{
  "audit_date": "2026-08-10",
  "authority": {
    "completion_rule": "ROADMAP.md done annotation plus independently checked durable evidence",
    "manifest_can_authorize_completion": false,
    "policy": "policies/roadmap_execution_v0.1.json",
    "roadmap": "ROADMAP.md",
    "schema": "docs/spec/ROADMAP_EXECUTION_MANIFEST_v0.1.schema.json"
  },
  "input_identities": {
    "policy_sha256": "1e446e626e47893fa3000989748830e4e6d243743929941d7bec4fa83551deae",
    "roadmap_sha256": "443750d8e8724bff62ebd5b71a787cc33f8606a06be529b27fe35f4369292888",
    "schema_sha256": "89c0e0733837cdba5518fece3a6609af0a9ddb05d470a534c0d0baeb202a5b88"
  },
  "kind": "genesis/roadmap-execution-manifest-v0.1",
  "ready_task_ids": [
    "R1.3.f",
    "R1.5.c",
    "R2.1.h",
    "R4.2.e",
    "R4.3.a",
    "R4.4.a",
    "R4.5.a",
    "R5.2.a",
    "R5.4.a",
    "R7.1.a"
  ],
  "summary": {
    "completed_count": 100,
    "open_count": 279,
    "ready_count": 10,
    "task_count": 379
  },
  "tasks": [
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_planning_docs_fresh.sh",
            "scripts/check_doc_topology_drift.sh",
            "scripts/check_capability_evidence_ledger_contract.sh"
          ],
          "completed_date": "2026-07-14",
          "input_identity": "git-commit-object-sha256:1a0d9bdc8d967af45835abeb4391a1601ab6e9e56cc6a16db35882ee198b527e"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "upgrade_plan.md",
          "feature_matrix.md",
          "docs/status",
          "scripts/lib"
        ],
        "prerequisite_task_ids": []
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Add `ROADMAP.md` to repository history, retain its README/index registration, and record the replacement mapping in section 11. Evidence: clean-clone visibility and planning-doc gates.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_planning_docs_fresh.sh",
        "scripts/check_doc_topology_drift.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.1.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject duplicate, missing, reordered, or self-completing roadmap task records"
      ],
      "objective": "Add `ROADMAP.md` to repository history, retain its README/index registration, and record the replacement mapping in section 11. Evidence: clean-clone visibility and planning-doc gates.",
      "owner_paths": [
        "ROADMAP.md",
        "upgrade_plan.md",
        "feature_matrix.md",
        "docs/status",
        "scripts/lib"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [],
      "resource_class": "static",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 804,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Track this roadmap",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_capability_evidence_ledger_contract.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "capability-ledger-bundle-sha256:80123071bac85018252e5aaac1ac9359f3a2c52fe19f79d792f04b02c787a1e7"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "upgrade_plan.md",
          "feature_matrix.md",
          "docs/status",
          "scripts/lib"
        ],
        "prerequisite_task_ids": []
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Convert `feature_matrix.md` to the L0-L5 maturity model, include supported-host scope, and replace \"Known gaps: none\" with generated gaps from the ledger.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_planning_docs_fresh.sh",
        "scripts/check_doc_topology_drift.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.1.b",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject duplicate, missing, reordered, or self-completing roadmap task records"
      ],
      "objective": "Convert `feature_matrix.md` to the L0-L5 maturity model, include supported-host scope, and replace \"Known gaps: none\" with generated gaps from the ledger.",
      "owner_paths": [
        "ROADMAP.md",
        "upgrade_plan.md",
        "feature_matrix.md",
        "docs/status",
        "scripts/lib"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [],
      "resource_class": "static",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 806,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Replace binary feature status",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_capability_evidence_ledger_contract.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "capability-ledger-bundle-sha256:80123071bac85018252e5aaac1ac9359f3a2c52fe19f79d792f04b02c787a1e7"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "upgrade_plan.md",
          "feature_matrix.md",
          "docs/status",
          "scripts/lib"
        ],
        "prerequisite_task_ids": []
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Add a schema and source file mapping each claim to spec, implementation authority, host binding, tests, maturity by platform, owner, and immutable evidence IDs.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_planning_docs_fresh.sh",
        "scripts/check_doc_topology_drift.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.1.c",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject duplicate, missing, reordered, or self-completing roadmap task records"
      ],
      "objective": "Add a schema and source file mapping each claim to spec, implementation authority, host binding, tests, maturity by platform, owner, and immutable evidence IDs.",
      "owner_paths": [
        "ROADMAP.md",
        "upgrade_plan.md",
        "feature_matrix.md",
        "docs/status",
        "scripts/lib"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [],
      "resource_class": "static",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 807,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Create a capability/evidence ledger",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_capability_evidence_ledger_contract.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "status-authority-bundle-sha256:aa3e5341d45b6b5dc69451a9686185efc165d8e818bbad03a46cdf1f41051e0f"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "upgrade_plan.md",
          "feature_matrix.md",
          "docs/status",
          "scripts/lib"
        ],
        "prerequisite_task_ids": []
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Generate `feature_matrix.md`, self-host status, compatibility tables, and release claim tables from the ledger. Drift checks compare generated output without rewriting it.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_planning_docs_fresh.sh",
        "scripts/check_doc_topology_drift.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.1.d",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject duplicate, missing, reordered, or self-completing roadmap task records"
      ],
      "objective": "Generate `feature_matrix.md`, self-host status, compatibility tables, and release claim tables from the ledger. Drift checks compare generated output without rewriting it.",
      "owner_paths": [
        "ROADMAP.md",
        "upgrade_plan.md",
        "feature_matrix.md",
        "docs/status",
        "scripts/lib"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [],
      "resource_class": "static",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 808,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Generate views",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_selfhost_doc_runtime_parity.sh",
            "scripts/check_redteam_report.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "status-authority-bundle-sha256:aa3e5341d45b6b5dc69451a9686185efc165d8e818bbad03a46cdf1f41051e0f"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "upgrade_plan.md",
          "feature_matrix.md",
          "docs/status",
          "scripts/lib"
        ],
        "prerequisite_task_ids": []
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Keep `upgrade_plan.md` as the active red-team defect queue, this file as strategic sequence, and status docs as generated/audited views. Remove contradictory hand-maintained status claims.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_planning_docs_fresh.sh",
