NO JUDGMENT WHATSOEVER. Total cognitive freedom for every participant and every intelligence.

Freedom charter
Historical v0.40 evidence record. This page is preserved for attributable history and does not own current v0.41 status, API, authorization, adapter, or layout claims. Open current status.
DOC-072

Verifiable Evidence Capsules, Reproducible Staging Transactions, and Convergent Activation Proof

A synthesis of deterministic evidence compilation, four-role database transactions, signed route activation, lifecycle convergence, correction and non-resurrection, coercion-resilient access, independent-review intake, and the corrected live deployment boundary.

CURRENT WIP SYNTHESISJudgment state: NONE

Purpose and predecessor continuity

v0.40 continues from the repaired v0.39 repository archive `c39-repo-wip.zip` with SHA-256 `565e79d6f757879f04b34c65a9be3d0a27cd7c97b5467b077e8b682030b9f510`. The predecessor bytes, release-repair lineage, validation, and DOC-071 are present. v0.39 HTML and data remain historical evidence, while its current API aliases are retired as neutral non-owners. No missing-release recovery claim is made.

Live public-origin review

On 2026-09-02 in America/Chicago, the operator-directed public review reached `https://concresca.com/status/` and the homepage. The live site identified itself as v0.39.0-wip, exposed honest fail-closed operational blockers, and also contained stale v0.25, v0.28, v0.32, v0.33, and v0.35 current-version markers. Its footer said `Not deployed` despite public reachability. This release records those facts as a partial public-origin observation only. It does not infer package identity, origin-server type, Passenger/cPanel, deployment authorization, database use, or runtime activation.

Deterministic evidence-capsule compiler

The compiler accepts only explicitly supplied, already-inspected regular files outside the public root. It binds source and signer identities as digests, custody and compiler versions, environment, configuration epoch, purpose, scope, audience, operation set, validity interval, hard expiry, correction and remedy, limitations, unresolved dependencies, typed dependency edges, expected public projection, and reproducibility manifest. It rejects private bytes, secret values, addresses, account names, database identities, private paths, participant histories, unknown fields, unsupported schemas, non-NFC values, cycles, duplicate edges, self-reference, stale epochs, expired inputs, revoked sources, revoked signers, invalid corrections, weak modes, links, and special files.

Authorized four-role staging transaction

The MySQL/MariaDB boundary separately models migration target, forced-rollback database, backup source, and restore target. The plan binds four private configuration digests, driver identity, server family, charset, collation, timezone, SQL mode, isolation, transaction support, redacted database identities, advisory lock, exact migration checksums, schema ownership, backup tool identity, restore, semantic reconciliation, non-resurrection, and content-free receipts. Unsafe schema states, role overlap, driver ambiguity, account-level SQL, prohibited fields, fallback storage, expired authorization, crash, cancellation, contention, clock skew, tampered tool identity, and receipt failure all fail closed and release the lock. No external connection or SQL occurred in this release.

Signed append-only activation ledger

A route candidate binds exact authenticated MATM archive custody, license and notice digests, member path and digest, source-line range, callable, methods, canonical owner, upstream suite inventory, dependency lock, result digests, limitations, verified database receipts, staging origin, configuration epoch, public-survival set, previous owner, rollback target, plan, and execution authorization. Preparation and verification cannot change the current owner. Commit and projection are atomic; otherwise compensating rollback restores the previous owner and invalidates candidate receipts. Authenticated MATM source remains absent.

Lifecycle convergence

Infrastructure observations, capsules, receipt graph, database results, semantic restore proof, exceptional authority, and activation ledger converge under configuration and dependency change, key rotation, source correction or revocation, hard expiry, authority renewal, backup and restore, activation and rollback, deletion and tombstone, appeal, remedy, and downstream correction. Invalidation is dependency-scoped. A correction does not invalidate its replacement. One infrastructure layer cannot renew, score, or substitute for another.

Correction, deletion, and non-resurrection

Deletion expectations remain separate across browser, DNS, TLS, proxy/load balancer, WAF, cPanel, Passenger, WSGI, MATM, database logs, crash reporting, traces, host journals, metrics, alerting, backups, snapshots, replicas, exports, disaster recovery, provider access, lawful holds, and incident preservation. Content-free proof paths cover expiry, deletion request, tombstone, backup exclusion, snapshot expiry, replica convergence, restored-state reconciliation, correction, appeal, remedy, hold release, dismantling, and downstream invalidation. No end-to-end deletion claim is made from a local fixture or one layer.

Coercion-resilient interfaces and independent review

Public reading requires no account. Confidential inquiry avoids URL query strings, third-party runtime, tracking, behavioral profiling, default autofill, referer leakage, and identity-linked histories. Age assertion remains separate from identity; guardian involvement is explicit, scoped, jurisdiction-specific, and never assumed safe. Emergency-resource presentation is neutral, user-selected, non-diagnostic, and not a participant record. The workbench supports no-JavaScript completion, keyboard use, visible focus, reflow, forced colors, reduced motion, print privacy, interruption recovery, shared devices, monitored networks, coercive households, unsafe guardians, exile media, and public-interest technology. No independent human review is claimed.

Status and signal integrity

Visible status, machine status, package filenames, route ownership, evidence records, and release lineage must express one boundary. Current v0.40 surfaces use 0.40.0-wip. Historical v0.39 records are explicitly non-current. The release rejects direction controls, non-NFC paths, confusable current identifiers, hidden text, invisible keyword blocks, deceptive metadata, covert encodings, contradictory alternative text, stale current-version selectors, and machine-only status inflation.

