Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
180 changes: 97 additions & 83 deletions White-Paper.html

Large diffs are not rendered by default.

110 changes: 110 additions & 0 deletions governance/contracts/public-explanation-surfaces.contract.v1.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,110 @@
{
"schema_version": "public-explanation-surfaces-contract.v1",
"contract_id": "public-explanation-surfaces-0001",
"classification": "PUBLIC",
"status": "PROPOSED_SOURCE_CLEANUP",
"mode": "PREPARE_ONLY",
"scope": {
"mutable_candidate_surfaces": [
"index.html",
"White-Paper.html"
],
"immutable_archival_artifacts": [
"Resilience Ledger v0 4.pdf",
"Resilience Ledger v0 5.pdf"
],
"verification_surface": "governance/harnesses/verify-public-explanation-surfaces.js",
"excluded_actions": [
"MERGE",
"DEPLOYMENT",
"PDF_REVISION",
"SEMANTIC_DATA_MIGRATION",
"LIVE_STATE_ACCEPTANCE"
]
},
"source_profile": {
"hash_basis": {
"repository_text": "SHA-256 of UTF-8 bytes with CRLF normalized to LF",
"pdf": "SHA-256 of exact file bytes"
},
"base_repository_commit": "3e809fc1596491cb252723d3ba694e7b73047f71",
"atlas_candidate_source": {
"path": "terms.enriched.json",
"sha256": "0a57277ffbdcfa00771ae05777f0c7b8782edeaee10b90ed5242430ecd4e2413",
"terms": 439,
"sources": 193,
"relations": 360,
"status_boundary": "REPOSITORY_LABEL_NOT_REVIEW_RECEIPT"
},
"atlas_projection_baseline": {
"path": "governance/contracts/atlas-data-sync-baseline.md",
"sha256": "81e5a5fb1b5f84c23b45017a5e53dcc5347595f361aa76bd98b02d0694f0a1d6",
"ask_terms": 435,
"curation_terms": 435,
"explore_terms": 435,
"gap_check_terms": 433,
"projection_statuses": {
"ask": "177 reviewed, 258 candidate",
"curation": "177 reviewed, 258 candidate",
"explore": "177 reviewed, 258 candidate",
"gap_check": "177 reviewed, 256 candidate"
}
},
"systems_primitives": {
"path": "primitives.json",
"sha256": "f0665f18d96b2084075d1b5bfb627e46f6f5f5ddfa4470aa2c997f3bbfefd457",
"records": 160
},
"resilience_ledger_v0_4": {
"path": "Resilience Ledger v0 4.pdf",
"sha256": "2543d21b5f7c29a50ae6a6769aa9af5611b60940a4373b0dc2077ce191c72f0b",
"artifact_status": "ARCHIVAL_UNCHANGED"
},
"resilience_ledger_v0_5": {
"path": "Resilience Ledger v0 5.pdf",
"sha256": "65644b4d567d6937a34639f9724de2b072becb278792b7c1c2ef05f4b2c8672a",
"artifact_status": "ARCHIVAL_UNCHANGED",
"function_terms": [
"Absorb load (alias: Buffer)",
"Check against a fixed reference (alias: Floor)",
"Reset to baseline (alias: Return)"
]
}
},
"presentation_invariants": [
"The home surface identifies 439 as the declared candidate-source inventory and does not imply that every tool serves all 439 records.",
"The home and explanation surfaces keep the 435- and 433-record public projections and their legacy status-label mismatch visible through the recorded data-sync baseline.",
"The Systems Primitives card reports 160 records for the pinned primitives.json source.",
"No unsupported novelty, uniqueness, endorsement, universal correctness, or certification claim is presented.",
"Area labels are not presented as working filters unless a distinct filtered result is implemented and verified.",
"Local processing, Cloudflare Web Analytics, network, privacy, offline, and determinism claims remain scoped to tested code paths and named assets rather than stated absolutely.",
"Cadence and Basin mappings are labeled as bounded analogies and expose source links; the cited physical or ecological result is not generalized as a law for AI systems.",
"The ledger function is named Reset to baseline; Return is shown only as its v0.5 alias.",
"White-Paper.html describes itself as a maintained public guide, not as the sole canonical state or a peer-reviewed paper.",
"The v0.4 and v0.5 PDFs are labeled archival, are linked as exact artifacts, and remain byte-for-byte unchanged.",
"The guide discloses the observed archival PDF pagination defects without claiming to repair the unchanged bytes.",
"No future Witness Ledger or v0.6 artifact is asserted without a repository artifact and a separate source decision.",
"Governance copy points to append-only events and checkpoints without claiming that every historical project change was logged.",
"Primary content has a working skip target, one main landmark, one page heading, and scoped table headings or captions where tabular data is used."
],
"acceptance_checks": [
"PINNED_SOURCE_DIGESTS_MATCH",
"PINNED_COUNTS_MATCH",
"ARCHIVAL_PDF_BYTES_UNCHANGED",
"HTML_SEMANTIC_BOUNDARIES_MATCH",
"UNSUPPORTED_ABSOLUTE_CLAIMS_ABSENT",
"INLINE_SCRIPTS_PARSE",
"MUTATION_CANARIES_REJECTED",
"OWNER_MERGE_STILL_REQUIRED",
"PRODUCTION_DEPLOYMENT_NOT_ATTEMPTED"
],
"claim_ceiling": [
"FILE_DIGEST_BOUND_SOURCE_CANDIDATE_ONLY",
"NOT_SEMANTIC_TRUTH_OR_REVIEW_RECEIPT",
"NOT_PDF_CORRECTION_OR_ENDORSEMENT",
"NOT_PRIVACY_SECURITY_OR_ACCESSIBILITY_CERTIFICATION",
"NOT_LIVE_HEALTH_OR_PRODUCTION_IDENTITY",
"NOT_MERGE_OR_DEPLOYMENT_AUTHORITY",
"OWNER_MERGE_REQUIRED"
]
}
51 changes: 51 additions & 0 deletions governance/decision-log/0011-public-explanation-surface-cleanup.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
# Decision 0011: Public explanation-surface cleanup