        "scripts/check_doc_topology_drift.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.1.e",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject duplicate, missing, reordered, or self-completing roadmap task records"
      ],
      "objective": "Keep `upgrade_plan.md` as the active red-team defect queue, this file as strategic sequence, and status docs as generated/audited views. Remove contradictory hand-maintained status claims.",
      "owner_paths": [
        "ROADMAP.md",
        "upgrade_plan.md",
        "feature_matrix.md",
        "docs/status",
        "scripts/lib"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [],
      "resource_class": "static",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 809,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Reconcile planning docs",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_roadmap_execution_manifest.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "roadmap-execution-contract-bundle-sha256:a5236f26498f58645385d180f8e970c2497e7d413103446b71c632105dcb445e"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "upgrade_plan.md",
          "feature_matrix.md",
          "docs/status",
          "scripts/lib"
        ],
        "prerequisite_task_ids": [
          "R0.1.b",
          "R0.1.c",
          "R0.1.d",
          "R0.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Mirror every roadmap task ID into a versioned manifest with prerequisites, risk class, expected inputs/outputs, owning spec/implementation surfaces, required checks and negative controls, resource class, rollback, and acceptance evidence. A drift check proves one-to-one coverage; the manifest schedules approved work but cannot mark its own task complete or override this roadmap's definition of done.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_planning_docs_fresh.sh",
        "scripts/check_doc_topology_drift.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.1.f",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject duplicate, missing, reordered, or self-completing roadmap task records"
      ],
      "objective": "Mirror every roadmap task ID into a versioned manifest with prerequisites, risk class, expected inputs/outputs, owning spec/implementation surfaces, required checks and negative controls, resource class, rollback, and acceptance evidence. A drift check proves one-to-one coverage; the manifest schedules approved work but cannot mark its own task complete or override this roadmap's definition of done.",
      "owner_paths": [
        "ROADMAP.md",
        "upgrade_plan.md",
        "feature_matrix.md",
        "docs/status",
        "scripts/lib"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.1.b",
        "R0.1.c",
        "R0.1.d",
        "R0.1.e"
      ],
      "resource_class": "static",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 810,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Add a machine-readable execution manifest",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            ".github/workflows/ci.yml",
            ".github/workflows/docs-site.yml",
            "scripts/check_docs_quickstart.sh"
          ],
          "completed_date": "2026-07-14",
          "input_identity": "git-commit-object-sha256:1a0d9bdc8d967af45835abeb4391a1601ab6e9e56cc6a16db35882ee198b527e"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "upgrade_plan.md",
          "feature_matrix.md",
          "docs/status",
          "scripts/lib"
        ],
        "prerequisite_task_ids": []
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Publish each coherent task-scoped checkpoint before the next high-risk tranche, require a clean-clone reconstruction from the published revision, run the complete GitHub CI matrix at least once as a shakedown, classify every remote-only failure, and protect release branches from bypassing required checks. A draft pull request is a valid backup checkpoint but cannot close this task until its exact revision is green remotely.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_planning_docs_fresh.sh",
        "scripts/check_doc_topology_drift.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.1.g",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject duplicate, missing, reordered, or self-completing roadmap task records"
      ],
      "objective": "Publish each coherent task-scoped checkpoint before the next high-risk tranche, require a clean-clone reconstruction from the published revision, run the complete GitHub CI matrix at least once as a shakedown, classify every remote-only failure, and protect release branches from bypassing required checks. A draft pull request is a valid backup checkpoint but cannot close this task until its exact revision is green remotely.",
      "owner_paths": [
        "ROADMAP.md",
        "upgrade_plan.md",
        "feature_matrix.md",
        "docs/status",
        "scripts/lib"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [],
      "resource_class": "static",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 811,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Establish checkpoint and remote-CI discipline",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_capability_evidence_ledger_contract.sh",
            "scripts/check_feature_matrix_gap_hygiene.sh",
            "scripts/check_release_notes.sh",
            "scripts/check_doc_topology_drift.sh"
          ],
          "completed_date": "2026-07-16",
          "input_identity": "capability-ledger-bundle-sha256:80123071bac85018252e5aaac1ac9359f3a2c52fe19f79d792f04b02c787a1e7"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "upgrade_plan.md",
          "feature_matrix.md",
          "docs/status",
          "scripts/lib"
        ],
        "prerequisite_task_ids": [
          "R0.1.b",
          "R0.1.c",
          "R0.1.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Replace broad rows that conflate headless planning, host reachability, archive generation, and real products with independently governed rows for application/UI, static web, interactive/SSR/PWA web, service/data, desktop by OS, iOS, Android, games/media, data/ML, Embedded Linux, MCU language/AOT, board/HAL families, flash/debug/OTA, and hardware-in-the-loop. Each row names exact L0-L5 maturity, host/device scope, authentic artifact predicate, one-language source predicate, owner, gaps, evidence, and release eligibility. Generate a product/target matrix and prohibit aggregate `CAP-DEPLOYMENT-PIPELINE`, `CAP-GRAPHICS-RUNTIME`, or similar L1 wiring from implying child-target support.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_planning_docs_fresh.sh",
        "scripts/check_doc_topology_drift.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.1.h",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject duplicate, missing, reordered, or self-completing roadmap task records"
      ],
      "objective": "Replace broad rows that conflate headless planning, host reachability, archive generation, and real products with independently governed rows for application/UI, static web, interactive/SSR/PWA web, service/data, desktop by OS, iOS, Android, games/media, data/ML, Embedded Linux, MCU language/AOT, board/HAL families, flash/debug/OTA, and hardware-in-the-loop. Each row names exact L0-L5 maturity, host/device scope, authentic artifact predicate, one-language source predicate, owner, gaps, evidence, and release eligibility. Generate a product/target matrix and prohibit aggregate `CAP-DEPLOYMENT-PIPELINE`, `CAP-GRAPHICS-RUNTIME`, or similar L1 wiring from implying child-target support.",
      "owner_paths": [
        "ROADMAP.md",
        "upgrade_plan.md",
        "feature_matrix.md",
        "docs/status",
        "scripts/lib"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.1.b",
        "R0.1.c",
        "R0.1.d"
      ],
      "resource_class": "static",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 813,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Expand the capability ledger to product and target truth",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_check_update_boundary.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "check-update-boundary-audit-sha256:08c0082749a597997094a308f9e1645191353df0f092cf441622db33cce2913b"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/spec",
