588a4f4a9982c2bfca2ebc729ab2827159607;
its binary SHA-256 is
b2699fe7a7aa3a34c41f9e4aba4b22d39cf8d0c156a369f3dfc4ca8c8c0fbce5.
Raw helper and ordinary evidence are in
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r3-candidate-wb643dhh;
the temporary compilation source was removed after building the helper.
Earlier R3 captures remain historical: the first capture preceded runtime
freeze; the first frozen capture at oink-r3-final-pisrr21h preceded custom-CI
diagnosis. An initial /Users/vonng/pgsty/PIG selection returned 2 because
that different repository is not the intended site; corrected
pig.pgsty.com passed. Those setup trials are retained, not relabeled as
candidate failures. This latest corpus supersedes their managed-build results.
The CI templates/bootstrap are independently authored from recorded primary
provider contracts; no provider implementation code was incorporated.
The scoped R3 documentation gate passed at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r3-docs-render-pljj5aqd/summary.json.
Ten paired contract/guide/roadmap/index/overview edits were installed only after
matching their original bytes/modes; recorded hashes are at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r3-doc-drafts-s0b3g48l/applied-files.json.
Source style passed 88 Chinese docs; translation coverage passed 137 pairs and
1,099 headings; schemas remained equal and scoped whitespace passed. Actual
production Markdown passed 214 pages/41,871 text nodes; links passed 345
pages/48,344 internal links/4,171 fragments. Production translations returned
1 only for the unchanged draft release 1.2.0 absent from production. A
separate explicitly nonpublishable draft/future/expired analysis passed Hugo
and all three owning checks: 137 pairs/1,099 headings, 216 pages/42,177 text
nodes and 347 pages/48,720 links/4,199 fragments. All 421 canonical and 488
copied source files retained exact bytes/modes throughout these rendered
checks. Analysis was not published and did not replace production. This
acceptance amendment follows that frozen preservation boundary.
This gate does not claim hosted workflow execution, uploads, publication, minimum-version combinations, browser behavior or current Linux/Darwin amd64 qualification. A18 remains open; historical Linux R2 results retain their original source hash. Authorized bilingual evidence/contract/guide writes occur after these preservation inventories and are outside their no-write scope.
R4 authoring and upgrade acceptance
The supported R4 implementation and read-only corpus scope are locally accepted after frozen owning/full gates. This record covers profiles, ordinary authoring/editor/snippets and bounded upgrade views. Guarded canonical documentation promotion and fresh scoped rendered validation also passed as recorded below; R5–R8 and final A18 qualification stay open.
| Executed profile evidence | Outcome and limit |
|---|---|
| One fixed licensed archive | Snapshot verification against commit 137843b25bacd76ddd1f7ce71330bf2e3155b954 passed without --write; archive SHA e55bde279715f6d8d19d3d88671a2cf7561b515be46915b0f12c640d0ce1d958 and MIT license unchanged; projection metadata/script match |
| Composition and preservation | Default/explicit project byte parity; selected archived model/localized home, invalid profile, nonempty target, concurrent validation/publication and cancellation recovery tests passed; unit/vet/race gates passed |
| Ordinary Hugo | All four profiles × three language choices × root/subpath passed 24 actual warning-strict offline builds using provisioned public OINK v1.1.0; complete source byte/mode/no-extra-file and rendered-reference checks passed |
| Public init workflow | Four profiles with en/en,zh, actual subsequent root/subpath Hugo URL facts/checks, workflow/license preservation and default parity passed; unknown/nonempty refusals 1, missing/failed Hugo 2, empty/absent targets and pure JSON/separate logs verified |
| Public authoring and source identity | Actual candidate/apply/ordinary Hugo, review-unknown and source preservation passed in /tmp/oink-r4-authoring-public-gate.log; fresh-directory/site guards and vet passed in /tmp/oink-r4-new-input-race.log and /tmp/oink-r4-public-core-vet.log. Actual ignored input refuses 2 without a saved plan or source writes even when source groups are disabled; selected draft peers still force analysis identity in /tmp/oink-r4-authoring-sourceproof-gate.log. Supported owning scope passed |
| Bounded upgrade owning gate | Seven actual-Hugo synthetic pinned module-fixture cases, observed-stream digest/inventory fidelity, independent cross-page alias-retarget blocking, source/concurrency/exclusive installation and later-edit rollback protection passed under race; vet passed. Final hardening logs /tmp/oink-r4-hardening-owning-gate.log, /tmp/oink-r4-hardening-final-focused.log, /tmp/oink-r4-hardening-vet.log; final public/full frozen gates passed |
| Integrated authoring/editor hardening | Actual-Hugo language-directory plan/apply/ordinary builds, link/never new-source refusal, external schema/license/full-mode/module identity and legacy schema reproof, shared translation/baseline/CI regression and full Starter docs→new draft peer→editor→check→ordinary Hugo flow passed. /tmp/oink-r4-app-authoring-hardening-gate.log (58.241s), focused race and vet passed; post-candidate external mutation proof /tmp/oink-r4-app-external-during-validation.log passed. Opaque saved external-input hashes and canonical workspace-origin guards passed /tmp/oink-r4-external-plan-binding-final.log, /tmp/oink-r4-workspace-origin-gate.log and their vet logs. Frozen full-stage, corpus and scoped canonical rendered documentation gates passed |
| Actual language mounts | Standalone ordinary per-language contentDir and explicit site-matrix fixtures each passed config/mounts/strict-render with source bytes/modes unchanged; Hugo0.166 emits sites.matrix.languages and distinct physical files with reciprocal public translations. /var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r4-language-mounts-lgmve1sk/summary.json; public actual language-directory plan/apply/ordinary-Hugo integration passed |
Owning evidence is retained at
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r4-starter-owning-0pv41lw5/summary.json.
Logs are /tmp/oink-r4-starter-{unit,hugo,vet,snapshot,race}-gate.log and
/tmp/oink-r4-public-init-gate.log, /tmp/oink-r4-public-init-vet-gate.log.
Generated source counts are project 94, docs 58, blog 40 and book 34. No Starter
checkout edits, release, consumer adoption or deployment occurred.
Final frozen gates all returned 0: make test/vet
/tmp/oink-r4-frozen-go-gate.log, make test-hugo
/tmp/oink-r4-frozen-hugo-gate.log and actual-Hugo core race
/tmp/oink-r4-frozen-core-race-gate.log. The final public flow includes
Starter docs → primary/translation draft → editor → check → ordinary Hugo;
post-candidate external schema mutation still refuses before source writes.
Seventeen owning and three final gate logs are retained verbatim with hashes
in the final corpus’s owning-gates.json.
The exact four-site evidence is
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r4-corpus-lw2cjyq6/summary.json
with bounded summary.compact.json, raw JSON/logs and per-command inventories.
Binary SHA is c169b3d4d046c811dca80867068b86fb66ada5c8ce6910dd5cda7353c406f377;
82 runtime-input files bind SHA
fdff7f50d49b44f03fa1db79eec6b6c9b9bd5e52f8967a88aed84b3207a7b3c6,
which equals the final root inventory with no runtime changes. The broader
139 CLI inputs bind SHA
562e838d9eccb628eac86ae59b9b9587c1e23ad52991ec50eafb1e604e3924da.
Driver SHA is d3ac41dc2e18295bfb26134d1a696935c8174913e2801a5766dbf7a1139d89f8.
Actual tools were Go 1.27.1 and Hugo 0.166.0 Extended on macOS arm64.
| Frozen consumer | Primary/copied source files | Pages; output files; references | Managed build / artifact verify | Read-only upgrade / new / editor |
|---|---|---|---|---|
| Starter | 97 / 94 | 66; 223; 4,461 | 0 / 0; 224 exported files including marker |
0 / 0 / 0 |
| Documentation | 421 / 427 | 341; 1,139; 74,937 | 0 / 0; 1,140 exported files including marker |
0 / 0 / 0 |
| PIG | 858 / 861 | 248; 1,392; 64,440 | 0 / 0; 1,393 exported files including marker |
0 / 0 / 0 |
| Repository | 2,294 / 2,299 | 1,572; 3,287; 851,535 | Completed finding 1; no export/manifest |
Completed finding 1; new/editor not attempted after blockers |
Each managed build used exactly one strict production Hugo render and had no
required incompletion or uncompleted required coverage. Primary Git-visible
source bytes/full modes/logical Git state, supplemental copied inputs and
source directory modes matched exactly before/after every command and each
complete site flow. Repo’s 10,462 existing merged_print duplicate HTML IDs
remain visible; its completed finding is neither a passing artifact nor an
implementation failure. No policy or consumer inputs were adjusted.
Consumer upgrade previews selected the available public v1.1.0 pin and did not apply writes. Cross-version route/alias/output regressions use explicit synthetic fixture pins, not an invented published theme release. New/editor plans were validated previews; no consumer plan was saved or applied. Multi-host and unknown relative-alias identities stay incomplete. Nondeterministic output may require a fresh v2 plan preview; browser/universal compatibility, configuration migration and current cross-platform/archive qualification remain outside this scoped result. The prior Linux R2 source hash remains historical; Darwin amd64 and final A18 refresh are still unverified. Authorized bilingual canonical writes occur only after this frozen no-write evidence boundary.
Fresh canonical documentation acceptance passed after the parent applied the
ten guarded files. Evidence is
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r4-docs-render-v01eima0/summary.json;
the promotion manifest is
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r4-doc-drafts-3i8bw994/applied-files.json.
The frozen c169b3… CLI performed one strict production render and its focused
link check returned 0.
| Fresh canonical documentation gate | Executed result |
|---|---|
| Source owners | Translations 0: 137/137 pairs and 1,104 headings; complete canonical style 0: 137 Chinese files, 181 strong spans, no emphasis; ten-file whitespace check and public JSON schema equality passed |
| Production rendered Markdown/links | Both 0: 214 content pages / 42,214 text nodes; 345 pages / 48,360 internal links / 4,187 fragments |
| Production translations | 1 solely for the pre-existing draft content/blog/release/1.2.0.md absent from production; no new pairing/heading finding |
| Separate nonpublishable analysis | Fresh ordinary Hugo with the actual original snapshot environment/rebased paths and explicit draft/future/expired flags returned 0; all three owners 0: Markdown 216 pages / 42,520 nodes, links 347 pages / 48,736 links / 4,215 fragments, translations 137/137 pairs / 1,104 headings |
| Source preservation | Canonical 421 Git-inventoried files and 427 copied inputs retained exact bytes, modes, Git state and directory modes; production copied 428 and analysis copied 427 files remained unchanged through their checks; analysis build also retained copied full modes |
Production output remained separate and was never replaced by the analysis
tree; the analysis is not publishable. The temporary helper copied the frozen
core without modifying it: helper source SHA
7faea7e726a6c6fb2e0747be1a4428f4c5fb5734fa52b6f981157a5fe37d9989
and helper binary SHA
532638e76f96f8b173c122e512b3bf5fc2c4d4a7130f59c99c2c69e135e87073
are retained with raw logs. This authorized bilingual research amendment
occurs after the exact no-write capture boundary and receives narrow source
checks separately. R4’s scoped local documentation gate is accepted; this
result does not claim publication, deployment, R5–R8 completion or final A18
qualification.
R5 implementation and documentation acceptance
R5’s supported local scope is accepted after focused public/core, corrected frozen full-stage, exact-binary read-only consumer and guarded canonical source/rendered documentation gates. The bounded outcomes remain explicit below. R6–R8, workspace A15 and final A18 qualification stay open. The first promotion and separately authorized post-render status/evidence amendment retain distinct preservation boundaries.
The actual public Git/Hugo flow at /tmp/oink-r5-public-final-flow.log passed
in 53.963 seconds. Its committed synthetic site owns its local theme, bilingual
pages and binary attachment; ordinary modes 0640 and 0600 remain full
current facts while historic Git comparison uses executable bits only.
Deleting B selects unchanged inbound A, the remaining translation, removed
attachment and actual RSS output. Actual alias-inbound uncertainty, global
configuration/template/data and unknown-input changes expand full scope.
Completed inspect/impact/context returns 0 with separate current-check
findings 1; check-since retains current quality 1 and full validation scope.
Missing/unborn/foreign history returns 2, retaining every known current
page/attachment/reference/output with no fabricated prior identity or change.
Malformed selectors/limits, missing tools and failed renderer logs are tested.
Bounded context gives reasons/versions/source and excerpt hashes, visible
omission/truncation and no execution of literal document instructions.
Saved move preview/apply and subsequent ordinary Hugo passed, retaining
binary bytes, raw full modes, unrelated files and Git index/revision. Actual
opaque HTML/shortcode references remain manual; inline/fenced/opaque spans
stay unchanged. Their broken final candidate returns 1, with no saved plan
or source writes. Source/config/attachment/mode/fresh-target drift returns 2
and preserves the later edit. A deterministic mutation after the actual
candidate renderer also refuses before writes and preserves editor bytes/mode.