Date: 2026-08-13
Authority: repository owner authorization for the bounded public Atlas cleanup
Decision: **ACCEPT_WITH_LIMITS**
Mode: **PREPARE_ONLY**
Consequence class: C2

## Observation

The merged Atlas repair is live, but the public home and `White-Paper.html`
still contain older explanatory copy that is not aligned with the repository's
recorded source boundaries. Examples include an unsupported novelty label, a
stale 150-primitives count, a 439-record claim applied to a 435-record
projection, absolute privacy and determinism language, an inverted
`Reset`/`Return` name, and future-edition language with no matching repository
artifact.

The v0.4 and v0.5 Resilience Ledger PDFs are historical artifacts. Their
content and layout can be assessed and bounded, but this packet does not
silently revise them.

## Accepted preparation

- Correct only the public home and maintained explanation surface.
- Separate the declared 439-record candidate source from the 435- and
433-record public projections recorded by the data-sync baseline.
- Derive the Systems Primitives count from the pinned 160-record JSON source.
- Remove unsupported novelty, universality, certification, and absolute
privacy or determinism claims.
- Keep Cadence and Basin cross-domain mappings explicitly bounded and linked to
their sources.
- Use the v0.5 source term `Reset to baseline`, with `Return` only as its alias.
- Link and label the v0.4 and v0.5 PDFs as archival artifacts while preserving
their exact bytes.
- Point self-governance language to the repository's append-only events and
checkpoints without claiming complete historical coverage.
- Repair the explanation surfaces' basic navigation and table semantics.
- Bind the resulting source candidate to deterministic checks and exact file
digests before presenting it for owner review.

## Limits

This decision accepts preparation of a file-digest-bound source candidate for
a public pull request. It does not accept the semantics of the 439-record
candidate inventory or any older projection, establish per-term review,
correct or endorse either archival PDF, validate every external citation,
certify accessibility, privacy, security, or offline behavior, establish live
health or production identity, authorize an agent merge, or authorize a
Cloudflare deployment. Owner merge remains required; production observation is
a separate event after any merge.
1 change: 1 addition & 0 deletions governance/harnesses/run-all.js
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ const scripts = [
'verify-atlas-data-materialization.js',
'verify-atlas-runtime.js',
'verify-home-surface.js',
'verify-public-explanation-surfaces.js',
'verify-atlas-foundational-repair.js',
'verify-six-signal-surface.js',
'verify-authority.js',
Expand Down
27 changes: 22 additions & 5 deletions governance/harnesses/verify-atlas-data-sync-v2.js
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@

const fs = require('fs');
const path = require('path');
const child = require('child_process');
const H = require('../../corpus-harness.js');
const L = require('../ledger/lib.js');