          "docs/program",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [
          ".genesis/perf"
        ],
        "deliverable": "Audit every `check_*.sh`; a check fails with an exact update command when required material is absent or stale. It never invokes `update_*`, writes `.genesis/perf`, warms caches, or compiles unless compilation is its declared subject.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_check_update_boundary.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.2.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject a check that mutates retained evidence or treats freshly produced material as independent proof"
      ],
      "objective": "Audit every `check_*.sh`; a check fails with an exact update command when required material is absent or stale. It never invokes `update_*`, writes `.genesis/perf`, warms caches, or compiles unless compilation is its declared subject.",
      "owner_paths": [
        "docs/spec",
        "docs/program",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.1.e"
      ],
      "resource_class": "static",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 819,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Separate check from update",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_genesis_evidence_profile.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "genesis-evidence-profile-bundle-sha256:39a8fc5e56371df34bd7a558d4847b8f1ab06402f37eeb9d71bee9d3689e6938"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/spec",
          "docs/program",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.e",
          "R0.2.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Profile in-toto Attestation Framework v1.2 with Statement v1 and a pinned authenticated envelope/bundle representation, plus SLSA 1.2 build/source provenance where its semantics fit; define versioned Genesis predicates for source revision, dirty-state policy, toolchain hashes, environment profile, declared network inputs, commands, negative controls, artifact hashes, raw samples, durations, peak RSS, disk delta, and verifier version.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_check_update_boundary.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.2.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject a check that mutates retained evidence or treats freshly produced material as independent proof"
      ],
      "objective": "Profile in-toto Attestation Framework v1.2 with Statement v1 and a pinned authenticated envelope/bundle representation, plus SLSA 1.2 build/source provenance where its semantics fit; define versioned Genesis predicates for source revision, dirty-state policy, toolchain hashes, environment profile, declared network inputs, commands, negative controls, artifact hashes, raw samples, durations, peak RSS, disk delta, and verifier version.",
      "owner_paths": [
        "docs/spec",
        "docs/program",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.1.e",
        "R0.2.a"
      ],
      "resource_class": "static",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 821,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Version the evidence manifest",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_genesis_evidence_verifier.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "genesis-evidence-verifier-bundle-sha256:6b1806d25003a759574a2ac9475190fd5fd451e0c9cfb4e227749c990cb9766c"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/spec",
          "docs/program",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.e",
          "R0.2.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Build a small read-only verifier for the profiled in-toto/SLSA envelopes, Genesis predicates, hash trees, signatures, compatibility profiles, and negative-control outcomes. Keep it outside the main CLI dependency graph and publish test vectors.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_check_update_boundary.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.2.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject a check that mutates retained evidence or treats freshly produced material as independent proof"
      ],
      "objective": "Build a small read-only verifier for the profiled in-toto/SLSA envelopes, Genesis predicates, hash trees, signatures, compatibility profiles, and negative-control outcomes. Keep it outside the main CLI dependency graph and publish test vectors.",
      "owner_paths": [
        "docs/spec",
        "docs/program",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.1.e",
        "R0.2.b"
      ],
      "resource_class": "static",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 823,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Add an independent verifier",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_evidence_storage_classes.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "evidence-storage-classes-bundle-sha256:c8994da4b2bbf66f1670de7863481b90b146f2b88812555f6d90b29212581fd6"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/spec",
          "docs/program",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.e",
          "R0.2.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Keep E0 observations under ignored `.genesis/`; keep E1/E2 schemas and goldens in-tree; publish E3/E4 bundles as immutable release assets with mirror instructions.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_check_update_boundary.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.2.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject a check that mutates retained evidence or treats freshly produced material as independent proof"
      ],
      "objective": "Keep E0 observations under ignored `.genesis/`; keep E1/E2 schemas and goldens in-tree; publish E3/E4 bundles as immutable release assets with mirror instructions.",
      "owner_paths": [
        "docs/spec",
        "docs/program",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.1.e",
        "R0.2.c"
      ],
      "resource_class": "static",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 825,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Establish evidence storage classes",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_evidence_adversarial_matrix.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "evidence-adversarial-matrix-bundle-sha256:80aa2c163a1364ef039c6c89145e4c52a280ce8bcea411fef95676696120a435"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/spec",
          "docs/program",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.e",
          "R0.2.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Reject missing fields, duplicate keys, path aliases, unsupported schema versions, reordered/altered replay facts, forged signatures, stale source identities, and reports produced from dirty inputs without an explicit dirty policy.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_check_update_boundary.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.2.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject a check that mutates retained evidence or treats freshly produced material as independent proof"
      ],
      "objective": "Reject missing fields, duplicate keys, path aliases, unsupported schema versions, reordered/altered replay facts, forged signatures, stale source identities, and reports produced from dirty inputs without an explicit dirty policy.",
      "owner_paths": [
        "docs/spec",
        "docs/program",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.1.e",
        "R0.2.d"
      ],
      "resource_class": "static",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 827,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Add adversarial fixtures",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_evidence_adversarial_matrix.sh"
          ],
          "completed_date": "2026-07-14",
          "input_identity": "evidence-adversarial-matrix-bundle-sha256:80aa2c163a1364ef039c6c89145e4c52a280ce8bcea411fef95676696120a435"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/spec",