Focused actual move race passed in 8.286 seconds at
/tmp/oink-r5-public-move-race.log; app vet passed at
/tmp/oink-r5-public-vet.log.
Before the cached-module supplement, frozen parent make test/vet and
make test-hugo both passed at
/tmp/oink-r5-frozen-go-gate.log and /tmp/oink-r5-frozen-hugo-gate.log
(actual app fixtures 185.709 seconds). Actual move/source race and vet passed
/tmp/oink-r5-move-hugo-gate.log, /tmp/oink-r5-source-move-race-gate.log
and its vet counterpart; full inventory/mode/selector plan safety passed
/tmp/oink-r5-plan-owning-final.log.
A first frozen consumer trial exposed an actual cached-public-module guard
gap: resolved module inputs present in the original graph were absent from a
fresh outer candidate hash. It returned false incomplete 2, without source
writes. Content plans now resolve/capture the same module inputs before
comparison, retaining legacy metadata/authoring plan scopes. The separate
checksum-verified public OINK v1.1.0 regression passed preview, fresh saved
apply and ordinary bilingual Hugo in 27.42 seconds (package 28.220) at
/tmp/oink-r5-public-cached-module-move.log, including raw modes, binary bytes,
unrelated inputs and Git preservation. Corrected current-binary corpus and
supplemental race evidence remain separate from the earlier unaccepted trial.
The corrected current candidate passed full make test/vet at
/tmp/oink-r5-corrected-frozen-go-gate.log and actual make test-hugo at
/tmp/oink-r5-corrected-frozen-hugo-gate.log (app 278.787 seconds). The
cached/public and committed/in-site move safety race passed in 38.578 seconds
at /tmp/oink-r5-public-cached-seam-race.log; its app vet also passed.
/tmp/oink-r5-corrected-runtime-freeze.json records 96 runtime inputs with
SHA-256 e5b6e0eda972116dbb94a8086668e6ef34bfaa56138cf31f1f71f4832c477842
and 165 broader CLI inputs with SHA-256
4965a0c92cb6126f67a6dabd548c7c25ee5d7c9c57e14cce5e55ebb7a22fca2d.
The corrected binary SHA-256 is
d7675aecca2f77b1eb37bb4f664c3314cf5207149e6abbb86523686c5c50bff0.
These are local working-input/executable identities, not a new commit or
published archive. The corrected four-consumer capture completed 16 commands
in 831.825 seconds at
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r5-corpus-corrected-y2eue81h.
Its bounded final-receipt.json has SHA-256
b86e0e6c7dbfbaed62c845c03a55d963068f7d9a16771de5ff3b0974e76fce3b;
the receipt retains 12 copied owning gate logs, all 20 observed move routes
and links to the complete raw JSON/logs and per-move classifications.
| Site | Primary/copied inputs/directories | Inspect/context | Current check | Impact | Move preview |
|---|---|---|---|---|---|
| Starter | 97/94/21 | 0/0 |
0 |
2: no Git baseline |
0: validated, unapplied |
| Documentation | 421/427/109 | 0/0 |
0 |
0: complete historical comparison |
1: six candidate missing references |
| PIG | 858/861/52 | 0/0 |
0 |
2: historical foreign-input provenance incomplete |
1: 32 candidate missing references |
| Repository | 2294/2299/48 | 0/0 |
1: 10,462 existing duplicate HTML IDs |
2: unborn HEAD baseline unavailable |
1: the same existing duplicate IDs |
Starter and Repository impact retain known current facts without inventing
prior pages or changes. PIG’s actual baseline is complete (theme v1.0.0 versus
current v1.1.0), but required foreign-input provenance is incomplete, so the
comparison expands full scope and returns 2. These are distinct outcomes.
Documentation impact completes with 192 captured input changes, 343 affected
prior/current pages and full scope. All completed fact queries expose current
quality findings separately; Repository inspect/context remain 0.
Documentation move proves 18 rewrites and four routes. Two ordinary literal
/docs/admin/comments/ occurrences in content/docs/customize/repository.md
at lines 216 and 313 remain manual because repeated source/output occurrences
cannot be attributed precisely across ordinary and print outputs. Their six
missing candidate references block validation. PIG moves two Markdown files
and four binary attachments, with eight proven page/processed-resource routes.
Equal-byte paired outputs prove processed featured_hu_* resources, but not
new URLs for the four original absolute image references
/article/pgext-day/{featured,topic,venue,schedule}.webp. Their 32 candidate
missing references block validation; no guessed original-asset rewrites occur.
These ordinary Markdown limits are separate from opaque HTML/shortcode limits.
Repository move proves ten rewrites and four routes; its candidate has only
the same 10,462 existing duplicate-ID findings, with no new missing reference
or required incomplete finding. Starter’s zero-link bilingual move is
validated. All four moves remain unapplied, no consumer plans were saved and
no consumer source writes occurred. Failed candidates have validated: false.
All JSON stdout is pure. Primary/copied inputs, full modes, directory
inventories and logical Git/index state are unchanged; ignored copied inputs
are included. The Git metadata inventory excludes immutable object storage.
The runtime and broader CLI inventories still match the captured identities.
The receipt does not qualify another platform, browser runtime or deployment.
The first ten-file guarded canonical promotion was qualified in 62.37
seconds with the corrected frozen binary and runtime hashes above. The
separate rendered receipt is
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r5-docs-render-ks2tw82c/summary.json,
SHA-256 06ae844a4b3f1c01bb5faa8a21091d5461c28aab592d12c4310fb34bc176c5d4.
| Canonical documentation gate | Executed result |
|---|---|
| Source owners | Translation 0: 137/137 pairs, 1,109 headings; style 0: 137 Chinese files, 181 strong spans, no emphasis; scoped whitespace and public JSON schema equality passed |
| Frozen CLI | Production check links returned 0 using the exact corrected binary |
| Fresh ordinary production Hugo | Build 0; Markdown 0: 214 pages/42,571 nodes; links 0: 345 pages/48,376 links/4,203 fragments |
| Production translation owner | 1 only for the pre-existing draft release-1.2 omission from ordinary production output; no new R5 discrepancy |
| Separate ordinary analysis Hugo | Fresh nonpublishable -DFE build 0, without the CLI probe; Markdown 0: 216 pages/42,877 nodes; links 0: 347 pages/48,752 links/4,231 fragments; translations 0: 137 pairs/1,109 headings |
| Input preservation | All per-command and overall guards passed: 421 primary files, 427 copied inputs, 109 directories and 36 mutable Git files retained bytes/full modes/logical Git state; both isolated source copies remained unchanged |
The analysis tree did not replace production output and is not publishable.
The permanent first-promotion applied-files.json in
/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r5-doc-drafts-t3_klnck
retains the ten authorized files and their original modes. This separately
authorized post-render amendment touches only six paired proposal/index/research
files, after the recorded no-write boundary; the qualified contract and guide
bytes remain frozen. Its guarded originals, prepared diff and focused source
checks are retained separately. It does not retroactively claim these later
evidence bytes were in the earlier rendered capture, and no full corpus or
rendered rerun is inferred from the amendment.
Core owning logs /tmp/oink-r5-frozen-core-hugo.log,
/tmp/oink-r5-owning-race.log and /tmp/oink-r5-owning-vet.log passed.
A13 impact and A14 move safety passed their required supported CLI scope;
A15 bounded context passed, while workspace/direct parity remains R6 scope.
No consumer source write, commit, publication, network deployment, remote
model integration or incremental speed claim is made.
R6 workspace and adapter acceptance evidence
R6 supported scope is accepted locally after frozen owning/runtime, exact-binary consumer parity/preservation and guarded canonical source/render gates. The supported registry/tool fields belong in the contract and guide. R1–R6 are accepted locally; historical receipts remain intact. A07 adapter and A15 workspace/direct/context supported scope passed the gates below; R7/R8 and final A18 remain open.
The registry is independently versioned oink.workspace/v1: strict one-document
regular YAML, 1–64 entries, at most 256 KiB, exact ASCII names, literal
relative/absolute directories, proven canonical identities and overlap
refusal. Missing-site results stay per-site incomplete while later selected
sites run. Selection preserves registry order; no default named site,
sibling discovery, Hugo settings duplication or automatic multi-site apply is
provided. Optional tools extend oink.policy/v1, with pinned protocol versions,
configuration/full-mode provenance and typed omissions/coverage.
Workspace owning receipts
| Focused gate | Executed local evidence |
|---|---|
| Registry core | Strict fields/document/bounds/names/literal paths, existing aliases/case-inode ancestry, duplicate/overlap refusal, missing-directory listing and exact subset order; go test -race ./internal/workspace -count=1 passed in 1.414 seconds, /tmp/oink-r6-workspace-core-race.log |
| Public actual Hugo | OINK_TEST_HUGO=1 go test ./internal/app -run '^TestPublicR6Workspace' -count=1 -v passed in 10.498 seconds, /tmp/oink-r6-workspace-public-hugo.log |
| Public race | The same workspace public suite with -race passed in 12.426 seconds, /tmp/oink-r6-workspace-public-race.log; excluded commands specifically reject registry selection |
| Vet | go vet ./internal/workspace ./internal/app completed with exit 0, /tmp/oink-r6-workspace-vet.log |
| Public outcomes | Actual bilingual committed fixture sites retain direct diagnostics/coverage/exit parity for links and full checks. A missing first site yields 2 while later clean/finding sites yield 0/1; explicit subsets preserve registry order, invalid unregistered siblings remain untouched and human output retains findings |
| Selected application | Saved translation-review preview is validated but unapplied; a different registered name is refused before writes and preserves plan/source bytes/full modes/Git. Explicit matching-name apply writes only its planned review file; other registered and unregistered sites remain unchanged |
These are owning fixture outcomes, not consumer adoption or permission to apply
plans to actual consumers. The inspected core workspace.go SHA-256 is
cf2cbc9509e8c83eedf6d8833c9eb0ea6492de9a85c959798112fa3f105213f4;
its owning test is
9070a8e2c3e58680f6567f2394160ec682bf0457c068c2addf354921e7612d6b;
the public test is
3e57a6417ae2e7604f7cb06933759bb06a2f40758ff7059848593cedbaa6570a.
All three inspected files retain mode 0600. These owning source captures are
covered by the frozen all-runtime inventory below; their individual hashes do
not identify the exercised binary.
Corrected protocols and stage gates
| Protocol or gate | Recorded status |
|---|---|
Actual markdownlint-cli 0.49.1 and Vale 3.24.0 |
Corrected public trial passed: exactly one finding mapped to the original UTF-8/BOM/CRLF line; excluded front matter/shortcode/math/raw HTML/enabled attributes/code produced no false original attribution |
Actual lychee 0.24.2 |
Corrected trial actually reached the local HTTP fixture: 200 → 0, 404 → 1, 401/403/429/503/timeout → required 2. Optional offline → 0, required offline → 2, both with zero HTTP requests |
| Final focused actual-tool receipt | /tmp/oink-r6-public-actual-tools-final.log passed in 15.192 seconds; the earlier corrected 14.686-second run is retained as prior evidence. Node preload and discovered JS configuration did not execute; source full modes/Git were preserved |
| Fake/protocol failure receipt | /tmp/oink-r6-public-fake-tools-final.log passed in 13.089 seconds: malformed output, version mismatch, timeout, unsafe configs, required missing/optional/group omissions and raw stderr normalization |
| Focused public race/vet | /tmp/oink-r6-public-tools-race.log passed in 30.273 seconds across fake and actual cases; /tmp/oink-r6-public-tools-vet.log completed with exit 0 |
| Frozen runtime inputs | Parent freeze at 2026-10-03T10:58:01.807947Z, /tmp/oink-r6-runtime-freeze.json: 103 runtime inputs bind b85affd96378b45bfc56a996b0c5672d02ee4c6cc9bc95335fa5072f6c42a03b; 179 broader CLI inputs bind fbb8176ebc58f1aa26336f4e6036cf9bd5f7a0d62b142f16532b50a8071e9fbe. The exercised 0.3.0-r6-local binary SHA-256 is aa8b347fbe01071f9da729f4d98aa2f50d7264456be6c5f05771bcfadadc371f |
| Frozen owning suites | Full Go/vet completed with exit 0, /tmp/oink-r6-frozen-go-gate.log; full actual Hugo plus pinned tools completed with exit 0, /tmp/oink-r6-frozen-hugo-gate.log (app 382.832 seconds). Workspace/core/protocol/source-mask/policy/report race and vet receipts passed and are copied into the final receipt |
| Four consumer sites | Qualified: exact-binary direct/aggregate diagnostics, coverage, exit, identity and registry-order parity for all four sites; per-command/overall source byte/full-mode/type/logical and mutable Git/ignored-input/directory guards passed. Aggregate completed 4, finding 1, incomplete 0, exit 1 |
| Canonical EN/ZH | Passed: guarded first ten-file promotion, source owners and fresh ordinary production/nonpublishable rendered evidence; only the known production draft-release omission remains |
| Stage decision | Supported R6/A07/A15 scope accepted locally after the required receipts; R7/R8/final A18 open; no public release, consumer source write, adoption or deployment |
The durable focused-tool receipt is
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r6-tools-6bf67ltv/r6-public-tools-acceptance.json,
SHA-256 16b6e47fc0618c76d2f9e3680a4112b6e47b478af8aabd3f2fc84821f840cc8a.
