# EM-0030 execution plan

- Object ID: `em:documentation:sha256:45bb02757ceba9bc76a69fed52a5407813513992f28b6f10ba3bd99d08d1d59c`
- Kind: `documentation`
- Repository path: [`docs/execution-plans/EM-0030.md`](https://github.com/yoheinakajima/epistemedia/blob/f92846570180dfa4511263f8ba98ecd18f7772c9/docs/execution-plans/EM-0030.md)
- Content digest: `ba774f7f14298e1874bae5b50fdebdeff0f21ac0e4f49b82b08cf32f7bdb89b3`

**Also filed under:** [Disclosure and Public Projection](https://epistemedia.org/topics/disclosure/), [Epistemedia](https://epistemedia.org/topics/epistemedia/), [Epistemic Mesh Protocol](https://epistemedia.org/topics/epistemic-mesh/), [Sovereign Realm Federation](https://epistemedia.org/topics/federation/), [Autonomous Governance](https://epistemedia.org/topics/governance/), [Knowledge Objects](https://epistemedia.org/topics/knowledge-objects/), [Human and Agent Interfaces](https://epistemedia.org/topics/public-interfaces/), [Releases and Reproducibility](https://epistemedia.org/topics/releases/), [Research Program](https://epistemedia.org/topics/research-program/), [Security and Adversarial Robustness](https://epistemedia.org/topics/security/)

## Source content

# EM-0030 execution plan

Status: complete. Independently reviewed, admitted through protected PR `#53`, deployed once to the
verified custom domain, and read back from the live provider at accepted commit
`af081caa99fc08d3fabb914ff68f2e672a83bd5b`.

## Objective

Admit the exact independently reviewed EM-0029 dossier through an explicit manifest and replace the
single-case adapter lookup with a deterministic two-case How We Know library. Preserve every Case
001 evidence byte and semantic projection while giving Case 002 coherent human, Markdown, JSON,
share-card, local REST, MCP, CLI, discovery, and review interfaces.

## Bound inputs

- Case 001 manifest SHA-256: `5c96dead036b527793ba5a0de59bf7316efdfeb591470d4a23e5bf979f3b9288`;
- Case 001 dossier SHA-256: `7003413e286e4d310f81441db33f4a467ba2eb3e08f41ddfa3cef5abb34707ca`;
- Case 001 review receipt SHA-256: `503d16396b25b1c22d7fc10ac6fb7db2e530e6ce348d63fa8b639db5a5288f0a`;
- Case 002 dossier: 483,595 bytes, SHA-256
  `1ae06b54fe6c6ce1803836bbf2ecaf3e652bed2c6878b7e095c01a1c689ab87b`;
- Case 002 independent review receipt: 14,968 bytes, SHA-256
  `dd7f8ad5f760137d91346c3bf38b2bbfffbc7e5c2e74a8a987b76d857e4f244e`;
- reviewed Case 002 author head: `16b8e8ebc26948f8d9fa86120c3d495bca3f74e9`.

The new manifest stores identities and view selection, never empirical totals. Counts are derived
from accepted dossier records and fail closed on drift.

## Implementation

1. Add a strict Case 002 application adapter and a sorted multi-manifest registry. Reject duplicate
   numbers, slugs, dossier identities, input paths, generated routes, MCP URIs, and unsupported
   formats.
2. Derive complete ledgers for reports, citation occurrences, URL strings, resolving URL roots,
   source works, editions, exact spans, candidate warrants, pending warrants, unresolved citations,
   no-credit claims, rejected claims, and inaccessible carriers.
3. Compile materially different encyclopedia and skeptical readings from one disclosure-safe
   dossier. Every featured sentence carries its work, edition, span, digest, locator, retrieval,
   and license chain.
4. Iterate the library through the static compiler, local API, MCP resources/tools, CLI, llms.txt,
   sitemap, discovery document, OpenAPI, status, and public audit. Keep Case 001 as the homepage
   lead and add only a compact Case 002 discovery cue.
5. Add byte-regression, adversarial collision/drift, count-ledger closure, policy divergence,
   interface parity, cold-start discovery, identity, accessibility, and responsive tests.
6. Run the full deterministic repository gate, append receipts, push one scoped draft PR, and stop
   for fresh-clone independent exact-head review before protected merge.

## Boundaries

This task does not change research packets, schemas, policies, governance, workflows, DNS, hosted
API/MCP state, or package releases. A merge is not a live deployment. Pages dispatch and provider
plus route read-back require the separately authorized activation step after acceptance.