          "docs/program",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.e",
          "R0.2.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Make denied capability decisions produce the same value/error boundary, exit contract, canonical log facts, and replay outcome across Rust and self-host engines on native and WASI. Add one shared regression corpus for allow, deny, unhandled, malformed, and tampered entries; compare every serialized fact including decision and capability; fail closed on any engine disagreement.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_check_update_boundary.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.2.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject a check that mutates retained evidence or treats freshly produced material as independent proof"
      ],
      "objective": "Make denied capability decisions produce the same value/error boundary, exit contract, canonical log facts, and replay outcome across Rust and self-host engines on native and WASI. Add one shared regression corpus for allow, deny, unhandled, malformed, and tampered entries; compare every serialized fact including decision and capability; fail closed on any engine disagreement.",
      "owner_paths": [
        "docs/spec",
        "docs/program",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.1.e",
        "R0.2.e"
      ],
      "resource_class": "static",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 829,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Restore denied-effect replay parity",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_test_execution_profile_matrix.sh",
            "scripts/check_host_bridge_fault_injection.sh",
            "scripts/check_gc_agent_task_cards.sh"
          ],
          "completed_date": "2026-07-14",
          "input_identity": "test-hermeticity-bundle-sha256:1a3d7b76a95c2205ad7e71476ecab4842f7a74a1c6d1d6b701e0b978994eb279"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/spec",
          "docs/program",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.e",
          "R0.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Remove aggregate-pipeline recursion from default Rust tests; place process-kill loops, performance probes, and dirty-tree stress in declared isolated lanes. Replace PID-log timing assumptions with explicit fixture readiness/ownership handshakes, prove descendant kill/reap deterministically, and run the affected host-bridge and agent-plan tests repeatedly under supported parallel CPU/I/O load. No closure through `ignore`, retry-until-green, reduced assertions, or serialized global execution unless the contract itself requires serialization.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_check_update_boundary.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.2.g",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject a check that mutates retained evidence or treats freshly produced material as independent proof"
      ],
      "objective": "Remove aggregate-pipeline recursion from default Rust tests; place process-kill loops, performance probes, and dirty-tree stress in declared isolated lanes. Replace PID-log timing assumptions with explicit fixture readiness/ownership handshakes, prove descendant kill/reap deterministically, and run the affected host-bridge and agent-plan tests repeatedly under supported parallel CPU/I/O load. No closure through `ignore`, retry-until-green, reduced assertions, or serialized global execution unless the contract itself requires serialization.",
      "owner_paths": [
        "docs/spec",
        "docs/program",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.1.e",
        "R0.2.f"
      ],
      "resource_class": "static",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 831,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Make test profiles hermetic and load-stable",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo clippy --workspace --all-targets --locked --offline -- -D warnings",
            "scripts/check_runtime_backend_feature_matrix.sh",
            "scripts/check_test_execution_profile_matrix.sh"
          ],
          "completed_date": "2026-07-14",
          "input_identity": "warning-free-workspace-bundle-sha256:5e0aaf06c95bfa2b7a600e6bc1040f2eb52873f338212a962fa5faab7b109567"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/spec",
          "docs/program",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.e",
          "R0.2.g"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Run format plus Clippy with warnings denied for all workspace targets and supported feature profiles, including MCP, warm, WASI, build scripts, tests, examples, and generated Rust. Remove the current warnings at their cause; any lint suppression must be narrow, justified, reviewed, and covered by a negative control that prevents module-level or workspace-wide suppression.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_check_update_boundary.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "R0.2.h",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject a check that mutates retained evidence or treats freshly produced material as independent proof"
      ],
      "objective": "Run format plus Clippy with warnings denied for all workspace targets and supported feature profiles, including MCP, warm, WASI, build scripts, tests, examples, and generated Rust. Remove the current warnings at their cause; any lint suppression must be narrow, justified, reviewed, and covered by a negative control that prevents module-level or workspace-wide suppression.",
      "owner_paths": [
        "docs/spec",
        "docs/program",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.1.e",
        "R0.2.g"
      ],
      "resource_class": "static",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 833,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Enforce a warning-free workspace",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_root_lock_policy.sh",
            "parser=posix-awk",
            "scripts/check_green_front_door.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "root-lock-policy-bundle-sha256:da5bce85a48b6e89b160c9ea720356f00ba3a63384978a6cc08d26d0c9cdc059"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [
          "scripts/check_root_lock_policy.sh"
        ],
        "deliverable": "Remove the undeclared Python 3.11 `tomllib` assumption from `scripts/check_root_lock_policy.sh`; use a Rust helper, a POSIX-safe parser for the required subset, or a checked fallback that works with the declared minimum Python.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_root_lock_policy.sh",
        "scripts/check_versioning_release_hygiene.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R0.3.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject undeclared tools, network inputs, rebuild islands, and benchmark environments"
      ],
      "objective": "Remove the undeclared Python 3.11 `tomllib` assumption from `scripts/check_root_lock_policy.sh`; use a Rust helper, a POSIX-safe parser for the required subset, or a checked fallback that works with the declared minimum Python.",
      "owner_paths": [
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.1.e"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 838,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Fix the root-lock check",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.3"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_prerequisite_manifest.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "prerequisite-manifest-bundle-sha256:b9a97b7316632f958bf2e0d6967e4bb8359caf977c53fe5d0934e7b5a45c3aaa"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.e",
          "R0.3.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Pin Rust, WASI/WebAssembly tools, Lean, shell/Python minimums, platform SDK expectations, and optional feature tools. Add a command that reports missing or mismatched prerequisites without mutating the host.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_root_lock_policy.sh",