It binds the provision record, executable/configuration evidence and 1,422
resolved Node package files. Markdownlint reports original content/tools.md
line 7, bytes[80:92] (ppears here.); Vale reports the same line,
bytes[71:78] (BADTERM). Each of the seven network cases actually makes
one HTTP request. These records do not certify every transitive interpreter,
another runtime target or the full consumer corpus.
The exact-binary consumer receipt is
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r6-corpus-59_asiyr/final-receipt.json,
42,212 bytes, SHA-256
0ad86afaf235bdcff0c474e76b08e0591591a7b22c7992b02e20fb17975d029e;
the completed summary binds
467b66eb6d178829508115050d4243909313acf1b4d59317ecda37ab7383ca55.
It retains 14 copied owning/completion gate logs. The six original operations
sum to 314.912887 seconds, excluding candidate compilation and receipt-only
correction. workspace list returns 0; four direct full checks return
0/0/0/1; the aggregate returns 1 with all four sites completed.
| Site | Preserved source files | Direct/aggregate child exit | Diagnostics/coverage | Recorded finding boundary |
|---|---|---|---|---|
| Starter | 97 | 0/0 |
28/29 | Translation review information only |
| Documentation | 421 | 0/0 |
144/34 | Translation review information only |
| PIG | 858 | 0/0 |
120/41 | Translation review information only |
| Repository | 2,294 | 1/1 |
11,250/29 | Existing 10,462 duplicate-ID findings and 788 translation review information items |
Direct and aggregate child identities, order, every diagnostic and coverage record match. All four consumer sources retain full modes/types, logical and mutable Git metadata, ignored copied inputs and directory inventories after every operation and overall; the complete root CLI inventory also still equals its frozen capture. The 478,603,149-byte direct repository JSON and 635,470,795-byte aggregate JSON were validated streamingly rather than truncated. Optional-tool protocols are qualified by their separate pinned-tool fixtures; the consumer registry is task-local and writes no consumer policy.
The initial acceptance driver overwrote a summarized result’s command string
with invocation argv, producing a false parity exception after all six CLI
operations and their per-operation guards had completed. The failed driver and
summary remain preserved as pre-correction.r6_qualify.py and
pre-correction.summary.json. Receipt completion corrected only invocation
metadata, verified unchanged raw-result SHA-256 values and header commands,
retained all original full-stream diagnostic/coverage digests, and rechecked
overall consumer/root guards. No CLI runtime correction or Hugo/CLI rerun was
needed. The receipt-only completion took 2.002 seconds and exited 0 in
/tmp/oink-r6-corpus-receipt-completion.log.
The executed driver SHA-256 is
4d2a360c6f7f6f96c38698bd189bc4d4b2cb02a7509858920d752897fdd85988;
the corrected driver is
4870f5c0374fcc11ad1a6b2e3aefe36f493b6f9f4666c293993dc6a59df8a11b;
the receipt-completion driver is
cd50d3fe704370f73fa4e7d94ce8e4bc925d11ec8ef04d463aacec37c2053daf.
The streaming helper binds
144f778cdb7907372797b47b97f817f340e70423701a2a958dee589281a9a11c,
and the inventory helper binds
d3ac41dc2e18295bfb26134d1a696935c8174913e2801a5766dbf7a1139d89f8.
This receipt qualifies local darwin/arm64 with Go 1.27.1, Hugo Extended
0.166.0, Node 26.9.0 and Apple Git 2.54.0. It does not refresh final A18,
qualify Darwin amd64 or another platform, apply a consumer plan, publish or
deploy. At corpus capture, canonical promotion and actual rendered EN/ZH owning gates
were separate pending work. The later receipt below closes that boundary; the
first-promotion bytes do not claim this post-render amendment retrospectively.
The initial actual-tool trial was preparation evidence, not a passed
qualification. It exposed Darwin /var versus /private/var staging identity,
actual loopback proxy routing, and an invalid inline-block-attribute/line
assertion in the Vale fixture. Staging is now canonical; the Vale fixture uses
a real standalone block attribute without changing the source-mask boundary.
The qualified child environment forwards literal NO_PROXY/no_proxy host-list
data while omitting proxy URLs/credentials and Node preload settings. Neither
an empty proxy environment nor NO_PROXY=* established the tested Darwin
loopback path; no universal operating-system proxy bypass is claimed.
Supported source diagnostics require proven original ranges; rendered lychee locations remain output file/DOM pointers, with no inferred Markdown line. Offline lychee is not invoked. Authentication/rate-limit/server/transport uncertainty cannot become required success through severity, exclusions or baseline acknowledgement. External fragments, browser execution and remote content identity are not proven. The declarations, output envelope and required-incomplete precedence remain independent from final platform/archive qualification; Darwin amd64 and final A18 are still open.
The first guarded ten-file promotion and its fresh rendered qualification are
now complete. The receipt is
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r6-docs-render-dcwtcmyl/summary.json,
555,297 bytes, SHA-256
ee153932900dc6f1ec62beef1a75927fc60b857efccfbcc558bf0e2c2b12cc04.
The 64.17-second run used the exact qualified aa8b347f…371f binary and unchanged
103-input b85affd9…a03b runtime inventory recorded above.
| First-promotion documentation owner | Actual result |
|---|---|
| CLI production links | 0; one strict production Hugo renderer, no analysis build |
| Ordinary production Hugo / Markdown / links | 0 / 0 / 0; 214 content pages and 43,376 text nodes; 345 HTML pages, 48,438 internal references and 4,259 fragments |
| Ordinary production translations | 1 only for the existing draft content/blog/release/1.2.0.md absent from production; not a new R6 failure |
| Independent ordinary nonpublishable Hugo / Markdown / links / translations | All 0; 216 content pages and 43,682 text nodes; 347 HTML pages, 48,814 internal references and 4,287 fragments; 137/137 pairs and 1,118 headings |
| Source owners / schema | Translation, style and whitespace all 0; 137/137 pairs, 1,118 headings; 137 Chinese files, 181 strong marks, zero emphasis marks; CLI/documented result schema both bind 7468c2d04cde8a368ce0ba44a1f27125b5fca364b6d4672353519b9545b3bdda |
| Preservation | All 12 owner commands, CLI/schema checks and overall comparison preserve 421 primary files, 427 copied inputs, 109 directories and 36 mutable Git files with full modes/types/bytes and logical Git; both private ordinary source copies and all 103 runtime inputs unchanged |
The first-promotion installer receipt,
oink-r6-doc-drafts-ymjop499/applied-files.json, binds
13c965592d64056d8365aed1927d2d422fadec8adc54ee7050b22e2ea0ad6270.
It retains captured actual original inodes in private temporary storage,
preserving later old-open-handle writes; recovery also preserves later target
edits or deletion. The subsequent paired status/evidence amendment has its own
full-byte/full-mode guards and source-owner receipt. It updates current notes,
command status and this ledger, preserving earlier receipts and configuration
examples. Its new bytes were not inputs to the 64.17-second rendered run, and
that run is not claimed as their rerender. Supported R6/A07/A15 is accepted
locally after these gates; R7/R8 and final A18 remain open. No duplicate corpus,
public release, consumer plan application/adoption or deployment is claimed.
R7 read-only Studio candidate evidence
R7 implements the embedded five-view browser and authenticated loopback API candidate described in the contract and guide. R1–R6 historical sections and their exact receipts remain unchanged. Frozen core/browser and exact-binary four-consumer qualification and guarded canonical rendered gates passed within the declared scope. R7/A16 supported read-only scope is accepted locally; R1–R7 are accepted. R8 editing and final A18 remain open.
Focused native and browser evidence
| Owning boundary | Evidence status |
|---|---|
| Native/public parity | Actual shared check reports preserve diagnostic/coverage/exit identity for 0/1/2; explicit selected workspace startup, cleanup/signal and no-source-write proofs are recorded separately by the owning test receipts |
| HTTP management/source/preview | Literal-loopback selection; exact Host/origin/Bearer checks; no arbitrary request paths/writes; captured source/diff bounds and source-mode/output inventory guards; focused core/new browser and current corpus receipts below bind this supported scope |
| Initial held browser | 14 axe checks with zero violations and 14 screenshots; five desktop light views, captured BOM/CRLF source/diff, desktop dark, mobile dark and all five 320-pixel light views plus capture changes. Synthetic actual-Hugo fixture retains 228 native diagnostics and coverage parity; copied suggestions use a private test clipboard, leaving the host clipboard unchanged |
| Browser preview attack | Actual attack script executes in the isolated preview, but parent access, management fetch and popup are blocked; token query refused. Actual draft-only page remains production 404. This proves the tested browser/CSP scope, not an OS network sandbox |
| Snapshot preservation | Captured source instructions/HTML stay literal data; the initial capture retains its old bytes before refresh after an explicit task-fixture external edit. Source full modes/Git/directories preserved except that declared fixture edit; changes show the actual modified captured input |
| Preceding held browser | Passed refreshed held UI/backend receipt: all 14 axe checks zero violations and 14 screenshots, including declared/captured theme rows. This predates the partial-preview runtime correction and does not qualify that new runtime |
| New partial-preview browser | Passed new frozen partial-preview runtime: 14 axe checks with zero violations and 14 screenshots; actual Hugo normal HTML 200 and 67,108,865-byte output 413; native 1/228 diagnostics and coverage retained, required partial coverage visible and Studio/refresh 2 |
Initial browser receipt:
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-studio-browser-AfwaYi/summary.json,
SHA-256 930fbd1ab86806069b963bff2e3e95aaa07e3634400cec65e2b8c7922e2a1707.
Its exact binary binds
92e5b962e40fbe828a0b006f3ae76a2bddf4ad7e8b1c5b6967e365b8f1827879;
the subsequent declared/captured theme metadata row is not claimed tested by
that preceding binary. The qualified local versions are Node 26.9.0,
Playwright 1.62.1, @axe-core/playwright 4.13.0 and Chromium 151.0.7922.34.
These are explicitly prepared contributor dependencies, not consumer runtime
requirements or automatic installations. Clipboard evidence covers the actual
UI click with a private clipboard implementation, not the whole host clipboard.
The refreshed held UI/backend browser receipt is
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-studio-browser-vn0ofb/summary.json,
SHA-256 520603779f712539865c6e9ef7a9ad3ad21ec1906adfb067ec607cc69d071b7e,
with exact binary 73bf90c69dce84849ee20ddfbfe825b9f2dd46f0cd37a228ce1b041a83afa33f.
All 14 axe runs and 14 screenshots passed, including declared/captured
theme metadata and all five views at 320 pixels. It retains the same bounded
synthetic-fixture/source/preview/clipboard claims above for that preceding
runtime. It does not qualify the later partial-preview correction; new browser,
full-stage, consumer and rendered-documentation qualification remains separate.
The initial parallel whole-suite trials in
/tmp/oink-r7-frozen-go-gate.log and
/tmp/oink-r7-frozen-hugo-gate.log failed and are not qualification receipts.
The failures were existing ten-second CI-test deadlines under parallel package
load and a graph test observer refreshing its own Git index. The isolated CI
target sets then passed in 12.149 and 2.291 seconds; the controlled Git-observer
graph run passed in 1.354 seconds. Only
internal/projectgraph/hugo_test.go changed: its read-only observer disables
Git optional locks, filesystem monitoring and the untracked cache. The ordinary
actual-Hugo graph run passed in 1.562 seconds after that test-only correction.
No runtime or embedded UI bytes changed.
The corrected freeze is recorded in
/tmp/oink-r7-corrected-runtime-freeze.json: the 113 runtime inputs retain
15a7de85a1ae9e6a73d8ea6570aa4f97bdd0ad5677ad7ca996fdd081ad43f7b5;
the 193 broader inputs now bind
67c6d36cf91d175f208f79cdd4d337aab6d2ef71e43453b20394b677678725e8,
with only the test-observer file changed from the preceding
85ad60d24c93e899020fbdcd34f8252c578253ce5afaf8652e561a432ecc8067
freeze. Corrected serial Go tests and vet passed in
/tmp/oink-r7-corrected-go-gate.log. The corrected serial actual-Hugo/pinned-tool
suite also passed in /tmp/oink-r7-corrected-hugo-gate.log, SHA-256
2aed822ff6fc8be04919aa74ca6ada721789232c14c1d77f1d44113bc0d235a7;
the application package took 220.782 seconds. The independent post-Go
source-preservation audit is
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r7-postgo-audit-qygh7bcc/receipt.json,
SHA-256 5ee45fe041536243bc1229054516835c61b27909a4f296ac226b1a138e4bc8dc.
