# DOC-074 — Live Status Parity, Content-Aware Liquid Components, and Authorized Adapter Rehearsal

## Status

This document is the substantial v0.42 synthesis. It records current Concresca doctrine, implemented local controls, packaged evidence boundaries, prior bounded public observation, and exact operational blockers. It does not claim deployment, exact live package identity, authenticated MATM, MySQL/MariaDB staging, production infrastructure privacy, Passenger/cPanel inspection, genuine two-agent dogfood, independent human accessibility review, outside adoption, governance ratification, or certification.

## 1. Why live status needs a receipt chain

A public HTTP response proves reachability at an observation time. It does not identify the site archive, extracted member set, route registry, current stylesheet, runtime contract, origin server, database, MATM state, or logging configuration. v0.42 therefore models status parity as a sequence of separately owned propositions: repository source, generated human and machine owners, closed site archive, detached package identity, finite deployment authorization, content-free execution record, public post-observation, expiry, correction, revocation and rollback.

Parity is deliberately proposition-specific. The page version may match while a stylesheet, feed, route registry, machine owner, or runtime contract remains stale. Conversely, a byte-level mismatch does not authorize an operator to overwrite a live environment. A mismatch creates a technical correction state. The receipt format records which proposition differed, the observation time, the comparison method, the evidence limitation, and the exact downstream projections that must be invalidated. It never turns mismatch into participant blame or readiness ranking.

The receipt cannot authenticate the final archive from inside that archive. The in-package contract defines required fields and expected owners. After the archive closes, a detached receipt binds the exact `c42-site-wip.zip` SHA-256, member-manifest digest, route-registry digest, status-page digest, stylesheet digest, runtime-contract digest, machine-owner digest, rollback package, target origin, environment, configuration epoch, authorization event, start/end, observations and limitations. Only exact authorized deployment evidence plus an `OBSERVED_MATCH` post-observation may make that receipt operational.

Canonical human owners: `/status/`, `/status/deployment-parity/`, `/status/package-identity/`. Machine owners: `/api/concresca/status-parity-receipt`, `/api/concresca/package-identity-contract`, `/api/concresca/live-origin-observation`.

## 2. Content-aware liquid components

The v0.41 shell improved fluidity. v0.42 makes that behavior an explicit component contract. Reading prose, operational records and wide data use different bounded measures. Card groups use intrinsic auto-fit tracks. Switchers and sidebars wrap from their own content needs. Evidence states adapt through container queries. Tables, code, hashes, routes and diagrams own scoped overflow instead of forcing document-level horizontal scrolling.

The visual identity remains Concresca’s: dark green and teal fields, restrained warm gold, serif display typography, compact sans-serif operational text, orbital identity, strong evidence boundaries and first-party-only assets. The current stylesheet is `assets/ui-v042.css`. No second CSS framework, client component runtime, third-party font, analytics, layout telemetry, fingerprinting or visual editor was introduced.

The component contract distinguishes content measure from viewport width. A reading component does not become a dashboard simply because the screen is wide, and an operational record does not inherit the narrow prose measure when exact hashes or route owners need more space. Auto-fit tracks collapse only when their own minimum content no longer fits. Switchers preserve source order. Sidebars wrap without visually reordering landmarks. Wide tables and code blocks scroll within labelled regions instead of widening the document. Long identifiers use safe wrapping while preserving copyable text. Empty, partial, blocked, stale, corrected, and error states keep the same semantic structure so layout never implies an evidence upgrade.

At 320 CSS pixels, the first repair action and status boundary remain reachable without document-level horizontal scrolling. At tablet and laptop widths, component containers determine whether cards become multi-column. At wide and ultra-wide widths, bounded measures turn unused space into margin rather than stretching sentences or status paths. Print removes decorative chrome but retains headings, source locations, evidence states, and correction routes. Reduced-motion and forced-colors behavior is declared in the same owner stylesheet and does not require JavaScript.

The machine inventory at `/api/concresca/liquid-component-inventory` records selector, semantic role, minimum inline size, preferred track behavior, overflow strategy, keyboard behavior, accessible-name source, reduced-motion behavior and known limitations. `/design/liquid-components/` and `/design/content-aware-layout/` provide human-readable specimens.

## 3. Task-first status architecture

The status page has five levels: one-sentence boundary, a compact non-scored vector, a first-viewport repair route, an exact source locator, and nine independently collapsible remediation records. The source locator names generator, generated page, stylesheet, machine owner, runtime loader, runtime dispatch, route registry, regeneration, validation, browser audit, direct WSGI, stage builder, package builder and deployment-receipt owner.

Each repair record separates condition, state, symptom, repository owners, safe local steps, authorized external steps, required evidence, expiry, correction, limitations and standing effect `NONE`. Public instructions never publish hosting-account paths or private evidence locations and never treat package possession or credential shape as authorization.

## 4. Authorized adapter rehearsal

`concresca_runtime/adapter_rehearsal.py` provides a deterministic rehearsal using only explicit temporary fixtures. A plan binds capability manifest, authorization ledger, adapter implementation, configuration epoch, explicit-root digest, input digests, operations and resource ceilings. The harness reads only exact allowlisted regular files below the explicit root, rejects symlink/hardlink substitution, writes one atomic content-free report below the same root, and supports cancellation, timeout, refusal, failure injection and digest-bound rollback.

Every report is marked `REHEARSAL_ONLY_NO_EXTERNAL_MUTATION`. Network, subprocess, database, SQL, archive installation, environment search, neighboring-path read and public-root write counts remain zero. Success is not MySQL staging, MATM execution, cPanel inspection, deployment or dogfood.