        "scripts/check_versioning_release_hygiene.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R0.3.b",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject undeclared tools, network inputs, rebuild islands, and benchmark environments"
      ],
      "objective": "Pin Rust, WASI/WebAssembly tools, Lean, shell/Python minimums, platform SDK expectations, and optional feature tools. Add a command that reports missing or mismatched prerequisites without mutating the host.",
      "owner_paths": [
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.1.e",
        "R0.3.a"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 839,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Declare one prerequisite manifest",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.3"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_dependency_mirror_contract.sh",
            "scripts/test_offline_dependency_mirror.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "dependency-mirror-bundle-sha256:5607324af26cbec4bf4b998b9cf1de64ec146e86fbfaa8b01590237f4dbef6c2"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.e",
          "R0.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "A fresh clone may fetch declared dependencies once; the offline profile then builds/checks from a content-addressed dependency mirror. Undeclared network access fails.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_root_lock_policy.sh",
        "scripts/check_versioning_release_hygiene.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R0.3.c",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject undeclared tools, network inputs, rebuild islands, and benchmark environments"
      ],
      "objective": "A fresh clone may fetch declared dependencies once; the offline profile then builds/checks from a content-addressed dependency mirror. Undeclared network access fails.",
      "owner_paths": [
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.1.e",
        "R0.3.b"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 841,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Verify clean and offline modes",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.3"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_version_surfaces.sh",
            "scripts/check_versioning_release_hygiene.sh",
            "scripts/check_release_smoke.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "version-surface-bundle-sha256:11f2b7ba680dbff18c2af291f1c6e5787a885252b7ff8c3be888730180bf0ee0"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.e",
          "R0.3.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Reconcile crate versions, CLI output, package schema, GCLOG writer/parser/spec, canonical hash profile, compiled artifact magic, docs, and release metadata. Add migration notes for every dual-read format.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_root_lock_policy.sh",
        "scripts/check_versioning_release_hygiene.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R0.3.d",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject undeclared tools, network inputs, rebuild islands, and benchmark environments"
      ],
      "objective": "Reconcile crate versions, CLI output, package schema, GCLOG writer/parser/spec, canonical hash profile, compiled artifact magic, docs, and release metadata. Add migration notes for every dual-read format.",
      "owner_paths": [
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.1.e",
        "R0.3.c"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 843,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Align version surfaces",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.3"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_v1_compatibility.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "v1-compatibility-registry-bundle-sha256:7ba9eecb5b3b0173c8ce5840362db4fe5ddb0ad254e2e9f45ebfe85b072c5341"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.e",
          "R0.3.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Reserve stable IDs for language profile, CoreForm, value/effect hash, log, evidence, package, patch, bytecode, snapshot, and bootstrap formats.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_root_lock_policy.sh",
        "scripts/check_versioning_release_hygiene.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R0.3.e",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject undeclared tools, network inputs, rebuild islands, and benchmark environments"
      ],
      "objective": "Reserve stable IDs for language profile, CoreForm, value/effect hash, log, evidence, package, patch, bytecode, snapshot, and bootstrap formats.",
      "owner_paths": [
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.1.e",
        "R0.3.d"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 845,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Create the v1 compatibility registry",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.3"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_gate_manifest.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "gate-manifest-bundle-sha256:36c86b517b6c8dc95ad30c7b411f57b32cca14a1e1553177629206688e31b421"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "docs/program",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.a",
          "R0.3.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Describe gate inputs, outputs, dependencies, profile, expected duration, disk budget, network policy, platform scope, sharding, and whether the gate is static, build, test, benchmark, proof, or release-only.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gate_resource_telemetry.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_test_execution_profile_matrix.sh",
        "scripts/check_roadmap_execution_manifest.sh"
      ],
      "id": "R0.4.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject self-generated evidence, unbounded nested execution, hidden cache-class changes, incomplete lifecycle cleanup, and watchdogs that omit a claimed profile"
      ],
      "objective": "Describe gate inputs, outputs, dependencies, profile, expected duration, disk budget, network policy, platform scope, sharding, and whether the gate is static, build, test, benchmark, proof, or release-only.",
      "owner_paths": [
        ".github",
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "docs/program",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.2.a",
        "R0.3.a"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 850,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Add a gate manifest",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_cargo_target_dir_policy.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "cargo-cache-bundle-sha256:d90b64cd3ad821d40098d44c823bb93be23d7dca2b0a09278d0f061a5f1ce2e5"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "docs/program",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.a",
          "R0.3.a",
          "R0.4.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Use one declared Cargo target/cache strategy per profile; stop scripts from creating redundant nested targets; key caches by toolchain/features/input hashes.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gate_resource_telemetry.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_test_execution_profile_matrix.sh",
        "scripts/check_roadmap_execution_manifest.sh"
      ],
      "id": "R0.4.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject self-generated evidence, unbounded nested execution, hidden cache-class changes, incomplete lifecycle cleanup, and watchdogs that omit a claimed profile"
      ],
      "objective": "Use one declared Cargo target/cache strategy per profile; stop scripts from creating redundant nested targets; key caches by toolchain/features/input hashes.",
      "owner_paths": [
        ".github",
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "docs/program",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.2.a",
        "R0.3.a",