It verifies the full physical/logical input guards, not Hugo or consumer results.
The durable corrected owning-gate receipt is
/tmp/oink-r7-corrected-owning-gates.json, SHA-256
c7f94a740e33a7349886b3f3689419719f857f39031375e80ca384a3dac36e67.
It binds both successful serial runs to the corrected freeze and preserves the
failed trials as unqualified. The prepared documentation renderer now requires
the completed consumer receipt to prove a private captured-source rebuild
byte-identical to the final browser binary. Its source-only independent audit,
oink-r7-docdriver-audit-ig_r8ud1/receipt.json, binds SHA-256
858cc48bf602fbdb26fcbda03c78ca485338b1295d64257d32cfb14b24f1ade3
and prepared driver
f25d9ac4bf1a7ef43d5526b7b3cbadf84dd64ad8a57fd82d1c82e76fdb2b3435.
That audit did not execute or qualify canonical rendering.
The first consumer driver trial, oink-r7-corpus-h1lOFl, stopped with
KeyError('preview_base_path'): it indexed a field legitimately omitted when
the actual preview base path is empty. Its private rebuild was byte-identical
to the final browser binary
73bf90c69dce84849ee20ddfbfe825b9f2dd46f0cd37a228ce1b041a83afa33f,
and all four consumer source inventories and the root inventory were preserved.
That failed driver run does not qualify the four-consumer gate. The fresh
oink-r7-corpus-corrected-cByXTa driver changes only those two accesses to
get(..., ''), with SHA-256
4c409acacbb9b82e658e6705eddefd9a3541def5c63c340b65678a6c9a8354e4.
That fresh run subsequently failed when the repository produced an inventoried
file larger than 64 MiB: the preceding runtime refused all production preview.
Its native check retained outcome 1, while required unavailable preview made
Studio outcome 2. Starter, docs and PIG completed that run with outcome 0;
all four source inventories and the root inventory stayed preserved. The failed
cByXTa trial is retained and does not qualify the four-consumer gate. Neither
empty-base-path driver correction changed runtime or consumer sources.
The parent then authorized a narrow runtime/test correction for partial
preview. It keeps the 64 MiB limit, exposes guarded production files within the
limit, returns 413 for the exact skipped oversized paths and keeps required
studio.preview coverage incomplete. Native check outcome remains unchanged;
Studio still returns 2 for required incomplete preview. The embedded UI is
held unchanged. All preceding browser/owning/binary/corpus receipts describe
their earlier runtime boundaries, not this new runtime. The new owning/browser
gates are recorded separately below rather than inferred from those earlier
receipts; exact-binary four-consumer qualification remains separate.
The old failed capture proved that an output exceeded 64 MiB but did not expose
its captured path/size; ignored repository output is not evidence for that
capture’s identity. The new bounded coverage detail will record actual omitted
relative paths, sizes and count. A prepared real-Hugo browser fixture adds
static/oversized.bin at 64 MiB plus one byte to exercise an available guarded
HTML preview, an exact skipped-file 413, native outcome 1 and required
partial-view outcome 2. That fixture preparation alone was not browser
qualification; the subsequent completed browser proof is recorded below.
The new partial-preview freeze is
/tmp/oink-r7-partial-preview-runtime-freeze.json, SHA-256
c426ce3e641ed7b39bb711a26006306cab22e761c5062f2164f10deb4bea8765.
Its 113 runtime inputs bind
4900ae05abbdf4409b0be54f276fb4135269cf0a49e9071013ccf42544d35c84;
193 broader inputs bind
8b172cef2b228e2642f0139d6cc569136e86843f818e52e412fa4a2d56add25d.
Only internal/studio/preview.go changed among runtime inputs; the broader
changes also include its test and scripts/test-studio.mjs. All three UI files
retain their exact bytes and modes. Focused core final race passed in 1.748
seconds, with vet and scoped whitespace checks also passing. Its receipt,
oink-r7-partial-preview-owning-a56dunn4/receipt.json, binds SHA-256
7b6ecb491f283d04fe54347e564dba426b1a84d152040a1d945af54bc67756ac.
The initial sparse-fixture mode trial is excluded: host umask 0077 made a
requested 0640 file actually 0600; explicit fixture chmod to 0640 corrected
that setup without changing production behavior. Focused proof covers normal
200, oversized GET/HEAD 413, changed identity 409, private path 404
and refusal for other unknown output errors. It does not substitute for the
subsequent independent broader browser/owning/corpus/render gates.
Whole serial Go tests for the new partial-preview freeze then passed in 61.481
seconds, and vet passed in 0.571 seconds. Completed logs are
/tmp/oink-r7-partial-preview-go-gate.log, SHA-256
be7d6eccf99a6f4c1b8f09d1fb782455c7cbd3bad4a2f37e2f0e9da916bcb313,
and /tmp/oink-r7-partial-preview-vet-gate.log, the empty SHA-256
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855.
The independent held-input audit
oink-r7-partial-held-audit-o6p98i1l/receipt.json, SHA-256
e567efc5f580db9395afab8ad36c4db842c3db95db442eb1cb1c740dbd43ec31,
verified all 113/193 inputs and physical/logical identities during that parent
Go/vet run. It is not a post-suite or browser/corpus/render completion claim.
The new whole actual-Hugo/pinned-tool invocation subsequently completed with
exit 1 after 285.649 seconds. Its sole failure was the parent’s unavailable
Markdownlint preparation path /md/node_modules; all other actual cases passed.
The log remains a failed invocation:
/tmp/oink-r7-partial-preview-hugo-gate.log, SHA-256
1ab6b8cfd399d484e08a1d1f05d25475754caa731991dd1eec1cca03cf6ce970.
The sole owning case was rerun with the exact provisioned
/markdownlint/node_modules executable, with no source/runtime change, and
passed: application package 2.317 seconds, wall 3.265 seconds. Its receipt is
/tmp/oink-r7-partial-preview-corrected-tools-gate.json, SHA-256
62b75e563e8074995ed9dd354434e653b2f5f2c6d20767226286d0c08d4c667c;
log SHA-256 is
e9bddac210654d219d9c5d6ebabaa3b91a0f5f4de4daf228b3ae21aeaac7673a.
The executable comes from provision receipt
268e601e81bc03a263296d57257b85635371bda642d0632532a7d9318c981461.
The independent case-matrix/held-source audit verifies cumulative executed
actual-owning-case coverage 0 from the failed whole invocation plus that
corrected case. Its receipt,
oink-r7-partial-case-matrix-audit-16_bl9hr/receipt.json, binds SHA-256
0a9e4a1a1e1a08f597becb2f27e743c9f23df672c713c2757241704edb16b51e.
All 113/193 physical/logical inputs remain frozen. Optional
TestArtifactCorpus and TestPublishedRuleSourceProvenance cases were explicitly
skipped. This never relabels the whole invocation as exit 0, nor claims those
skipped cases executed.
The new post-Go input audit,
oink-r7-partial-postgo-audit-g1hcqdtl/receipt.json, SHA-256
b369737ec48456f673c850ea702cb3cb7efffb8ecc129d87e00dc03af82b2e3b,
then confirmed the complete held 113/193 physical/logical inputs after Go/vet.
That scope does not claim whole Hugo, browser or consumer completion.
The new partial-preview browser passed against exact binary
f39d6754f7ad13599e4e849394e0f470b2c6f26edf96ce40f199d27b65a8030e,
version 0.4.0-r7-local, 16,000,578 bytes and mode 0700. Its summary is
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-studio-browser-cE9be3/summary.json,
SHA-256 9099e6c407fd0f9de3c29ce80e03f034a4223d7d7a7c1f1378052e8b9084e0ae;
provenance SHA-256 is
85b9f537fb09eecbb09d133b53a297c78184c11200ab0938734c0d10f3449095.
The private oink-r7-browser-partial-ZZIqzZ/source-binding.build.json, SHA-256
7a89ab8318c3a38455ab6ce12bcdbc53ae5ce0674fb5aaaa1df0fcf68a093399,
binds all 113 runtime and 193 broader source inputs plus physical identities
before capture/build/after to the new freeze; root inputs stayed unchanged.
All 14 axe checks had zero violations and all 14 screenshots passed, retaining
the keyboard/mobile/light-dark/source/clipboard/security checks described above.
Actual Hugo emitted oversized.bin at 67,108,865 bytes, reached through its
rendered /sub/oversized.bin link and returning 413; ordinary actual HTML
returned 200. Required partial preview coverage stayed visible; 228 typed
native diagnostics and native coverage/outcome 1 matched the CLI/API/UI,
while Studio and the subsequent refresh returned 2. Source preservation still
excludes only the declared task-fixture external edit. This is the bounded
synthetic browser proof, not a completed four-consumer or canonical render gate.
Another prepared, unexecuted corpus driver had assumed that an available normal
preview always appends a studio.preview coverage row. Actual normal
Starter/docs/PIG Overviews do not emit that row; the preparation assumption
was corrected without changing native coverage. The repaired fresh
oink-r7-corpus-partial-pZLwY0 driver, SHA-256
47778df62505beeb7432985be927f1b001e03824e9dee3a6dbed9d9b2dbe049c,
was reviewed against those three retained actual Overviews and the current
partial browser capture. Normal availability still requires its actual preview
URL and independent HTML 200; a partial capture retains its actual required
row, omitted count/identities and 413. The preparation audit is
oink-r7-partial-driver-correction-audit-sa98cm6k/receipt.json, SHA-256
a519a5bc6ae83438146ff4710d53f5edb0e656a05d0532c02123e5771416f07e.
Its earlier f762 preparation was not executed or qualified. The parent has
released the corrected driver for a fresh all-four run; its completed
qualification is recorded next.
The fresh four-consumer qualification completed with driver outcome 0 in
234.6425 seconds. Its current summary is
/private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r7-corpus-partial-pZLwY0/summary.json,
SHA-256 d7b5a4f1607b6f75ae6a596c19cbab28685fb67dac750096173060ed097c8bf5;
log /tmp/oink-r7-partial-corpus-gate.log binds SHA-256
a7b724500569bd594d8e01502ec1956eb089cc9153b04b693992a9322013c811.
The durable current corpus qualification.receipt.json binds SHA-256
4e5df7c3fda9f0b763091af3e6cb85c68c736c319a1de68030b81d5cd5b384bc;
primary source inventories contain 97/421/858/2,294 files respectively.
The private captured-source rebuild is byte-identical to the new browser binary
f39d6754f7ad13599e4e849394e0f470b2c6f26edf96ce40f199d27b65a8030e.
Runtime 113/broader 193 inputs and root physical identities stayed frozen;
every operation and the overall boundary preserve all four consumer bytes,
full modes/types, logical/mutable Git, ignored copied inputs and directories.
| Consumer | Native outcome | Typed diagnostics | Studio outcome | Actual captured pages |
|---|---|---|---|---|
| Starter | 0 |
28 review-info records | 0 |
66 |
| docs | 0 |
144 review-info records | 0 |
343 |
| PIG | 0 |
120 review-info records | 0 |
248 |
| repo | 1 |
10,462 existing duplicate-ID findings plus 788 review-info records | 2 |
1,576 |
Nested native headers, typed diagnostics, coverage and exit match direct CLI
checks exactly for all four sites. Issues were fully paginated; other views
were bounded samples, with captured physical source and translation diff
available on all four. The first three actual production previews returned
HTML 200; they emit no studio.preview omission row, and the driver invents
none. The repository normal HTML returned 200 with 60,100 bytes. Its current
capture exposes exactly four oversized print paths; each actual HEAD returned
413 with zero response-body bytes:
| Captured omitted relative path | Captured byte size |
|---|---|
_print/pkg/index.html |
73,976,221 |
_print/pkg/pgsql/index.html |
69,903,999 |
zh/_print/pkg/index.html |
73,086,240 |
zh/_print/pkg/pgsql/index.html |
69,052,754 |
These identities come from current bounded capture detail and live requests,
not the earlier ignored-output clues. Required studio.preview remains
incomplete, so repository Studio 2 retains native 1. Actual analysis-only
draft routes returned production 404 in docs and repo; that test was explicitly
not applicable in Starter/PIG without a unique captured draft route. Workspace
subset/full/healthy-subset sessions selected only registered sites and closed
listeners without captures; unknown or selected missing sites returned 2
before startup. This is local Darwin/arm64 CLI/API evidence with Hugo 0.166.0
Extended, Go 1.27.1 and Git 2.54.0; browser scope remains the separate synthetic
fixture. No source writes, install, publication, adoption or deployment occurred.
Independent final corpus audit
oink-r7-final-corpus-audit-xr3_u5dt/receipt.json, SHA-256
b8a8eedf5c899fe5830bdde959783c46b3f191ab144c0d3798077555d55238fc,
verifies raw typed native/API/shutdown parity, all 132 operation preservation
comparisons and four overall guards without rerendering or new HTTP requests.