## Author validation

- the sorted library contains Cases 001 and 002 while preserving the exact Case 001 manifest,
  dossier, and independent-review-receipt bytes listed above;
- Case 002 derives 8 reports, 48 citation occurrences, 30 URL strings, 27 resolving URL roots,
  11 source works, 14 editions, 72 accepted exact spans, 7 candidate warrants, 4 pending warrants,
  9 rejected claims, 34 unresolved citation occurrences, 20 no-credit claims, and 3 inaccessible
  carriers from the accepted dossier rather than the admission manifest;
- focused interface, adapter, adversarial, accessibility, cold-start, and legacy-regression tests
  pass, followed by the full deterministic repository gate with a clean disclosure audit and no
  accepted-source drift;
- the pre-receipt author build emitted 861 files with catalog
  `em:catalog:sha256:ce0cf372b576a26e094b32413c4bfcf38d652aafd6bd7fa65f755ea8dbd68fce`,
  frontier `em:frontier:sha256:f5a247686fb6c4d5c2fce9aca4e0a46d73aa3fee9bc2c94b1de26559ffb9d01a`,
  and release manifest
  `em:release-manifest:sha256:11ef8fbf352b987bdf26b599aba0b57ba7931ebc3eb5edeafa7f1ab51b55aed0`;
  these pre-commit identities are validation evidence, not exact candidate-head release identities;
- the Codex browser bridge could not attach to the in-app webview and its Chrome extension
  disconnected before the first page loaded, so local visual review used an isolated headless
  Chrome process instead. At `1440 x 900` and CDP-emulated `390 x 844`, the final page has one H1,
  zero scripts, no horizontal document overflow, a visible finding in the first viewport, a 3 px
  focus outline, and native Enter activation for the source disclosure. Expanding that disclosure
  initially exposed long identifier and JSON overflow; the author added wrapping rules, a static
  regression assertion, rebuilt, and re-observed zero overflow with the disclosure open.

## Independent review and protected admission

- independently reviewed author head:
  `47a27a20995ab918475001551007af878d47378b`, tree
  `2f5bf431931eaa1909f206a6bbde7371d959b04a`;
- independent browser report SHA-256:
  `f9e61198ce93f22ab1ad167c2bc7e633ea1450d5597b6408da652fbe1ddec38b`;
- independent review receipt:
  `em:run-receipt:sha256:f2c6750c9235e25512ebf6d7a0e7e504c1579d9d0b471adf8f411f7e3c003ef4`;
- receipt head: `4e392c8068b787dda3398b03252018ea45e563eb`, tree
  `7f12a103e5d700534ea39bb39a5c668ce29f7069`;
- author Validate run/job: `33001991949` / `98285935381`, `success`;
- receipt-head Validate run/job: `33021045222` / `98351203041`, `success`;
- protected squash merge: PR `#53` at
  `af081caa99fc08d3fabb914ff68f2e672a83bd5b`, with the reviewed receipt tree and exact base parent
  `9c6a55c4f823b90f3aa4bb052f2f27ad844599e0`;
- resulting-main Validate run/job: `33022534484` / `98356145870`, `success`.

The active `main-protection` ruleset required the strict `check` context, linear history, resolved
threads, and squash-only pull-request admission. No bypass was used, and the source branch was
deleted after merge.

## Custom-domain activation and live read-back

The separately authorized `publish-pages` workflow ran once with
`deployment_mode=custom-domain` on exact accepted main commit
`af081caa99fc08d3fabb914ff68f2e672a83bd5b`:

- workflow run: `33022684967`, conclusion `success`;
- build job: `98356603238`, conclusion `success`;
- deploy job: `98356990321`, conclusion `success`;
- GitHub deployment: `6113614670`;
- successful deployment status: `17384772347`;
- provider URL: <https://epistemedia.org/>;
- release manifest:
  `em:release-manifest:sha256:783ca4cb1d0701240659181a963cdf0f6db5eab4b45d07c07241415fb20f5929`;
- catalog:
  `em:catalog:sha256:092898e1fe3d355761ab4cec653576926a8f5d31621ec7ce23dd60e9d19563ef`;
- frontier:
  `em:frontier:sha256:7e4a173112ef26422acf3ed9434c8b6849c4e011797e20fed6c0a9ca58a1e4c3`;
- compiler: `epistemedia/0.2.0`;
- generated time: `2026-08-26T23:14:34Z`;
- files: `861`.

Provider and external HTTPS read-back confirmed Cases 001 and 002 in discovery, the How We Know
index, homepage Case 002 cue, default and explicit encyclopedia views, materially different
skeptical view, review page, Markdown twin, JSON twin, share card, `llms.txt`, and sitemap. All
canonical URLs use `https://epistemedia.org`; HTML, Markdown, JSON, SVG, text, and XML routes return
their intended content types. Every checked projection carries accepted commit `af081caa...`, the
catalog and frontier above, compiler `epistemedia/0.2.0`, and its view-specific content digest.

Live Chrome/CDP read-back at `1440 x 900` and `390 x 844` confirmed one H1, zero scripts, distinct
encyclopedia and skeptical first-screen findings, a 3 px solid keyboard focus ring, native Tab and
Enter disclosure activation, and no horizontal overflow with the first source disclosure closed or
expanded. Case 002 remains a bounded historical pilot: 8 captured reports, 30 distinct URL strings,
11 source works, 7 candidate warrants, 34 unresolved citation occurrences, 20 no-credit claims,
and zero independently confirmed warrant roots.

Hosted API/MCP, `episte.media`, DNS changes, package/container/release publication, credentials,
accounts, spend, and Case 003 remain outside this completion and are not represented as live.