        "R0.4.a"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 852,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Eliminate accidental rebuild islands",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_changed_impact.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "changed-impact-bundle-sha256:a56286c16c783aba0efafe5ffad9faaea02af8a6b90e671882620fc1536511f2"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "docs/program",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.a",
          "R0.3.a",
          "R0.4.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Map files and generated schemas to affected crates/gates, conservatively falling back to broader profiles when dependency certainty is incomplete.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gate_resource_telemetry.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_test_execution_profile_matrix.sh",
        "scripts/check_roadmap_execution_manifest.sh"
      ],
      "id": "R0.4.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject self-generated evidence, unbounded nested execution, hidden cache-class changes, incomplete lifecycle cleanup, and watchdogs that omit a claimed profile"
      ],
      "objective": "Map files and generated schemas to affected crates/gates, conservatively falling back to broader profiles when dependency certainty is incomplete.",
      "owner_paths": [
        ".github",
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "docs/program",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.2.a",
        "R0.3.a",
        "R0.4.b"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 854,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Implement changed-impact selection",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_gate_resource_telemetry.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "gate-resource-telemetry-bundle-sha256:0232e719e9a216ad988b4b3a5db934c6139b1ee51974a0ecf249ea1a9c1d988d"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "docs/program",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.a",
          "R0.3.a",
          "R0.4.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Every gate emits duration, peak RSS, bytes read/written, generated disk delta, cache hits, and network attempts in a common schema.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gate_resource_telemetry.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_test_execution_profile_matrix.sh",
        "scripts/check_roadmap_execution_manifest.sh"
      ],
      "id": "R0.4.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject self-generated evidence, unbounded nested execution, hidden cache-class changes, incomplete lifecycle cleanup, and watchdogs that omit a claimed profile"
      ],
      "objective": "Every gate emits duration, peak RSS, bytes read/written, generated disk delta, cache hits, and network attempts in a common schema.",
      "owner_paths": [
        ".github",
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "docs/program",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.2.a",
        "R0.3.a",
        "R0.4.c"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 856,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Add resource telemetry",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_deterministic_cleanup.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "deterministic-cleanup-bundle-sha256:c82b4c9554c1ec87b2a89fc07b80dd5e01bdaf8b7aa09a0ce9763c437d2ff6c5"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "docs/program",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.a",
          "R0.3.a",
          "R0.4.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Provide dry-run and execute modes that classify rebuildable outputs, retained evidence, dependency mirrors, and user-authored data. Never delete untracked user files by pattern alone.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gate_resource_telemetry.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_test_execution_profile_matrix.sh",
        "scripts/check_roadmap_execution_manifest.sh"
      ],
      "id": "R0.4.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject self-generated evidence, unbounded nested execution, hidden cache-class changes, incomplete lifecycle cleanup, and watchdogs that omit a claimed profile"
      ],
      "objective": "Provide dry-run and execute modes that classify rebuildable outputs, retained evidence, dependency mirrors, and user-authored data. Never delete untracked user files by pattern alone.",
      "owner_paths": [
        ".github",
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "docs/program",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.2.a",
        "R0.3.a",
        "R0.4.d"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 858,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Add deterministic cleanup",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_engineering_gate_contract.sh",
            "scripts/check_upgrade_plan_health.sh --profile prepush-standard",
            "scripts/check_gate_resource_telemetry.sh",
            "scripts/check_cargo_target_dir_policy.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "engineering-gate-budget-bundle-sha256:43d9f7c0bd2d3609525eeda6154d67134aaaecf44f6d73dbc73f9acc09e5246e"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "docs/program",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.a",
          "R0.3.a",
          "R0.4.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Split or redesign gates that exceed budgets. The no-panic/TCB policy check must not require a multi-minute cold build merely to scan source policy.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gate_resource_telemetry.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_test_execution_profile_matrix.sh",
        "scripts/check_roadmap_execution_manifest.sh"
      ],
      "id": "R0.4.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject self-generated evidence, unbounded nested execution, hidden cache-class changes, incomplete lifecycle cleanup, and watchdogs that omit a claimed profile"
      ],
      "objective": "Split or redesign gates that exceed budgets. The no-panic/TCB policy check must not require a multi-minute cold build merely to scan source policy.",
      "owner_paths": [
        ".github",
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "docs/program",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.2.a",
        "R0.3.a",
        "R0.4.e"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 860,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Enforce GB-1 through GB-8",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_deterministic_cleanup.sh",
            "scripts/check_cargo_target_dir_policy.sh",
            "scripts/check_default_iteration_workflow.sh"
          ],
          "completed_date": "2026-07-14",
          "input_identity": "generated-state-lifecycle-bundle-sha256:54f5e2baddd3b6b5be4932d3b7ed9b97badc651c6e260eb2bdbbc3603486e658"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "docs/program",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.a",
          "R0.3.a",
          "R0.4.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Apply GB-5 continuously, not only when a human remembers cleanup: every producer declares owner, content key, last-use/lease, size class, retention class, and safe reclamation order. Enforce configurable soft/hard quotas with concurrency-safe admission and garbage collection; refuse new rebuildable growth before crossing the hard limit; preserve user-authored data, retained evidence, dependency mirrors, active leases, and rollback quarantine. Prove dry-run/execute parity, crash recovery, concurrent builders, low-disk behavior, and steady state across repeated full profiles.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gate_resource_telemetry.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_test_execution_profile_matrix.sh",
        "scripts/check_roadmap_execution_manifest.sh"
      ],
      "id": "R0.4.g",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject self-generated evidence, unbounded nested execution, hidden cache-class changes, incomplete lifecycle cleanup, and watchdogs that omit a claimed profile"