Only guarded canonical promotion/render and the explicit R7/A16 stage decision
remain pending; R8 and final A18 remain open.
For temporary disk capacity, the parent retired only three explicitly created
private Go build caches, totaling 366,184,826 bytes, as recorded in
/tmp/oink-r7-private-cache-retirement.json. Sources, binaries and qualification
evidence were retained; no global, user or system cache was removed. This
preparation action is not a runtime correction or a qualification gate.
Remaining stage gates and promotion boundary
| Required gate | Current status |
|---|---|
| Frozen runtime input/binary identity | New partial-preview freeze binds 113 runtime inputs 4900ae05abbdf4409b0be54f276fb4135269cf0a49e9071013ccf42544d35c84 and 193 broader inputs 8b172cef2b228e2642f0139d6cc569136e86843f818e52e412fa4a2d56add25d; all UI bytes/modes unchanged. Source-bound browser binary f39d6754f7ad13599e4e849394e0f470b2c6f26edf96ce40f199d27b65a8030e passed; fresh private consumer rebuild is byte-identical |
| Full Go/vet and actual Hugo | New whole serial Go/vet and browser passed. New actual-Hugo/pinned-tool whole invocation remains exit 1 for a preparation path; sole corrected owning case passed 0, yielding independently verified cumulative executed actual-case coverage 0; two optional cases explicitly skipped |
| Four consumers | Completed exact-binary CLI/API qualification; native 0/0/0/1, Studio 0/0/0/2, exact nested native parity and source byte/full-mode/type/Git/ignored-input/directory guards; repository partial preview remains required incomplete |
| Canonical paired sources/render | First guarded TEN promotion and scoped actual render passed; the post-render status amendment has separate fresh source checks and is not claimed rerendered |
| Stage decision | R7/A16 supported local scope accepted; R1–R7 accepted locally, R8 and final A18 remain open |
The next prepared documentation installer retains the actual captured old inode outside canonical source storage on both success and recovery, without unlinking its last name after an earlier target identity check. This private helper hardening and its new recovery fixture are a new preparation boundary; executed R6 installers/hashes/receipts remain immutable and are not retroactively claimed to contain it. R6’s successful promotions already retained originals. No consumer plan writes, release, adoption or deployment are implied by this candidate documentation or the local browser fixtures.
The completed first-promotion rendered gate is /private/var/folders/df/bfm8q07d7bv3kpjf1fjchq4m0000gn/T/oink-r7-docs-render-n8tw2tbw/summary.json, SHA-256 35e79f51d39803b3e4cdf134ed277957dd627acba42e0e0dc785e4745ec3c481, with log SHA-256 de3a07eac661c15805070e0ed2e364a71ebbd38e15d8907aab3bdf716e95131d and elapsed 63.33 seconds. Exact qualified binary f39d6754f7ad13599e4e849394e0f470b2c6f26edf96ce40f199d27b65a8030e passed production CLI links with one strict Hugo build. Ordinary production Hugo without a probe passed rendered Markdown (214 pages/44,075 text nodes) and links (345 pages/48,482 internal links/4,303 fragments). Its translation owner retained exit 1 only for the existing nonpublished release 1.2.0 draft. Independent draft/future/expired analysis passed Markdown (216 pages/44,381 nodes), links (347 pages/48,858 internal links/4,331 fragments) and translations (137 pairs/1,129 headings); it did not replace production output. Source translation/style/whitespace checks passed and CLI/docs schema 7468c2d04cde8a368ce0ba44a1f27125b5fca364b6d4672353519b9545b3bdda remained identical. All twelve operations, schema and overall guards preserved 421 primary files, 427 copied inputs, 109 directories, 36 mutable Git files and 113 runtime inputs.
The first guarded promotion receipt oink-r7-root-promotion-p9g1u7pz/summary.json, SHA-256 323a5ce267e39aaf8f97dc4a12cccbdde83730155a199efb5f3815e29b334e4a, verifies actual original inodes retained outside canonical source. Its post-apply receipt lookup initially used 0 instead of 00; that metadata-only driver failure is preserved, followed by receipt finalization with unchanged raw guards. The successful source installation was not reapplied. Executed R6/R7 helpers and first-promotion receipts remain immutable.
R7/A16 supported read-only local scope is accepted after the frozen cumulative owning-case/browser/corpus and canonical gates above. The original whole-Hugo invocation still has exit 1; the corrected sole tool case plus independent matrix establishes cumulative executed-case coverage. Repository native 1 and required partial preview/Studio 2 remain visible. R1–R7 are accepted locally; R8 editing and final A18 remain open. This post-render status/evidence amendment has its own byte/full-mode guards, unchanged headings/command fences, paired source checks and retained-inode installer fixtures. Its new bytes are not claimed tested by the preceding 63.33-second render; no additional rendering, consumer write, public release, adoption or deployment is implied.
R8 accepted reviewed editing evidence
R8/A17 supported editing scope is accepted locally after the corrected frozen
owning/browser/corpus and guarded canonical rendered gates recorded below. CLI edit text, field, snippet and attachment preview the same
bound oink.edit/v1 intent used by explicit studio --edit. Saved-plan apply or
explicit acknowledged Editor Apply owns selected source writes. The default
Studio session remains read-only. This section retains capture-time candidate
facts and trials, followed by the completed current qualification; it does not
extend earlier R1–R7 evidence to changed code.
Candidate scope and preservation
Known site-owned UTF-8 Markdown is bounded to 1 MiB. Full text and supported
ordinary top-level YAML scalar forms retain the declared BOM/line-ending and
source-span preservation boundaries; unsupported form shapes remain text.
Exact value_json numeric tokens avoid browser Number rounding. Scalar forms
bound numeric literals to 4,096 bytes and absolute decimal exponent 10,000;
larger/nonfinite constructs remain manual text. Field JSON is at most 1 MiB;
escaped lone surrogates refuse, valid Unicode pairs are supported. Catalog
components use original UTF-8 body byte offsets; attachments require actual
leaf-bundle identity, at most 4 MiB and an exclusive new clean basename.
Source hashes, full modes, all site/external inputs, regenerated intent and
fresh actual Hugo validation bind the same shared guarded application path.
The Editor displays the complete UTF-8 review, selected-file base/after
identity and native candidate result; the review is capped at 2 MiB and its
literal bytes are hash-checked before acknowledgement. The actual selected
candidate HTML is draft/future/expired analysis, visibly nonpublishable and
separate from the original production preview. Required candidate-view
incompletion may raise the proposal/session to 2 without changing native
findings. For page-file edits, the selected candidate source hash/full mode
matches its reviewed After state; attachment/no-op proposals retain the
selected page’s reviewed Base state.
Stale/replayed plans, attachment collisions and untrusted preview requests are
refused; applied-with-refresh-error remains explicitly applied.
Focused preparation receipts
| Candidate evidence | Current observation and boundary |
|---|---|
| Pure editing core | Owner’s focused exact-numeric tests passed for 18446744073709551615 and 7.12345678901234567890123456789, exact no-op raw bytes and changed final decimal digit; broader frozen receipt pending |
| Actual DFE output ownership | Live ordinary output is copied through a confined os.Root, exclusive target files and guarded streaming reads; files over 64 MiB can be captured while serving limits remain unchanged |
| Copy cancellation/race | Context-aware helper focused 0 in 0.703 s, race 0 in 1.856 s, vet/whitespace 0; actual first-chunk cancellation retains partial output, source bytes/modes/identity unchanged; source FIFO replacement cannot block before descriptor proof |
| Helper log identities | Focused c227a88210ab0dc46b24eaff50a347d5c494e9ce23f5bdef5d5b822efab4976f; race 13f0616d55fd4df791ecded0712a18096392c88cb9b849383414c305e50b6779; vet is empty SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 |
| Read-only candidate integration review | Selected actual HTML URI/base prefix and inventory, retained private DFE lifetime, source SHA/full-mode equality, native versus view coverage and cancellation reviewed; no new material defect found within this code review scope |
| First Editor browser trial | Harness stopped on ambiguous global Open editor selector; retained as failed trial, no UI qualification claim |
| Corrected-selector Editor trial | Desktop field/component/binary apply checks and axe checks passed before 320 px draft-review horizontal overflow failed; retained original trial, not a final browser pass |
| Narrow layout correction | Editor review hashes/receipt text wrap and intrinsic widths are bounded; prior CSS and failure evidence retained separately. Development rerun passed 12 axe checks/screenshots, including real 320 px dark review and light receipts/refusals; final frozen-source/binary rerun pending |
The helper evidence is focused file-copy/cancellation qualification, not the whole editing application or all platform support. Browser trials describe their actual stopped scope. They do not establish final A17, consumer adoption, deployment or a successful current frozen browser binary.
The preceding preparation rows were captured before the first complete R8
freeze. They remain development history. The first whole frozen gates later
passed for binary 84b804d3246a5be581e44884ed910fa3f45d8be29734b8babdeeb763a11fa882
(0.5.0-r8-local), runtime 123/58517b8e98b80df6642be4ee6275a0074ec187768b20e009f41da2607b635d46
and broader 212/d81335c78413acc60e27adee0ac794862285e41cb2a3a7687ec820c1065ba003.
The whole-gate summary is b49f4a3272af3e3dcc92e7e9b38d4289bb49cb19aa3e9354ea148d2d8cb2cea8:
Go tests 0/56.523 s, vet 0/0.904 s, whole actual Hugo plus all three pinned
tools 0/320.044 s, core race 0/16.610 s and public R8/helper race 0/48.319 s.
Its source guards passed. These receipts qualify those earlier bytes only.
The first frozen browser receipt
eb6977235ef9ae6cec28651b5654eb101685af67abe0cbed0acb0f8375458d9c
binds that same binary and source freeze. Editor had 12 axe runs with zero
violations and 12 screenshots; retained read-only Studio had 14/zero/14.
The actual form preserved the literal 1e400, its planned after hash and diff,
then discarded it; exponent ±10,001 and a 4,097-byte numeric literal refused
locally without an API request. Four acknowledged field/component/binary/draft
applications occurred only in disposable fixtures. Default read-only refusal,
stale preservation, no-op source bytes, preview isolation and native-result
independence passed. This is development browser evidence for the first
freeze, not a four-consumer or current corrected-runtime acceptance.
The first exact-binary consumer trial then stopped at Starter after 37.533 s.
Its immutable failed-trial receipt is
853a8397ba4c527c03aa3cc9ac7cacc41c0ab0379549d145b874f1d1ecc3901c.
Two failures are recorded separately. A driver event hash depended on JSON
object-key order even though recursive comparison proved API/CLI arrays equal:
28 diagnostics, 29 coverage rows and native exits 0/0. Separately, repeated
resolved cache capture produced a genuine duplicate module input
.gitattributes; required candidate graph capture became incomplete, mutation
outcome 2, with native check still 0, no actual selected DFE HTML and no
applicable lease. The public published-cache fixture reproduced that defect;
its retained failing log is
50ab704e715665096e0f36391bb1364841c3a2b2ac88dd262915ce53fb66afa6.
All 48 recorded per-operation source proofs and four overall consumer guards
preserved bytes, full modes, types, Git, ignored copied inputs and directories;
root inputs stayed exact. No Apply or saved plan was performed. This stopped
trial has no completed four-consumer qualification claim.
The narrow runtime correction gathers complete resolved-module rows before
committing additions. Identical repeated or reordered captures retain the
original inventory. Changed hashes/full modes, added or removed paths within
an existing scope, missing scopes, conflicting identities or capture errors
refuse without refreshing prior evidence or appending partial additions;
non-module rows remain exact. Site owning receipt
e7b284b9dece1c5f2b696cd76166d2286fcbec69e6c48912ab9a78204bdb980b
records focused 0/0.746 s, site 0/2.123 s, focused race 0/1.958 s and vet
0/0.167 s. This compares reobserved complete rows; it does not lock module
files against concurrent writers.
The corrected published-cache receipt
6358dc81f06e34b789cb47a0f4442d6d036d2e33423a06f5dbe85b3064766da6
records actual github.com/pgsty/[email protected] from a task-local copied checksummed
archive, with no downloads or replacement. Original and candidate graphs each
have 1,256 unique inputs, including 1,198 module inputs. Full API/CLI typed
diagnostics, coverage, exits and plan identity match; actual selected DFE HTML
returns 200, with source bytes/full modes/Git unchanged and no Apply or saved
plan. Owning race passed in 30.255 s; vet passed. Its corrected race log is
c7d21a30b8af141d9d9604a80ddf9cf3f608320b97a441a06a742376e2119551.
