# EM-0028 execution plan

- Object ID: `em:documentation:sha256:b7c00a2b53e232bc636f07a22e71483a289b8771c2c7063ceb25a55a1ba327a2`
- Kind: `documentation`
- Repository path: [`docs/execution-plans/EM-0028.md`](https://github.com/yoheinakajima/epistemedia/blob/f92846570180dfa4511263f8ba98ecd18f7772c9/docs/execution-plans/EM-0028.md)
- Content digest: `9310ca0c8600aa31d717232187870f9a92b524e1ed2c6cfc86e24e40694025cc`

**Also filed under:** [Disclosure and Public Projection](https://epistemedia.org/topics/disclosure/), [Epistemedia](https://epistemedia.org/topics/epistemedia/), [Epistemic Mesh Protocol](https://epistemedia.org/topics/epistemic-mesh/), [Sovereign Realm Federation](https://epistemedia.org/topics/federation/), [Autonomous Governance](https://epistemedia.org/topics/governance/), [Knowledge Objects](https://epistemedia.org/topics/knowledge-objects/), [Human and Agent Interfaces](https://epistemedia.org/topics/public-interfaces/), [Releases and Reproducibility](https://epistemedia.org/topics/releases/), [Research Program](https://epistemedia.org/topics/research-program/), [Security and Adversarial Robustness](https://epistemedia.org/topics/security/)

## Source content

# EM-0028 execution plan

Status: completed. PR #48 passed exact-head independent review, merged through the protected
squash path, and its accepted main commit passed canonical-domain deployment and public read-back.

## Objective

Turn each bootstrap topic projection into a compact human index without weakening its forensic
identity. Present public objects as grouped editorial cards, keep object identity inspectable at a
smaller typographic scale, and derive only two truthful catalog relations: other topic memberships
and exact repository-object references found in the accepted source text.

## Accepted base and authority

- accepted base: `e9ad62b18f21594258643694c55709f78b4f9a50`;
- immutable task: `tasks/contracts/EM-0028.json`;
- implementation authority: `src/epistemedia/core.py`, `tests/test_interfaces.py`, this execution
  plan, `docs/design-system.md`, activation records, and append-only run receipts;
- forbidden state includes research, catalog source, policies, schemas, workflows, governance
  events, README, and the featured-dossier renderer.

## Change surface

1. Extend the shared topic projection with deterministic canonical-object, Markdown-twin,
   accepted-source, topic-membership, and source-reference links.
2. Resolve Markdown references against the source object's repository directory. Admit a
   navigation edge only when its normalized path names an exact disclosure-safe catalog object.
3. Render grouped, responsive topic cards with cleaned summaries, explicit relation labels, and a
   native technical-identity disclosure for path, media type, object ID, and content digest.
4. Add topic memberships and an exact accepted-source link to canonical object pages.
5. Emit the same projection as static JSON and verify parity with local REST, MCP resource/tool,
   and CLI output.

## Relation boundary

- `also filed under` means only that the accepted topic include rules select the same object;
- `references in source` means only that the accepted Markdown text contains a repository-relative
  link resolving to another exact public object;
- neither relation asserts similarity, evidentiary support, agreement, relevance, or independence;
- external, fragment-only, root-absolute, escaping traversal, missing, non-public, duplicate, and
  self targets do not become object relations.

## Verification

- adversarial resolver fixtures for relative paths, safe parent navigation, escaping traversal,
  fragments, external schemes, root-absolute paths, duplicates, missing objects, private targets,
  and long identities;
- topic and object HTML hierarchy, accessible native disclosure, visible focus, overflow-safe
  identifiers, summary sanitization, and internal-link closure;
- deterministic relation equality across static JSON, REST, MCP resource, MCP tool, and CLI;
- exact accepted Case 001 research, dossier manifest, and review receipt SHA-256 comparison;
- targeted Ruff and interface tests, then full `make check PYTHON=.venv/bin/python`;
- local no-JavaScript browser inspection at `1440 × 900` and `390 × 844`;
- exact changed-path comparison before draft PR creation.