      ],
      "objective": "Apply GB-5 continuously, not only when a human remembers cleanup: every producer declares owner, content key, last-use/lease, size class, retention class, and safe reclamation order. Enforce configurable soft/hard quotas with concurrency-safe admission and garbage collection; refuse new rebuildable growth before crossing the hard limit; preserve user-authored data, retained evidence, dependency mirrors, active leases, and rollback quarantine. Prove dry-run/execute parity, crash recovery, concurrent builders, low-disk behavior, and steady state across repeated full profiles.",
      "owner_paths": [
        ".github",
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "docs/program",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.2.a",
        "R0.3.a",
        "R0.4.f"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 862,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Enforce bounded generated-state caches",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_gate_manifest.sh",
            "scripts/check_check_update_boundary.sh"
          ],
          "completed_date": "2026-07-14",
          "input_identity": "governance-consolidation-bundle-sha256:b4c23a101399afd34899b06e21b1e7b4ac11580a347153e6411951075b985a21"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "docs/program",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.a",
          "R0.3.a",
          "R0.4.g"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Until M1, use a one-in/one-out budget for governed check entrypoints and prefer extending existing schemas, manifests, matrices, and shared libraries. Remove duplicate wrappers/update scripts, collapse checks with the same authority and resource envelope, and publish the before/after inventory plus saved default/CI time and disk. A new entrypoint requires a distinct trust boundary and cannot be justified by documentation convenience alone.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gate_resource_telemetry.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_test_execution_profile_matrix.sh",
        "scripts/check_roadmap_execution_manifest.sh"
      ],
      "id": "R0.4.h",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject self-generated evidence, unbounded nested execution, hidden cache-class changes, incomplete lifecycle cleanup, and watchdogs that omit a claimed profile"
      ],
      "objective": "Until M1, use a one-in/one-out budget for governed check entrypoints and prefer extending existing schemas, manifests, matrices, and shared libraries. Remove duplicate wrappers/update scripts, collapse checks with the same authority and resource envelope, and publish the before/after inventory plus saved default/CI time and disk. A new entrypoint requires a distinct trust boundary and cannot be justified by documentation convenience alone.",
      "owner_paths": [
        ".github",
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "docs/program",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.2.a",
        "R0.3.a",
        "R0.4.g"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 864,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Consolidate governance machinery before adding more",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_generated_artifact_policy.sh",
            "scripts/check_check_update_boundary.sh",
            "scripts/check_gate_manifest.sh"
          ],
          "completed_date": "2026-07-16",
          "input_identity": "generated-authority-closure-bundle-sha256:cf2d7548dcfca38f3085bd9ac42376723b20684176a42233c4623a26cdc043fa"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "docs/program",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.a",
          "R0.3.a",
          "R0.4.h"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Replace the current operator-remembered updater sequence with one canonical, schema-driven dependency graph from authoritative inputs through every generated source, manifest, card, release note, evidence identity, site index, and publication view. Reuse the gate manifest and check/update audit as discovery authorities rather than maintaining a contradictory second inventory; require exactly one owner per output, declared read and write sets, acyclic topological order, bounded resources, and explicit edges for self-excluding fixed-point identities. The updater stages the complete closure outside authoritative paths, validates every read-only check against the staged result, then promotes all outputs atomically or leaves the repository byte-identical; it never signs, attests, rewrites retained E3/E4 evidence, or upgrades claims. A second update is byte-identical and leaves a clean tree. Changed-impact and `prepush-standard` run the complete read-only freshness closure for affected canonical inputs before publication. Negative controls mutate at least `Cargo.lock`, CLI schema, roadmap task/evidence text, diagnostic/profile authorities, and GenesisBench authorities, proving that release notes, version surfaces, authoring bundles, gate and roadmap manifests, reference/site indexes, and every other transitive dependent either regenerate in one invocation or fail closed. Satisfy R0.4.h by extending/replacing an existing canonical updater and retiring at least one redundant entrypoint rather than adding another permanent wrapper.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gate_resource_telemetry.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_test_execution_profile_matrix.sh",
        "scripts/check_roadmap_execution_manifest.sh"
      ],
      "id": "R0.4.i",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject self-generated evidence, unbounded nested execution, hidden cache-class changes, incomplete lifecycle cleanup, and watchdogs that omit a claimed profile"
      ],
      "objective": "Replace the current operator-remembered updater sequence with one canonical, schema-driven dependency graph from authoritative inputs through every generated source, manifest, card, release note, evidence identity, site index, and publication view. Reuse the gate manifest and check/update audit as discovery authorities rather than maintaining a contradictory second inventory; require exactly one owner per output, declared read and write sets, acyclic topological order, bounded resources, and explicit edges for self-excluding fixed-point identities. The updater stages the complete closure outside authoritative paths, validates every read-only check against the staged result, then promotes all outputs atomically or leaves the repository byte-identical; it never signs, attests, rewrites retained E3/E4 evidence, or upgrades claims. A second update is byte-identical and leaves a clean tree. Changed-impact and `prepush-standard` run the complete read-only freshness closure for affected canonical inputs before publication. Negative controls mutate at least `Cargo.lock`, CLI schema, roadmap task/evidence text, diagnostic/profile authorities, and GenesisBench authorities, proving that release notes, version surfaces, authoring bundles, gate and roadmap manifests, reference/site indexes, and every other transitive dependent either regenerate in one invocation or fail closed. Satisfy R0.4.h by extending/replacing an existing canonical updater and retiring at least one redundant entrypoint rather than adding another permanent wrapper.",
      "owner_paths": [
        ".github",
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "docs/program",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.2.a",
        "R0.3.a",
        "R0.4.h"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 866,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Make generated-authority closure atomic",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_generated_artifact_policy.sh",
            "scripts/check_check_update_boundary.sh",
            "scripts/check_gate_manifest.sh",
            "scripts/check_roadmap_execution_manifest.sh",
            "30826800834"
          ],
          "completed_date": "2026-08-03",