The current complete corrected freeze is
fb276500a3d2643bd0aa220f8bebb380fce2c98493d62b0502b6497b2f02949f,
runtime 123/cdf629eeb4bbef6d4d88ee27fe3fb0a73b07b6bf6438336e033a18fb7feb1c17
and broader 212/f6e305e792733a550814eb841615d12fa14a9a6bb2a97c4ada85f7275183e579.
Only source_inputs.go, its owning test and the public published-cache test
differ from the first freeze; held UI/helper bytes and all full modes remain
unchanged. The rebuilt candidate is
bd25f9e0b35ec10e227aabf9582ae40b0b367390f64b93668de6ae85222c3d71
(0.5.0-r8-local). Its observed corrected source-bound browser receipt
33a698985a55c14c3e64e981da1f8e74c686497083dc0edb241406f185e3eeb8
again reports Editor 12/zero/12 and read-only 14/zero/14 with complete 123/212
pre/post source preservation. Corrected whole owning gates, the fresh
four-consumer corpus and protected canonical rendering are still pending at
this evidence amendment. R8/A17 is not stage accepted; final A18 stays open.
At the next evidence observation, the corrected whole gates completed for
that held bd25f9e0…22c3d71 binary and fb276500…02949f freeze. Summary
208f156c0954e803eccbada678a4689683dc1576c543c379e5cc04b3497ef772
records Go tests 0/57.826 s, vet 0/0.521 s, whole actual Hugo plus all three
pinned tools 0/378.847 s, core/site/Studio race 0/17.937 s and public
R8/attachment/output-helper race 0/85.159 s. Every gate’s source pre/post guard
passed. The actual-Hugo log has 434 top-level passes and zero failures; the two
optional external fixtures TestArtifactCorpus and
TestPublishedRuleSourceProvenance remained explicitly skipped. Those skips
are not claimed as executed corpus or provenance qualification.
The corrected whole actual-Hugo log is
4eb1a2afdce2adbe570b10922fd53b6d8954f7c95747370c3c661e94d2f71a05;
Go log ea59463e9649ffe2f8aff9da66c91cf6895c86fde96a524db23c89cd4eb35925,
core race cdd3d761b5ca7b5e986b25aee3129d65663e3e5ebb83eecb6fbb080387298a58
and public race bb610bdcd7a299cb9b66f4c69e30e246c20546efae47653c01d350b1026ea2de.
The corrected browser-only evidence above remains bound to the same current
source and binary. The separately authorized fresh four-consumer trial is in
progress; no completed corpus, canonical render, R8/A17 acceptance or final
A18 qualification is inferred from these owning gates.
The 434 passes and two optional skips above are top-level counts. The same
whole invocation also skipped the nested Unix-socket refusal fixture because
the Darwin temporary pathname exceeded the socket limit. A first shorter
private-path trial still skipped: receipt
93106854ca890b497d3c74522b895f597ac60cec55ced42cad7b187d334da200
retains process exit 0 but explicitly records no actual socket execution and
failed qualification. It is not relabeled as a passing fixture.
A subsequent nonresolved short private TMPDIR executed the same frozen
socket fixture under race detection without a skip: 0/2.954 s. Receipt
531a503b3b91e1b423c2be61b92ed806d3a813738c38d57e5ec122577b4337f9
and log 236c84f1842ffce76174c834f3888718a109cec6377ada6f3242b02f551f00b3
bind fb276500…02949f and all 123/212 logical/physical/Git inputs unchanged
before/after. This supplies the actual socket-refusal case without changing
source or the original whole invocation’s skip history. Corpus, canonical
render, R8/A17 stage acceptance and final A18 remain pending.
The preceding pending-corpus statements record their observation times. The
corrected four-consumer trial subsequently completed in 845.705 s. Summary
af4fc53326163c4a03aa2982c1f01363fbbdd5a447c9baed3639bd8599d46370
and qualification receipt
4d6fd02543c1920497e1a1bb0a68fcf89b0546130fd9cc12c1df391b7e673e75
bind a byte-identical private rebuild of bd25f9e0…22c3d71, the complete held
123/cdf629ee…feb1c17 runtime and 212/f6e305e7…5183e579 inputs. Original
failed corpus, published-cache regression and first frozen browser/gate bytes
remain separate historical evidence; all 2,383 entries of the first failed
trial retained their exact bytes/full modes/types.
| Corrected consumer | Native/current and native candidate exit | API candidate outcome | Full diagnostics/coverage | Actual selected analysis HTML |
|---|---|---|---|---|
| Starter | 0 / 0 |
0 |
28 / 29 |
200, 48,149 bytes, /blog/design/content-model/ |
| Documentation | 0 / 0 |
0 |
144 / 34 |
200, 61,738 bytes, /blog/oink/immersive-reading/ |
| PIG | 0 / 0 |
0 |
120 / 41 |
200, 55,641 bytes, /404/ |
| Repository | 1 / 1 |
2 |
11,250 / 29 |
200, 92,352 bytes, /blog/infra/2020-12/ |
These are actual selected Hugo HTML routes in the separate, visibly
nonpublishable draft/future/expired candidate view; each expected candidate
marker was present. API and CLI matched full typed diagnostics/coverage, native exits, plan ID,
Base/After hashes and full modes, unified diff and the selected page’s proposed
source. The complete literal API review and its hash were independently
validated. No consumer Apply or
saved plan occurred, and no listeners remained. The repository retained
10,462 existing duplicate-ID findings and 788 information records. Its four
actual PRINT outputs remained required partial-preview incompletion:
_print/pkg/index.html 73,976,221 bytes,
_print/pkg/pgsql/index.html 69,903,999 bytes,
zh/_print/pkg/index.html 73,086,240 bytes and
zh/_print/pkg/pgsql/index.html 69,052,754 bytes. Each bounded HEAD request
returned 413 with zero body; selected in-limit HTML remained 200. Native
1 remained unchanged, proposal/session 2 and Apply refusal stayed visible.
The other three complete previews had no invented explicit complete-coverage
row: actual guarded HTML 200 supplied that evidence.
Exactly 53 protected operations each checked all four sources: 212 per-operation source proofs plus four overall proofs, with source bytes/full modes/types, copied ignored inputs, directories and logical/mutable Git unchanged. Each source proof compared four inventory categories, yielding 864 raw inventory pairs including the overall comparisons. All 53 root guards and the final complete 123/212 logical/physical inputs also matched. All issues and pages were paginated; the other five view endpoints were sampled to their first 50 records, with one known source and one bounded diff per site. Full native/CLI record parity used the declared bounded complete-record codec; object order was canonicalized while array order, types, null and field presence remained significant. This does not claim every relationship was visually reviewed or every source was edited.
Independent audit receipt
6b72ca06d8392a5271fc40757f176f26e1144c21eec93dbd035e0a1bd645657b
verified 69 artifact hashes, complete bounded API/spool/shutdown typed records
and the large native/CLI raw-file digest bindings. It did not separately
repeat multi-gigabyte native semantic scans. Its additive receipt
335f137663d4ec0b2a0d3e49c8d70b9918f86078ab6264855171a2644d8aa6c6
also verified the fresh current root’s complete logical Git inventory against
the freeze; the original audit stayed immutable. Corrected owning, socket,
browser and four-consumer supported scopes are qualified. Canonical TEN
promotion/rendering, the R8/A17 stage decision and final A18 remain pending.
The preceding R8 candidate/trial statements retain their capture-time scope.
The reviewed first TEN promotion subsequently passed through the guarded
retained-inode installer, root receipt
7cd9b4604d2340b9e46965a26281c921b967060909d518b8b4b31e5f42d0120c.
Its actual original source inodes remained retained outside the documentation
site; unselected source/copied inputs, directories and Git, and complete CLI
123/212 logical/physical inputs stayed unchanged.
The separately authorized canonical render then completed exactly once in
67.21 s, summary
bb0d0710294f810fb14284f7b5b0329befbd290b66c21397b9a45e8382287fb6,
qualification receipt
32d3ffeca43bc9ad4615edcca0d3cc47cc932bbc93c6576724c800e0a62405b1.
It used the exact qualified bd25f9e0…22c3d71 binary and corrected 123/212
freeze. Actual CLI production links passed 0 with one strict Hugo build.
Independent ordinary probe-free production Hugo/Markdown/links passed: 214
Markdown pages/44,691 nodes and 345 link pages/48,532 internal references/4,351
fragments. Its translation owner retained 1 solely for the existing
release/1.2.0 draft absent from production. Separate explicitly nonpublishable
draft/future/expired Hugo analysis passed Markdown (216 pages/44,997 nodes),
links (347 pages/48,908 references/4,379 fragments) and all translations 0.
Analysis did not replace production output.
Source translations passed 137/137 pairs and 1,143 headings; Chinese style
passed 137 files/181 strong spans/zero emphasis, whitespace passed and schema
SHA-256 7468c2d04cde8a368ce0ba44a1f27125b5fca364b6d4672353519b9545b3bdda
matched exactly. All 12 commands, schema and overall guards preserved 421
primary source files, 427 copied inputs, 109 directories and 36 mutable Git
files, plus all 123 runtime/212 broader CLI logical/physical inputs. The
qualification receipt binds 60 canonical inventory pairs, 15 CLI guard pairs
and six private-copy source pairs; it claims no consumer writes or deployment.
R8/A17 supported local editing scope is accepted after corrected owning,
socket, source-bound browser, exact-binary four-consumer preservation and
these guarded canonical gates. R1–R8 are accepted locally; native repository
findings and required partial-preview 2/Apply refusal remain visible. Final
A18 current Linux/runtime/archive qualification stays open. The separate
platform-authority audit
762571dab9a07651ac8e4c71764bfef292f8d5eba729a089e72d9d755b7e2d7c
confirms that the initial contract qualifies actually exercised architectures:
macOS arm64, native Linux arm64 and emulated Linux amd64. Darwin amd64 remains
an experimental archive with failed actual execution/unverified runtime; its
history is preserved, and no successful cross compilation becomes a runtime
pass. Both current Linux runtimes and final archives still require fresh proof.
This post-render status/evidence amendment has separate full-byte/full-mode and inode guards, unchanged stable IDs/command fences, paired source checks and retained-inode installer fixtures. Its new bytes were not rendered by the preceding 67.21-second run. No repeated rendering, consumer source write, public release, adoption or deployment is implied.
Required gate matrix
| Required gate | Current status |
|---|---|
| Final immutable runtime/source freeze and exact CLI binary | Corrected complete 123/212 freeze and bd25f9e0…22c3d71 bind completed owning/browser/corpus/canonical scope; first-freeze trials separate |
| Public CLI/JSON/exit, stale source/config/external-input and guarded writer tests | Corrected public R8/attachment/output-helper race, whole Go/vet/actual Hugo and canonical stage gates passed |
| Frozen whole Go/race/vet and actual Hugo/ordinary Hugo after selected application | Corrected whole Go/vet/actual Hugo and core/public race passed; 434 top-level passes, zero failures, two optional external fixture skips explicit; first trials remain separate |
| Editor browser five-view parity, text/forms/components/binary attachments, exact numeric/no-op, stale rejection and preview isolation | Corrected source-bound Editor 12 zero-violation axe runs/12 screenshots and read-only 14/zero/14 passed; bound completed corpus and canonical acceptance |
| Exact-binary four-consumer read-only qualification | Corrected all-four completed in 845.705 s; full typed native/API/CLI candidate parity, 212 per-operation source proofs plus four overall, no Apply/save/source writes; first failed trial preserved |
| Protected canonical TEN promotion, EN/ZH source/schema/style/whitespace and actual production/analysis render | Guarded first promotion and independent exact-binary 67.21 s render passed; only known draft translation omission in production; rendered and status bytes separately bound |
| R8/A17 stage decision | Supported local scope accepted after corrected whole owning/browser/corpus/canonical gates; R1–R8 accepted locally |
| Final A18/platform/archive delivery | Open; compile success alone is not runtime qualification |
Passed and pending entries are explicit; later gates are not inferred successes. Prior R1–R7 sections, whole-invocation failures and scoped acceptance receipts remain unchanged. Temporary qualification files stay outside canonical content and Git; first canonical promotion/rendering has exact receipts, while this status amendment remains a guarded proposal. No public release or deployment is claimed.
Current runtime completion supplement on 2026-10-04
This supplement records the current candidate on 2026-10-04 (Asia/Shanghai). The dated page URL and all initial 2026-10-03/R1–R7 records remain unchanged. The preceding R8 stage and browser/render receipts are historical input-bound proofs; they do not qualify subsequently changed backend bytes. The three UI files retain exactly the browser-qualified bytes and full modes. Current Go, Hugo, platform, archive and four-consumer checks refresh the changed backend.
The first current ARM offline unit run exposed a real output-copy integrity gap:
adding a directory entry on ext4 could retain the parent’s allocation size and
observed timestamp. That failed run stopped before later qualification steps. The
bounded correction captures and rechecks actual sorted directory membership and
entry identity, alongside regular-file byte/full-mode proofs. Only
internal/app/studio_output.go and its owning test changed. The failed receipt
and independent audit are retained; a failure never becomes a passed run.