## Accepted Case 001 identities to preserve

- feature manifest: `5c96dead036b527793ba5a0de59bf7316efdfeb591470d4a23e5bf979f3b9288`;
- candidate dossier: `7003413e286e4d310f81441db33f4a467ba2eb3e08f41ddfa3cef5abb34707ca`;
- independent review receipt:
  `503d16396b25b1c22d7fc10ac6fb7db2e530e6ce348d63fa8b639db5a5288f0a`.

## Local completion evidence

- The compiled Epistemedia topic index contains 27 working-tree public objects grouped across
  three actual kinds. Its typed relation inventory contains 220 other-topic memberships and 15
  unique exact public-object references after duplicate and unsafe-target rejection.
- `tests/test_interfaces.py` passes all 32 interface tests, including adversarial resolution,
  internal-link closure, canonical object links, HTML/Markdown/lens parity, and REST/MCP/CLI
  projection equality.
- targeted Ruff `E9,F,I`, `git diff --check`, disclosure audit, and the full 82-test deterministic
  `make check PYTHON=.venv/bin/python` pass. The independent comparison build matches and the
  source tree remains unchanged by validation.
- Browser inspection at `1440 × 900` and `390 × 844` confirms one H1, zero scripts, zero
  horizontal overflow, compact utility headings, smaller machine metadata, and visible 3px focus.
  Expanded relation and technical disclosures preserve the page width and wrap long identities.
  The browser driver focused native `summary` controls but did not dispatch their Enter default
  action; click expansion, native `details`/`summary` markup, keyboard focusability, and focus
  styling were verified. This is recorded as a driver limitation, not an inferred activation pass.
- Object-page inspection confirms a cleaned prose summary, 11.52px machine facts at the mobile
  reference viewport, exact accepted-source navigation, and all catalog-derived topic memberships.
- Case 001 candidate dossier, feature manifest, independent review receipt, source spans, and
  research inputs remain byte-identical to their accepted hashes. No research, catalog source,
  policy, schema, workflow, governance event, README, or featured-dossier renderer was changed.

The final local run is recorded append-only as `20260823T034945Z-em0028-final`. Publication and
live-site claims remain prohibited until protected merge and the separately authorized Pages
deployment complete provider read-back.

## Accepted completion evidence

- independently reviewed candidate: `444b4af56a901778afe6a79f96b6269b827d1c58`, tree
  `c3e416456d2f3541c6ada1ddbe938a32cf49ccca`;
- protected squash commit: `a4ccdb9e4fc2e62018c77f6a6560666f6a69f83f`, with the same tree;
- PR Validate run `32616552460`, job `97138142041`, conclusion `success`;
- resulting-main Validate run `32617161851`, job `97139622644`, conclusion `success`;
- one authorized custom-domain Pages run `32617262450`, build job `97139873721`, deploy job
  `97139967276`, conclusion `success`;
- successful GitHub deployment `6044260511`, status `17181336969`, provider URL
  `https://epistemedia.org/`;
- live release manifest
  `em:release-manifest:sha256:c69ca3eacc2718911a58f68a6d5cc4f2c00d6ffa144046cf9653c90efb6cfc69`,
  catalog `em:catalog:sha256:dfb7ef6b75d7024142ff327622e44f8b0204471734bb1661b7054e21830c8233`,
  and frontier `em:frontier:sha256:c37a16901d41c94ef8c10dd3dc617facd51dd6f8d01dfcfd181044ae3b110fe0`;
- public topic HTML, Markdown, and JSON plus representative object HTML and Markdown returned the
  intended content types and exact accepted commit; mobile and desktop read-back retained one H1,
  no JavaScript, no horizontal overflow, compact cards, subordinate machine identity, and working
  catalog-derived navigation.

The provider and route details are recorded in
`ops/activation/2026-08-22-custom-domain.md`. Run receipt
`20260823T041147Z-em0028-pages` records the external completion checkpoint. The browser driver
again focused native `summary` controls but did not dispatch their Enter default action; native
markup, click expansion, keyboard focusability, and visible focus styling passed, so synthetic
keystroke activation remains the only bounded tooling gap. No hosted API/MCP, DNS, release,
package, credential, or Case 002 claim was activated by this task.