Expand All @@ -18,6 +19,7 @@ const V1_CONTRACT_PATH = path.join(L.repoRoot, 'governance', 'contracts', 'atlas
const V1_CONTRACT_SHA256 = '45cb718d137cf38b15cd849475faabe10a10df155eff0db0bfb71dca62070821';
const CORRECTION_EVENT_PATH = path.join(L.repoRoot, 'governance', 'ledger', 'events', 'governance',
'000008-atlas-data-sync-portability-corrected.json');
const CORRECTION_RECORDING_COMMIT = '2a9e5f30451b1e5f3ac0c3cf86f9c4e5f96fa425';
const REQUIRED_PROJECTION_KEYS = ['expected', 'id', 'kind', 'path'];

function readJson(relative) {
Expand All @@ -28,8 +30,24 @@ function canonicalTextHash(text) {
return L.sha256CanonicalTextBytes(Buffer.from(text, 'utf8'));
}

function historicalBytes(relative) {
try {
return child.execFileSync('git', ['-c', `safe.directory=${L.repoRoot}`, 'show',
`${CORRECTION_RECORDING_COMMIT}:${relative}`], {
cwd: L.repoRoot, encoding: null, maxBuffer: 64 * 1024 * 1024,
stdio: ['ignore', 'pipe', 'pipe']
});
} catch (error) {
throw new Error(`${relative}: cannot resolve portability-correction evidence at its recording commit`);
}
}

function verifyCorrectionBindings() {
const event = JSON.parse(fs.readFileSync(CORRECTION_EVENT_PATH, 'utf8'));
if (L.sha256CanonicalTextBytes(historicalBytes(path.relative(L.repoRoot, CORRECTION_EVENT_PATH).replace(/\\/g, '/'))) !==
L.sha256CanonicalTextBytes(fs.readFileSync(CORRECTION_EVENT_PATH))) {
throw new Error('portability correction event differs from its recording commit');
}
if (event.event_id !== 'evt_governance_atlas_data_sync_portability_correction_0008' ||
event.decision !== 'CORRECT' || event.payload?.semantic_data_changed !== false ||
event.payload?.data_migration !== 'DEFER') {
Expand All @@ -41,12 +59,11 @@ function verifyCorrectionBindings() {
ref.source_locator.split(/[\\/]/).includes('..')) {
throw new Error(`${ref.ref_id}: unsafe or missing correction evidence locator`);
}
const absolute = path.resolve(L.repoRoot, ref.source_locator);
if (!absolute.startsWith(`${path.resolve(L.repoRoot)}${path.sep}`) || !fs.existsSync(absolute)) {
throw new Error(`${ref.ref_id}: correction evidence file is missing or outside the repository`);
if (!path.resolve(L.repoRoot, ref.source_locator).startsWith(`${path.resolve(L.repoRoot)}${path.sep}`)) {
throw new Error(`${ref.ref_id}: correction evidence file is outside the repository`);
}
if (L.sha256CanonicalTextBytes(fs.readFileSync(absolute)) !== ref.sha256) {
throw new Error(`${ref.ref_id}: correction evidence digest mismatch`);
if (L.sha256CanonicalTextBytes(historicalBytes(ref.source_locator)) !== ref.sha256) {
throw new Error(`${ref.ref_id}: historical correction evidence digest mismatch`);
}
}
}
Expand Down
46 changes: 34 additions & 12 deletions governance/harnesses/verify-home-navigation-history.js
Original file line number Diff line number Diff line change
Expand Up @@ -4,16 +4,31 @@
const fs = require('fs');
const path = require('path');
const vm = require('vm');
const child = require('child_process');
const L = require('../ledger/lib.js');