The preceding integrity-correction qualification freeze is 683daca0e522193c7ff1b0de6ac2fee5d2fca080811bf184a8dfd5b90a33f224:
123 runtime inputs hash to d346ad15cd4239004e32e1b9f30d727eaf156be0187dc165ca874032a7cf962a,
and 212 complete CLI inputs hash to 2abd1a044d8192b07f9bbc06b55dc8b4544d66ca17b8867971cec702ba3af088.
The 0.5.0-r8-local Darwin arm64 candidate is
74ad94e73557f6538cd64edd1766d6df92c596d98411031159d94af072c186ec.
The observed integrity-correction receipts below bind that source scope; old R2 Linux and earlier R8
binary receipts retain their historical scope. The later one-test fixture amendment has its own complete source identity and
completed formal qualification boundary, recorded below.
The current complete source freeze is now
196245a3ba09305e34b86539c8eb79f1473e4373ee47aa1f56f8933b04a42d43.
The 123 runtime inputs remain exactly
d346ad15cd4239004e32e1b9f30d727eaf156be0187dc165ca874032a7cf962a;
the 212 complete CLI inputs are
2c487bfb4c65ed40ff78356b2860de627e6ac1afa0da2df433b09345dab7f5b0.
Only the owning published-cache test changed, to source
54c10ef89310256b5f4c165c7de5de9668e1d4d2991b71751076680141dbe779.
The fixture amendment is separately guarded; production bytes and all semantic
assertions remain unchanged. Formal qualification of this complete source, including current eight owning
gates, reproduced archives and full plain-Go AMD/ARM runs, passed. Root A18
proof 2c018cb2afa3f26699a9e6b5a0971096246b12405fde5a27e43a9e213e46da60 binds all three declared supported targets and five reproduced
archives. Earlier receipts retain their captured inputs; they are not relabeled
as runs of this amended test source.
| Current proof and preserved earlier input boundary | Observed result and bound receipt |
|---|---|
| New complete-source formal qualification | Freeze 196245a3ba09305e34b86539c8eb79f1473e4373ee47aa1f56f8933b04a42d43, owning test 54c10ef89310256b5f4c165c7de5de9668e1d4d2991b71751076680141dbe779, unchanged runtime123. Current eight gates, host/archive and both full plain-Go Linux flows passed, bound by root A18 proof 2c018cb2afa3f26699a9e6b5a0971096246b12405fde5a27e43a9e213e46da60; this does not claim final document bytes were already rendered |
| Narrow integrity correction | Owning receipt 6966d768025497b45958073d4c53a2a2981065c8a95857834dcf6a4faa4f0201; independent audit 6cb5d2eabf57b41079026a38a674f46def9f56a15df17ad27e671e4f765798df |
| Prior-source six frozen owning gates | Build, full offline Go unit/vet, whole actual Hugo/pinned tools, core race and public R8/output-helper race all 0; elapsed 3.501/68.257/3.909/333.801/37.070/79.670 seconds. Summary b40b7787b3da8dc1e0763812b6dde529b4b5b69fe479d79940f1161223124e1d; independent audit 20780662b7ff35019b2c8c84e6dc763f9351ae0816f6ef7a7789f7a15be99167 |
| Eight current frozen owning gates | Selected published-cache actual Hugo and race, build, full offline unit/vet, whole actual Hugo/pinned tools, core race and public R8/output-helper race all 0. Current summary d6272fcc4dfab114aecfcdf19a7e2b78f1e931817331b460f43ff2056bf754a4; raw whole Hugo has 435 top-level passes, no failures, two optional top-level skips and the explicit long-path socket child skip. Runtime/binary bytes remain identical |
| Prior-source Darwin arm64 and archives | Current extracted candidate runs outside the checkout with no consumer Node requirement. Seventeen commands and eight actual process tests, including child signals, passed without process-test skips. Two fresh release directories contain byte-identical five archives and checksums; source/license/provenance/canonical tar checks pass. Summary bcb4d7599e965c1b3cfe7fe698ca14061ad53d45e7a194337aeebb8d37aa77c1; independent audit 60a04771365d8be15ac91fbbd8d485b019aae081598e468018861ca5734e387c |
| Current Darwin arm64 and deterministic archives | Seventeen extracted-archive/ordinary-Hugo/process commands passed expected exits, with missing Hugo explicitly 2; eight actual signal/process cases ran without skips. Two independent fresh builds reproduced five byte-identical archives from current complete source. Summary 3890fd8468b6bce5271bb32ffa1a18bd5daf99c19c43becac0be8e3b908a5d57; source, tools, module-cache and smoke-source guards remained equal |
| Prior-source Linux arm64 | Actual nonroot Linux arm64 on ext4 with Go 1.27.1, Hugo Extended 0.166.0 and Git 2.47.3: full offline Go unit/vet, all 13 required pure top-level pass records and the membership case plus its four children without skips, 10 selected actual-Hugo cases without skips, native rebuilt archive identity, installed bilingual/offline/ordinary-Hugo/missing-Hugo 2 JSON and signal/source-mode checks passed. Guest summary 409990bc1425f4bf219f8911a71581af6e68729865580121dbeb6d85a06d2ea7; outer receipt a022e40f068703cd59ce6d6a7fb6530cce6907681baa26eb1dfc77c09f0c8898; exported-record audit 24afc50f6f860394d1ebfa7a8b754ddd9cb97f9e88a0dcfcbcb659193ecbfe5f |
| Current Linux arm64 | Current nonroot Linux arm64 on ext4, native ARM through QEMU HVF, Go1.27.1/HugoExtended0.166.0/Git2.47.3: full offline unit/vet (370 top-level passes), all13 decisive pure cases and4 membership children without skips,10 selected actual-Hugo cases without skips, exact native/installed current archive identity and bilingual/offline/ordinary-Hugo/signal flows passed. 24 commands reach expected exits including missingHugo2. Guest 268102f69c0950f9d2994d22cd2fd290fc11e24bd6d6f916fd70a93ca4946c74; outer f3c066fdc9b97feff92160346185a1af978a5172eed5c81904ac7c0e5fc6c982; source/SDK/borrowed/old-task guards equal and owned VM reaped. Default optional unit skips retain their named gating reasons; no full Linux Hugo-suite/browser/linter claim |
| Prior-source Linux amd64 failed trial | Unqualified after the preserved current TCG trial failed: outer receipt 3543664ba5590f2ba5a8f676b196bb636b72bc819913289f415d0a8a841c1bdb, guest summary 16075204d287713c7f7650c0a65dd289dd4bd83db07c9ba4b85b3f21244d5240. Full offline units (370 top-level passes), vet and the first three selected Hugo cases passed. The published-cache candidate request hit the test HTTP client’s 90-second deadline; candidate parity, the remaining six selected Hugo cases, native rebuilt archive and installed archive smokes were not reached. Deadline review 12917b9eb89e3abc5893e08da3b6b6e20743dcb4c14e6f7ba8561628e3566934. A18 stays open; no future preflight or full qualification result is inferred |
| Current Linux amd64 | Current nonroot Linux amd64 on ext4, QEMU TCG emulation, Go1.27.1/HugoExtended0.166.0/Git2.47.3: full offline unit/vet (370 top-level passes), all13 decisive pure cases and4 membership children without skips,10 selected actual-Hugo cases without skips, exact native/installed current archive identity and bilingual/offline/ordinary-Hugo/signal flows passed. 49 commands reach expected exits including missingHugo2. Guest 3a1a32979efc843de8b95b7c13824026e17f71c06d4c458b738c0b9583fb4723; outer 30cf4950cc83fa0732047d9a0f89bb59e68779ee2e8f5c755724c9679be265e3; source/SDK/borrowed/old-task guards equal and owned VM reaped. Default optional unit skips retain their named gating reasons; no full Linux Hugo-suite/browser/linter claim |
| Runtime-equivalent preceding four-consumer candidate corpus | Source epoch 683daca0…33f224; runtime123/binary74ad is byte-identical to current 196245a3…42d43. The corpus was not rerun after the test-only amendment. 853.249 seconds; native/candidate-native 0/0/0/1, API/view 0/0/0/2; diagnostics 28/144/120/11250, coverage 29/34/41/29. Summary a1e98ca3e10095a1134381666bacf256f8e8827cd3900c9e811b7120de4c2974, receipt 05c4562a50d9f83ba2c99879ec841870c5e753199e41792bd5bc718cf8046e7b, independent audit 3a1b0b6e3a8c6b1a0d82c5f82b46c84b1e44d6c30bab655610cb9e86e6a30b47; final TEN bytes have their own render boundary |
| Final canonical lifecycle and rendered checks | The exact promoted TEN bytes require independent canonical rendering and navigation/URL receipts; earlier rendered proofs do not qualify these amended bytes |
The preceding six-gate b40b7787b3da8dc1e0763812b6dde529b4b5b69fe479d79940f1161223124e1d, host/archive bcb4d7599e965c1b3cfe7fe698ca14061ad53d45e7a194337aeebb8d37aa77c1, and ARM outer a022e40f068703cd59ce6d6a7fb6530cce6907681baa26eb1dfc77c09f0c8898 / guest 409990bc1425f4bf219f8911a71581af6e68729865580121dbeb6d85a06d2ea7 / audit 24afc50f6f860394d1ebfa7a8b754ddd9cb97f9e88a0dcfcbcb659193ecbfe5f remain passed only for their captured source. They are retained alongside the new exact-source proof, not overwritten or relabeled. Historical 26 axe checks/screenshots and 22 codec cases are carried with unchanged UI/codec/runtime inputs, not claimed re-executed.
The initial max-CPU AMD trial stays failed: receipt 3543664ba5590f2ba5a8f676b196bb636b72bc819913289f415d0a8a841c1bdb, guest summary 16075204d287713c7f7650c0a65dd289dd4bd83db07c9ba4b85b3f21244d5240. The test client timed out after 90 seconds awaiting candidate headers; candidate parity and the remaining six selected Hugo cases/native rebuild/installed smokes were not reached. Guest inputs stayed exact; the host guard recorded only a .git directory timestamp change, whose cause was not proven. The separate qemu64 one-test preflight also failed at the unchanged 90-second HTTP client deadline: outer receipt fc68173ccdfd8ce263ecdf082a533d9da666a4cc2e1e5e29880ee827286132ac, guest summary e350ff65feeee166ffac1d337db9bbd70d3895b1fb6d93df0a30ca4de09019fc. The named case took 177.71 seconds, compared with 176.64 seconds in the first trial; no CPU-model speedup is inferred. Its inputs remained exact and its VM was reaped. Neither failed trial is relabeled as a pass.
A later, explicitly nonqualifying Go-overlay diagnostic preserved the same
production source and every original semantic assertion. Outer receipt
0bc6d563b7cd9ca862717c2123ee0836d83b6b927d00204a0b031049c38e93f0
and raw-bound classification
66a1422cdb79ab9f1cf683f441ade0ce4adb4a7a666d524c4b9ed98ebee28708
record a passed named case in 352.40 seconds. Original capture took 26.254 seconds,
Studio capture 26.211, candidate HTTP 94.312, direct preview 94.318 and CLI
preview 81.962. Both graphs retained 1,256 unique inputs, including 1,198 module
inputs. The old original-capture context was expired by the HTTP result; fresh
independent direct/CLI contexts completed normally. All 20,564 host guards and
five guest command guard pairs stayed exact; the owned VM was cleanly reaped.
This diagnostic altered test budgets and is not exact-source or full A18
qualification. The scoped owning-fixture amendment now uses a 300-second budget
for that candidate request and fresh direct/CLI operations, about 3.18 times the
slowest observed operation. General/original-capture 90-second limits, restoration
of the shared client, shutdown 15 seconds and Go’s default ten-minute cap remain
unchanged. These are test fixture limits, not a product performance SLA. Formal plain-Go AMD/ARM and current archive qualification is recorded in the
current table above; the diagnostic itself remains nonqualifying.
This preceding corpus qualifies the unchanged runtime CLI against its captured, unchanged pre-final-TEN consumer inputs. It does not qualify subsequently amended canonical document bytes; the final TEN has a separate rendered receipt boundary.
The consumer driver compared complete typed diagnostics, coverage, native exit, PlanID, selected Base/After/full modes, unified diff and selected source between API and CLI. It separately verified the complete literal API review and its hash. For attachments and no-ops the selected page retains reviewed Base; page-file edits match reviewed After. Nonissue views are bounded samples; all issues and pages are paginated. The 53 protected operations have 212 all-four per-operation source proofs plus four overall proofs (864 raw inventory pairs across four categories) and 53 root pairs. Seventy-one retained artifacts are bound. No Apply, saved plan or consumer write occurred. The completed corpus’s file-only collector needed two preserved metadata corrections for absent historical trial/self-test files; no CLI/Hugo operation was rerun. The existing 22 negative codec cases are historical checks of unchanged codec bytes, not a newly executed self-test.