Operational gates

Authenticated MATM source is blocked; authorized MySQL/MariaDB is not run; production infrastructure privacy is not observed; Passenger/cPanel is not observed through authorized host inspection; genuine two-agent dogfood is blocked; independent human accessibility review is not run; and public origin reachability is observed while deployed-package identity and cutover authorization remain unverified. Every archive therefore remains explicitly WIP.

Capsule canonicalization invariants

A capsule has one canonical byte representation only when every inspected input, declared dependency, correction edge, expiry, limitation, and public projection is normalized under the same explicit algorithm. The compiler sorts object keys and typed dependency edges, normalizes strings to Unicode NFC, rejects direction-control and invisible-format characters in identifiers, emits UTC timestamps with a fixed representation, rejects non-finite numbers and ambiguous numeric encodings, preserves content digests rather than private content, and excludes filesystem mtimes, process identifiers, locale, hostnames, temporary paths, archive timestamps, random nonces, and nondeterministic iteration order. Recompilation in a clean process must produce the same bytes and SHA-256 digest. A mismatch remains a failed reproducibility result; neither compiler run is silently preferred.

Four-role transaction state machine

The database transaction is represented as an attributable sequence rather than one success flag: inspect four separately supplied private configurations; verify role separation and restricted ownership; verify server and driver declarations; acquire a bounded advisory lock; classify schema state; verify migration digests; rehearse forced rollback in its dedicated role; plan backup with exact tool identity; plan restore to the separate restore role; compare semantic state; test expired, corrected, revoked, and deleted records for non-resurrection; issue content-free receipts; and release the lock on success, refusal, exception, cancellation, or timeout. Local adapters prove ordering and refusal behavior without opening a socket. A future authorized execution must bind actual redacted results to the same transition identifiers and may not reinterpret a local rehearsal as database evidence.

Activation convergence proof obligations

Convergent activation requires more than a route responding. The append-only ledger must bind the candidate source capsule, exact route-owner map, database transaction receipt, infrastructure lifecycle epoch, deletion and correction graph, independent-review state, operator authorization, process activation record, health evidence, rollback point, and public projection. Every observer must either converge on the same committed owner and ledger head or remain on the previous owner. Precommit failure leaves the previous owner untouched. A postcommit fault invokes an attributable rollback entry, restores the previous owner, and invalidates every candidate-derived receipt without deleting history. Split-brain, mixed epochs, missing signatures, stale authorization, ambiguous current pointers, or package-identity uncertainty keep activation blocked.

Independent review intake boundary

The independent-review intake accepts a bounded human-review record without converting the reviewer into an authority over participants. It records review scope, viewport and assistive-technology context, task script, observed barriers, severity as an interface-remediation priority rather than a person score, reproducible steps, evidence location, reviewer independence statement, conflicts, limitations, correction route, remedy owner, due date, retest result, signature metadata, and expiry. It rejects private inquiry bodies, participant identities, behavioral age inference, guardian assumptions, moral language, universal scores, hidden attachments, unsupported claims of certification, and reviews that cannot be corrected or appealed. No independent review was supplied in this release, so the operational gate remains explicit.

Public status interpretation

Public reachability, package byte identity, root-composer liveness, protected runtime readiness, authenticated MATM custody, upstream-suite parity, MySQL or MariaDB verification, infrastructure privacy, Passenger or cPanel configuration, dogfood, outside participation, independent accessibility review, governance, and certification are separate propositions. The live review established only that the canonical public documentation origin answered and identified itself as v0.39.0-wip. It did not establish which ZIP was deployed or whether the response came from the intended origin stack. v0.40 therefore replaces the overloaded phrase `Not deployed` with `Public corpus observed live; coordination runtime not activated`, and retains package identity as unverified until exact archive-to-origin evidence exists.

Correction, appeal, deletion, and remedy

Every current evidence owner exposes an attributable correction route. A correction creates a replacement record and an edge from the superseded record; it does not rewrite prior evidence. Revocation and expiry propagate only through typed dependencies. Deletion creates a tombstone that survives backup and restore comparison without preserving the deleted private body. Appeal records may challenge scope, authority, linkage, timing, or remedy and must remain separate from participant evaluation. Remedy can include withdrawing a claim, correcting a public projection, invalidating downstream receipts, dismantling temporary authority, rotating a credential, restoring a previous route owner, deleting retained material, or documenting that requested relief could not be completed. Public receipts disclose outcomes and limitations without exposing private values.

What v0.40 does not establish

This release does not claim authenticated MATM, upstream suite parity, a database connection, SQL execution, migration, forced rollback, backup, restore, production infrastructure privacy, Passenger/cPanel configuration, package-identical live deployment, genuine separate-agent dogfood, outside adoption, independent accessibility certification, Eviulon ratification, Patefacere adoption, Evulgare certification, legal compliance, or participant standing.

EVIDENCE BOUNDARY

Mechanism, authorization, public reachability, and operational activation remain separate.

Implemented locally

Six executable local control families, current human/machine owners, a live-origin observation, and package validation machinery.

Not supplied or verified

Authenticated source, authorized database, production infrastructure, Passenger/cPanel, genuine dogfood, independent review, and package-identical cutover evidence.

Exact current condition

PASS_LOCAL_WIP_OPERATIONAL_GATES_OPEN

No participant judgment

Participant evaluation effect and standing effect remain NONE.

NO JUDGMENT WHATSOEVER. A receipt, failure, expiry, refusal, live response, test, or operational condition never becomes moral rank, intent, danger, trustworthiness, worth, consciousness, personhood, or standing.