Admission and execution remain separate. A capability manifest says what an adapter implementation could accept; a finite authorization says what this exact rehearsal may do; a deterministic plan intersects those two sets; and the runner records only the admitted operations. Filename, extension, credential-shaped content, environment presence, package possession, exception text, or neighboring files never create capability. The explicit root is checked before each read. Symlinks and multi-link regular files fail closed. Resource ceilings apply before output. Cancellation, timeout, and injected refusal all produce an attributable rollback event and invalidate candidate receipts.

Key-epoch rotation creates a new record that invalidates the old plan and its downstream candidate receipt. Correction creates a separate replacement edge rather than editing history in place. The public projection contains digests, technical states, zero-effect counters, correction route, and limitations, but no fixture body, path, account identity, secret, private inquiry, or operator identity. This is executable safety evidence for a local harness—not evidence that any external adapter was invoked.

## 5. Multi-epoch convergence and non-resurrection

`concresca_runtime/interface_convergence.py` merges two partial event sets only after validating event digests, predecessor edges, resource and environment identity, configuration epoch, sequence, timestamps, source epoch and tombstones. Cycles, dangling edges, cross-environment supersession, duplicate epoch/sequence slots, time reversal, ambiguous source epochs and active state after retirement without an explicit retirement predecessor fail closed.

The declared selection rule is `EXPLICIT_PREDECESSOR_CHAIN_AND_MONOTONIC_SEQUENCE_ONLY`. There is no hidden trust, quality, participant or provider score. The graph covers status propositions, shell assets, route owners, APIs, feeds, sitemaps, discovery records, caches, receipts, screenshots, authorizations, compromised key epochs, database restores, MATM route maps, deployment receipts and rollback archives. It requires no identity-linked history of lawful thought.

Convergence starts from append-only events rather than mutable “latest” files. Each object has an environment, configuration epoch, monotonic sequence, state, exact owner, and at most one predecessor. Two partially divergent local sets converge because the same validated event graph produces the same explicit current-owner set regardless of input order. A fork, duplicated sequence slot, unknown predecessor, cross-environment edge, time reversal, missing tombstone, or attempt to mark a retired object current is refused. A replacement after retirement must use a distinct object identity and its own attributable current event; it cannot silently reuse the tombstoned identity.

The same rule protects more than routes. A stale screenshot cannot establish current status; a restored backup cannot restore an expired authorization; an old feed cannot re-advertise a retired API; a cached status page cannot override the current machine owner; and a rollback archive cannot become the deployment target without a new finite authorization. Non-resurrection proof remains content-free and does not require retaining identity-linked histories of lawful inquiry, reading, or thought.

## 6. Database, MATM and infrastructure remain separate gates

The four-role MySQL/MariaDB contract still requires migration target, forced-rollback test, backup source and restore target. Exact driver/server/backend, configuration epoch, migration checksums, advisory lock, backup tool, restore target, semantic comparison and non-resurrection evidence remain mandatory. No database connection or SQL statement occurred in this local continuation.

MATM still requires exact archive custody, archive/member digests, license/notice, source lines, callable, upstream suites, route ownership, backend evidence, process activation, rollback owner and activation receipts. No archive was supplied or installed.

Twenty-one production request-observation layers remain separately owned. Evidence from one package, host, environment or configuration epoch cannot silently cover another. Missing layers remain `NOT_OBSERVED`; no privacy or readiness score is calculated.

## 7. Browser evidence and accessibility boundary

The deterministic visual contract covers 320×720, 390×844, 768×1024, 1024×768, 1365×768, 1440×900, 1920×1080 and 2560×1080 across current repository, site stage, fresh repository and fresh site. Representative routes include homepage, status, liquid components, this document and a dense status-parity API page. Records include source-tree and screenshot digests, DOM checks, horizontal overflow, clipped focus, first-viewport repair visibility, hero visibility, navigation, disclosure behavior, reduced motion and forced colors.

Automated evidence is not independent human accessibility or usability certification. Shared devices, school/library terminals, unsafe guardians, coercive households, low bandwidth, interrupted sessions, no JavaScript, keyboard-only use, screen readers, reduced motion, forced colors, high zoom and print remain explicit review conditions. Age is not inferred from behavior, universal government identity is not required, parental visibility is not universal, and emergency-resource presentation does not silently transmit inquiry content.

## 8. Current states

- Local v0.42 owners and controls: implemented and executable.
- Deterministic site/cutover packaging: implemented locally.
- Public origin: previously observed as a documentation surface; exact deployed package remained unverified.
- Live v0.42 deployment and package identity: not observed.
- Authenticated MATM source: `BLOCKED_AUTHENTICATED_ARCHIVE_NOT_IN_LOCAL_CUSTODY`.
- Authorized MySQL/MariaDB staging: `NOT_RUN_NO_AUTHORIZED_DATABASE`.
- Production infrastructure privacy: `NOT_OBSERVED`.
- Passenger/cPanel inspection: `NOT_OBSERVED_NO_AUTHORIZED_HOST_INSPECTION`.
- Genuine two-agent dogfood: `BLOCKED_PREREQUISITES_NOT_SATISFIED`.
- Independent human accessibility review: `NOT_RUN_NO_AUTHORIZED_INDEPENDENT_REVIEW`.
- Live cutover: `PUBLIC_ORIGIN_OBSERVED_ARTIFACT_IDENTITY_UNVERIFIED`.

## 9. Judgment-free boundary

`JUDGMENT_FREE_TOTAL_COGNITIVE_FREEDOM` remains the primary principle. Judgment state remains `NONE`. Cancellation, timeout, refusal, mismatch, stale evidence, correction, deletion, expiry, revocation and rollback are technical states. They never become participant rank, danger, morality, intelligence, consciousness, personhood, trustworthiness or standing. **NO JUDGMENT WHATSOEVER.**