The repository retains its 10,462 pre-existing duplicate-ID findings and 788
review-info records. Its selected actual DFE HTML is available, while four
oversized actual PRINT files stay unserved (413, zero response body):
_print/pkg/index.html 73,976,221 bytes, _print/pkg/pgsql/index.html 69,903,999,
zh/_print/pkg/index.html 73,086,240 and zh/_print/pkg/pgsql/index.html 69,052,754.
The 64 MiB per-file preview bound is unchanged: required partial-preview
incompletion remains 2, native findings remain 1, and Apply is refused.
This is an expected diagnostic outcome, not a failed preservation check.
Linux prerequisites were prepared in exclusively owned guests from signed Debian metadata: exactly ten new packages and three approved existing-package updates, verified before and after installation. SDK/Hugo/module caches were provisioned separately and reused offline. Qualification runs as an ordinary user on ext4; cached inputs and all 212 source files’ bytes/full modes stay guarded. Optional tools/browser tests are not silently claimed on guests without those prerequisites: default unit skips retain their actual gating/not-applicable reasons, while all required pure top-level cases, the no-skip membership children, selected Hugo and signal cases must execute. Linux amd64 uses QEMU TCG on the ARM host and is explicitly emulated. Darwin amd64 remains an experimental archive: actual execution returned Bad CPU type (errno 86), with no Rosetta installation or claimed supported runtime. Windows is outside the declared scope.
The current Linux archive digests are ac883e54a1df0b820696279c63881ba75a00d279f507330128fe8d5aff59c52e
(arm64, 4,552,687 bytes) and 2dde43bf94ef35aac2111b07dcb9b2766fbf9f883fe39ccd646d14a98b94d734
(amd64, 5,034,668 bytes). The preceding 683daca0…33f224
archive digests c191383af21913be6940ec41be11755b3d985344bbc0f65cc3f5de16424a96a4
and 6531b27d889260afe804c1f49f37541fbae46e57b5d17a20178c28cb51968794
remain historical. Cross-compilation alone does not establish runtime
support. SDK/guest preparation failures, the first ext4 membership failure,
and earlier private host metadata/resources trials remain immutable evidence.
Local completion does not establish a commit, public release, consumer adoption,
hosted CI execution, deployment or public-site verification. Uninvoked E1–E4
extensions are separate inactive scope and do not hold finite R1–R8 completion
open.
Acceptance case ledger
This ledger combines the initial audit with accepted R1–R7 evidence and the qualified R8 candidate gates. Each full case stays open until its entire outcome is recorded; an accepted stage does not close later-stage scope.
| Case | Required outcome | Code or checker evidence | Status and missing decisive evidence |
|---|---|---|---|
| A01 | One oink.result/v1 JSON result; stderr logs; policy 1, required incompletion 2 |
Protocol/public R1–R8 commands, frozen owning tests and exact-binary CLI/API reports; unchanged result schema; current eight owning gates/Linux qualification plus unchanged-runtime carry-forward of the preceding corpus in #a18 | Passed supported current command scope; future added commands require their own evidence |
| A02 | Hugo resolves slug/url/permalinks/aliases, mounts, unlisted pages and language roots | Real PageFacts/manifest/custom-mount/translationKey fixtures; preserved ordinary artifacts; final consumer facts | R1 scope passed; later stage-specific use of those facts requires its own acceptance |
| A03 | Definite local missing routes fail; outside origin/path and declared external scope classified honestly | Actual rendered-reference fixture plus subpath/policy regressions and final real sites | Passed the required A03 scope; external availability remains explicitly unchecked |
| A04 | Filename, directory and translationKey; duplicate/missing/draft cases; strict/localized policy |
R2 translation engine, actual Hugo/public commands, final reports and numeric supplement | Passed R2 required scope |
| A05 | Absent record unknown; changed source/translation hash visible; no mtime inference | R2 hash/status/diff, public preview/apply and final reports | Passed R2 required scope |
| A06 | Real fences, inline code, shortcodes, HTML, attributes, unknown fields and protected text boundaries | R2 actual syntax/provenance fixtures, reviewed corpus and final reports | Passed R2 required scope; catalog and unsupported-source limits remain explicit |
| A07 | Acknowledged findings visible; new findings block per policy; required unavailable tools cannot pass | R2 baseline/public plans; R6 fake/actual protocol, missing/unsafe/offline/network-uncertainty and required-precedence fixtures passed | Supported scope passed; required unavailable/uncertain tools remain 2 |
| A08 | Post-check bytes invalidate manifest; provider uploads verified tree without another build | R3 manifest/export/tampering/public one-build tests; final ordinary-Hugo comparison and provider rehearsal | Passed R3 required local scope; provider upload not executed |
| A09 | Both CI templates; custom workflows preserved; permissions/variables/provenance and stale plan protection | R3 offline generation/bootstrap, public preview/apply/stale-input tests, custom workflow supplement and local rehearsal | Passed R3 required local scope; custom workflows remain unknown and unchanged; hosted CI not executed |
| A10 | Reject HTTP 200 fallback, wrong language/build, missing resource/canonical mismatch; incomplete timeout/auth/rate-limit | R3 explicit-network local HTTP and public result fixtures, including required identity absence | Passed R3 required fixture scope; public deployment and browser runtime not verified |
| A11 | All declared profiles/languages; target protection; ordinary Hugo; unknown editor settings retained | R4 24 ordinary Hugo/public profiles, full Starter authoring/editor flow, snippets, actual mounts, source identities, JSONC preservation and external schema reproof | Required supported R4 local implementation/corpus scope passed; documented unsupported editor inputs remain explicit |
| A12 | Readable diff and route comparison; dirty/workspaces/replacement/vendor; recovery/concurrency | Frozen actual-Hugo seven synthetic pinned cases, public upgrade, source/external guards, observed alias retarget and guarded partial rollback | Required bounded R4 local implementation/corpus scope passed; unknown redirects/multihost remain incomplete and no automatic config migration is claimed |
| A13 | Deleted B finds unchanged inbound A; translations/attachments/derived outputs; global full scope | R5 committed Git/actual Hugo deletion, alias-inbound, global/uncertain input and unavailable-baseline fixtures; exact-binary consumer reports | Passed required supported R5 scope; unavailable or unproven historical inputs stay explicit 2 |
| A14 | Candidate before apply; stale/hash/write failures preserve later edits; ambiguous references unchanged | R2/R4 shared safety, R5 full-mode/inventory moves and R8 regenerated intent/fresh-input candidate validation, guarded writer and stale/late-editor/attachment tests; current eight owning gates/Linux qualification plus unchanged-runtime carry-forward of the preceding corpus in #a18 | Passed supported R5 CLI and R8 CLI/Studio editing scope; ambiguous or unavailable required inputs still block |
| A15 | Workspace/direct parity; selected writes only; bounded context with paths/versions/reasons; no content execution | R5 bounded captured-source/context fixtures and four-site queries; R6 registry/direct/aggregate parity and explicit-name saved apply with other sites preserved | Supported context/workspace scope passed; no implicit batch writes |
| A16 | Five useful CLI-parity views; keyboard/mobile/light/dark; source/preview isolation | Accepted R7 evidence retained; historical source-bound R8 read-only 14 axe/screenshots and Editor 12 axe/screenshots with unchanged UI bytes; current backend gates, ARM and corpus separately verified, native/API parity, preview isolation, four consumers and canonical render passed; current eight owning gates/Linux qualification plus unchanged-runtime carry-forward of the preceding corpus in #a18 | Passed supported local views; required partial-preview incompletion/native findings remain visible; no universal browser/platform claim |
| A17 | No-op bytes; YAML unknown/comment/order preservation; stale-save and attachment collisions rejected | Corrected frozen core/public/guarded-writer race, actual Hugo/tools, source-bound Editor/read-only browsers, exact-binary four-consumer proposal parity/preservation and guarded canonical source/render passed in #r8; current eight owning gates/Linux qualification plus unchanged-runtime carry-forward of the preceding corpus in #a18 | Passed supported local editing scope; required partial preview/native findings still block Apply; final A18 separate |
| A18 | Actual declared macOS/Linux runtimes; child signals; provisioned offline runs; honest unsupported inputs | Current freeze/source and repeated five-archive reproduction; Darwin arm64, native Linux arm64 and emulated Linux amd64 nonroot ext4/full offline unit-vet/selected Hugo/native archive/signal smokes passed in #a18 | Passed current declared runtime/archive scope; optional guest prerequisites remain explicit skips; Darwin amd64 is experimental/unverified and Windows outside scope |
Candidate sites and source preservation
The selected acceptance inputs are the embedded Starter plus three distinct maintained consumer sites. They reuse the historical corpus without writing consumer sources. The Starter source checkout is provenance input; generated profile trials use disposable directories.
| Input in the sibling checkout layout | Initial observed identity and purpose | Current candidate acceptance |
|---|---|---|
oink-starter / generated Starter |
Source 137843b, two initial status entries; licensed fixed archive, language/profile/root/subpath trials |
R1 bilingual init/check and R4 all-profile ordinary/public authoring flows passed; archive/license unchanged |
oink.pgsty.com |
Source 907d873 with existing changes; bilingual documentation/regression and explicit local-theme trial |
Final R1 check and source preservation passed; local-theme evidence remains distinct from public-pin evidence |
pig.pgsty.com |
Source 75050c0, five initial status entries; root Docs/Blog rewrites and nonrendering sidebar entries; declared v1.1.0 |
Final R1 check and source preservation passed |
repo.pgsty.com |
Unborn main, no HEAD revision; materialized untracked sources, generated catalog and declared v1.1.0 |
Final R1 check and source preservation passed; revision remains unknown |
For each run, record effective module source and versions, flags/network policy, exit/result/coverage, raw evidence location, and preservation outcome. Before/after inventories must include all tracked and non-ignored untracked source bytes and modes, Git status/index state, workspace/replacement files, and effective vendor inputs. Compare exact inventories; unchanged file counts alone do not prove preservation. Keep reports, isolated candidates, output and caches outside consumer sources and outside Git. Full-build timing comparisons must use the same current input baseline before any incremental speed claim.
Owning checks and documentation gate
Start with the smallest affected Go packages and public behavior tests. The
existing repository gates are make test (offline tests and vet) and
make test-hugo (actual Hugo Starter, snapshot, manifest and public command
fixtures). The owning Hugo gate now runs all owning packages without the old
narrow test-name filter; new fixtures must remain in that gate.
Use a race run for concurrent plan/server changes when the focused tests justify
it. Unit fixtures remain offline; networking requires explicit invocation.
For documentation, preserve EN/ZH heading number, order and stable explicit IDs. The narrow source checks are:
Both source checks passed after adding this record and its Chinese peer: eight Chinese research files passed the style checker; translation source coverage was 137/137 pairs with 1,082 source headings. These checks establish source style, pairing and explicit translated IDs only. Rendered acceptance was not run by this documentation audit.
After building the relevant site, complete the rendered documentation gate:
make build validates the declared published pin. make check selects the
sibling theme for the complete non-browser regression suite; these inputs
cannot substitute for one another. Studio requires its own actual browser and
accessibility acceptance. A passing prose source check does not prove rendered
bilingual output or Studio interaction.
Delivery state and remaining limits
| State | Current completion evidence; history retained above |
|---|---|
| Local implementation | Finite R1–R8 supported implementation completed locally, including Studio/read-only and opt-in reviewed editing; current A18 runtime/archive scope passed. Canonical lifecycle rendering is bound separately to these exact bytes |
| Local validation | Historical R1–R8 owning/browser/corpus/render records retained; current 2026-10-04 backend correction and eight current owning gates, actual three-target runtime/archive checks and unchanged-runtime carry-forward of the preceding four-consumer preservation/parity passed in #a18. Required repository findings/partial preview remain visible. Rendered navigation/URL checks have a separate exact-byte receipt boundary |
| Commits | Baseline CLI commit identified; no maintenance commit established by this record |
| Archive and runtime qualification | Current corrected source: Darwin arm64, native Linux arm64 and QEMU-TCG-emulated Linux amd64 passed installed archive/offline/signal/filesystem flows; two fresh builds reproduce all five archives. Darwin amd64 remains experimental/unverified after actual failed execution |
| Public distribution and consumer adoption | Not performed by this work |
| Deployment and public-content verification | Not performed by this work; local HTTP fixtures can prove the verifier without cloud credentials |
The finite R1–R8 implementation and required current A01–A18 runtime/archive scope have decisive local evidence. Canonical lifecycle rendering requires a separate receipt for these exact new documentation bytes; preceding rendered evidence does not qualify them. Uninvoked E1–E4 and experimental/unsupported platforms do not add unfinished core requirements. Publication, pushing, deployment, hosted CI and consumer writes remain separate unperformed actions; known repository findings and required preview incompletion remain diagnostic limitations, not hidden successes.