const root = path.resolve(__dirname, '..', '..');
const recordingCommit = '12b31befb0731a2e511672d108d9696c80f0f32b';
const eventPath = 'governance/ledger/events/governance/000009-atlas-navigation-history-corrected.json';
const contractPath = 'governance/contracts/atlas-navigation-history.contract.v1.json';
const observationPath = 'governance/observations/2026-08-13-atlas-navigation-local-browser.json';
const source = fs.readFileSync(path.join(root, 'index.html'), 'utf8');
const contract = JSON.parse(fs.readFileSync(
path.join(root, 'governance', 'contracts', 'atlas-navigation-history.contract.v1.json'), 'utf8'));
const event = JSON.parse(fs.readFileSync(path.join(root, 'governance', 'ledger', 'events', 'governance',
'000009-atlas-navigation-history-corrected.json'), 'utf8'));
const browserObservation = JSON.parse(fs.readFileSync(path.join(root, 'governance', 'observations',
'2026-08-13-atlas-navigation-local-browser.json'), 'utf8'));

function historicalBytes(relative) {
try {
return child.execFileSync('git', ['-c', `safe.directory=${root}`, 'show', `${recordingCommit}:${relative}`], {
cwd: root, encoding: null, maxBuffer: 64 * 1024 * 1024, stdio: ['ignore', 'pipe', 'pipe']
});
} catch (error) {
throw new Error(`${relative}: cannot resolve navigation evidence at its recording commit`);
}
}

const historicalEventBytes = historicalBytes(eventPath);
const currentEventBytes = fs.readFileSync(path.join(root, eventPath));
const contract = JSON.parse(historicalBytes(contractPath).toString('utf8'));
const event = JSON.parse(currentEventBytes.toString('utf8'));
const browserObservation = JSON.parse(historicalBytes(observationPath).toString('utf8'));

function extractFunction(text, name) {
const start = text.indexOf(`function ${name}(`);
Expand Down Expand Up @@ -244,6 +259,9 @@ function failuresFor(text) {
}

const errors = [];
if (L.sha256CanonicalTextBytes(currentEventBytes) !== L.sha256CanonicalTextBytes(historicalEventBytes)) {
errors.push('navigation correction event differs from its recording commit');
}
if (contract.schema_version !== 'atlas-navigation-history-contract.v1' ||
contract.status !== 'PROPOSED_CORRECTION' ||
!contract.claim_ceiling.includes('OWNER_MERGE_REQUIRED')) {
Expand All @@ -255,7 +273,7 @@ if (event.event_id !== 'evt_governance_atlas_navigation_history_corrected_0009'
errors.push('navigation correction event boundary is invalid');
}
if (browserObservation.schema_version !== 'atlas-browser-observation.v1' ||
browserObservation.subject.source_sha256 !== L.sha256CanonicalTextBytes(fs.readFileSync(path.join(root, 'index.html'))) ||
browserObservation.subject.source_sha256 !== L.sha256CanonicalTextBytes(historicalBytes('index.html')) ||
browserObservation.subject.source_state !== 'UNCOMMITTED_WORKTREE_CANDIDATE' ||
browserObservation.instrument.profile_or_session_data_collected !== false ||
browserObservation.result !== 'MATCHED' || browserObservation.cases.some((item) => item.result !== 'MATCHED') ||
Expand All @@ -270,9 +288,12 @@ for (const reference of event.evidence_refs) {
continue;
}
const absolute = path.resolve(root, locator);
if (!absolute.startsWith(`${root}${path.sep}`) || !fs.existsSync(absolute) ||
L.sha256CanonicalTextBytes(fs.readFileSync(absolute)) !== reference.sha256) {
errors.push(`${reference.ref_id}: evidence digest mismatch`);
if (!absolute.startsWith(`${root}${path.sep}`)) {
errors.push(`${reference.ref_id}: evidence locator is outside the repository`);
continue;
}
if (L.sha256CanonicalTextBytes(historicalBytes(locator)) !== reference.sha256) {
errors.push(`${reference.ref_id}: historical evidence digest mismatch`);
}
}
errors.push(...failuresFor(source));
Expand All @@ -284,7 +305,7 @@ const canaries = [
source.replace("replaceFrameLocation(frame,'about:blank')", "replaceFrameLocation(frame,'Delta-Atlas-GapCheck.html')"),
source.replace("return Object.prototype.hasOwnProperty.call(NAV_ROUTES,h)?h:null;",
'return h||null;'),
source.replace("}catch(e){return false;}}\n frame.onload", "}catch(e){}}\n frame.onload"),
source.replace("}catch(e){return false;}}\n loading.textContent", "}catch(e){}}\n loading.textContent"),
source.replace("if(!replaceFrameLocation(fr,'Agentic-AI-Governance-Chat.html#embed')){fr.onload=null; return;}",
"fr.src='Agentic-AI-Governance-Chat.html#embed';"),
source.replace("if(!replaceFrameLocation(fr,'about:blank')) return false;",
Expand All @@ -294,7 +315,8 @@ const canaries = [
source.replaceAll("if(writeHistory!==false){try{history.back();}catch(e){}} return false;", 'return false;')
];
for (const [index, mutated] of canaries.entries()) {
if (failuresFor(mutated).length === 0) errors.push(`navigation mutation ${index + 1} was not rejected`);
if (mutated === source) errors.push(`navigation mutation ${index + 1} did not alter source`);
else if (failuresFor(mutated).length === 0) errors.push(`navigation mutation ${index + 1} was not rejected`);
}

if (errors.length) {
Expand Down
16 changes: 16 additions & 0 deletions governance/harnesses/verify-home-surface.js
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,8 @@ check(/<nav\b[^>]*aria-label="Primary navigation"/.test(html), 'primary navigati
check(/<main\b[^>]*id="stage"/.test(html), 'semantic main exists');
check(/<footer\b[^>]*class="floor"/.test(html), 'semantic footer exists');
check((html.match(/<h1\b/g) || []).length === 1, 'exactly one h1 exists');
check(/<a class="skip" href="#stage">/.test(html) && /<main\b[^>]*id="stage"[^>]*tabindex="-1"/.test(html),
'skip link targets the focusable main landmark');
check(!/<(?:div|span|a)\b[^>]*\bonclick=/.test(html), 'no click-only div, span, or anchor controls remain');
check(!/nothing leaves it|no tracking/i.test(html), 'unsupported absolute privacy copy is absent');
check(/Cloudflare Web Analytics/.test(html) && /plan and search text are (?:analyzed|processed) locally/i.test(html) &&
Expand All @@ -34,6 +36,20 @@ check(/Object\.freeze\(\{/.test(html) && /NAV_ROUTES/.test(html) && /hasOwnPrope
check(/Paste a plan into Gap Check/.test(html) && html.indexOf('Paste a plan into Gap Check') < html.indexOf('<details class="sample">'), 'primary plan action precedes optional sample');
check(/sample\.addEventListener\('toggle'/.test(html) && /data-src="Delta-Atlas-GapCheck\.html#embed"/.test(html), 'sample frame is opt-in');
check(/min-height:44px/.test(html) && /@media \(max-width:700px\)/.test(html), 'mobile touch and navigation rules exist');
check(!/THE ONE NOBODY ELSE HAS/.test(html), 'unsupported competitive superlative is absent');
check(/Candidate source inventory: 439 vocabulary records/.test(html) && /Ask and Explore snapshot: <b>435 records<\/b>/.test(html),
'source inventory and embedded projection counts remain distinct');
check(/160 recorded cross-domain primitives/.test(html), 'primitive count matches the recorded library');
check(!/\b150 cross-domain primitives\b/.test(html), 'stale primitive count is absent');
check(/These are the six topic filters available inside Explore/.test(html) &&
(html.match(/<button class="area"/g) || []).length === 0 &&
/Open Explore and choose an area/.test(html),
'area summaries do not pretend to deep-link to an unselected filter');
check(/design hypothesis, not a transferred law/.test(html) && /conditional indicators, not diagnoses/.test(html),
'analogy cards preserve their scientific claim ceilings');
check(/role="status" aria-live="polite"/.test(html) && /frame\.focus\(\)/.test(html),
'embedded route loading is announced and focus is moved');
check(!/every change logged with its reason|every seam on record/i.test(html), 'absolute history-coverage copy is absent');
for (const tag of html.matchAll(/<a\b[^>]*target="_blank"[^>]*>/g)) {
check(/rel="[^"]*noopener/.test(tag[0]), `new-tab link has noopener: ${tag[0].slice(0, 100)}`);
}
Expand Down
Loading
Loading