          "input_identity": "generated-authority-closure-bundle-sha256:cf2d7548dcfca38f3085bd9ac42376723b20684176a42233c4623a26cdc043fa"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "docs/program",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.a",
          "R0.3.a",
          "R0.4.i"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [
          "crates/gc_cli/tests/cli_genesisbench_front_door.rs"
        ],
        "deliverable": "This M0/M1-A/M1-B publication blocker refines R0.4.i after the round-five counterexample; it adds no check or updater entrypoint and consumes the existing generated-authority hardening allocation. Extend the canonical graph so every governed gate's recursively discovered implementation/input identity, including Rust integration tests and non-shell helpers reached by an aggregate authority, is either a declared graph input with complete reverse edges or an explicit fixed-point exclusion with an independently checked justification. A change to `crates/gc_cli/tests/cli_genesisbench_front_door.rs` must route through the GenesisBench protocol/profile closure, agent corpus/bundle, gate manifest, roadmap manifest, and reference/site indexes in one transaction; `generated_authority.py --check`, changed-impact, and hosted CI must fail before any partial publication. Add dependency-completeness controls that mutate one Rust test, one transitive Python import, one gate helper, one generated bundle input, and one fixed-point exclusion; compare graph discovery against the gate manifest and check/update audit; reject unowned reads, stale execution/input identities, and a graph that reports fresh while any governed check fails only for freshness. Extend the existing roadmap-manifest controls to reject a scalar prerequisite on a non-sequential workstream unless it expands to every required leaf; cover parallel proof, archetype, benchmark, and model-lane counterexamples. The updater must remain atomic, read-only checks must remain non-mutating, a second update must be byte-identical, and no retained E3/E4 evidence may be rewritten. Completion requires the current stale GenesisBench/gate identities to be repaired, the exact counterexample to pass locally and in protected CI, and PR publication to `main` without bypassing required checks.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gate_resource_telemetry.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_test_execution_profile_matrix.sh",
        "scripts/check_roadmap_execution_manifest.sh"
      ],
      "id": "R0.4.k",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject self-generated evidence, unbounded nested execution, hidden cache-class changes, incomplete lifecycle cleanup, and watchdogs that omit a claimed profile"
      ],
      "objective": "This M0/M1-A/M1-B publication blocker refines R0.4.i after the round-five counterexample; it adds no check or updater entrypoint and consumes the existing generated-authority hardening allocation. Extend the canonical graph so every governed gate's recursively discovered implementation/input identity, including Rust integration tests and non-shell helpers reached by an aggregate authority, is either a declared graph input with complete reverse edges or an explicit fixed-point exclusion with an independently checked justification. A change to `crates/gc_cli/tests/cli_genesisbench_front_door.rs` must route through the GenesisBench protocol/profile closure, agent corpus/bundle, gate manifest, roadmap manifest, and reference/site indexes in one transaction; `generated_authority.py --check`, changed-impact, and hosted CI must fail before any partial publication. Add dependency-completeness controls that mutate one Rust test, one transitive Python import, one gate helper, one generated bundle input, and one fixed-point exclusion; compare graph discovery against the gate manifest and check/update audit; reject unowned reads, stale execution/input identities, and a graph that reports fresh while any governed check fails only for freshness. Extend the existing roadmap-manifest controls to reject a scalar prerequisite on a non-sequential workstream unless it expands to every required leaf; cover parallel proof, archetype, benchmark, and model-lane counterexamples. The updater must remain atomic, read-only checks must remain non-mutating, a second update must be byte-identical, and no retained E3/E4 evidence may be rewritten. Completion requires the current stale GenesisBench/gate identities to be repaired, the exact counterexample to pass locally and in protected CI, and PR publication to `main` without bypassing required checks.",
      "owner_paths": [
        ".github",
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "docs/program",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.2.a",
        "R0.3.a",
        "R0.4.i"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 868,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Close transitive gate-input authority and prove no partial freshness",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "31284542152",
            "31284543591",
            "31287266902",
            "scripts/check_gate_resource_telemetry.sh",
            "scripts/check_generated_artifact_policy.sh",
            "scripts/check_test_execution_profile_matrix.sh"
          ],
          "completed_date": "2026-08-10",
          "input_identity": "ci-release-dag-aggregate-sha256:6c5c4e3da4ce4ee04fd744caaa7d088746aa814463061021d702a8a4244733b9"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "docs/program",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.a",
          "R0.3.a",
          "R0.4.k"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [
          ".genesis/perf"
        ],
        "deliverable": "This is an M0/M1-A/M1-B critical-path refinement of R0.4.f, not a new release or platform scope. Give the serialized release evidence bundle one closed manifest whose report identities, semantic inputs, runtime/toolchain identities, and freshness are validated by every direct and nested consumer; source-decomposition and other aggregate checks may reuse a report only when the invoked gate, complete inputs, environment profile, and required evidence class match exactly, otherwise they rerun. Eliminate repeated native/WASI gauntlets, backend matrices, and other proven duplicate work without replacing execution with stale `.genesis/perf` state or weakening parity. Provision and document a named reference CI shard set with real iOS simulator, Android emulator, edge runtime, and service/container commands; bind each command, runtime class, SDK/image/device identity, artifact hash, logs, and lifecycle result. Until R6.3.f/R6.6 make the emitted packages genuinely installable and executable, strict target qualification must stop at a typed `unsupported-product`/readiness blocker and may not call a synthetic launcher non-synthetic; infrastructure/configuration failures remain distinct hard failures. Make the CI control plane fail boundedly: PR-only supersession may cancel an older run for the same PR, but default-branch pushes, schedules, and dispatches cannot silently replace one another; a hosted preflight binds exact self-hosted runner labels and prevents impossible 24-hour queues; unavailable optional pack runners produce typed non-claiming dispositions while unavailable runners required by a claimed profile fail; and a disjoint watchdog enforces latest-`main` standard disposition within two hours, full-run termination within sixty minutes, and successful full freshness within forty-eight hours. Replace the impossible v0.1 serial cold/warm pair with a closed v0.2 release-evidence DAG: execute exact-revision invariant nodes once with manifest-bound same-run fan-out, run independently matched odd cohorts of at least three cold and three deterministically prewarmed cache-sensitive workers plus separately declared odd stress/performance cohorts, and have one read-only aggregate reject missing or undeclared duplicate execution, cross-class reuse, forged cache state, overlapping exclusive lanes, identity drift, incomplete cleanup, or any failed node. Completion requires P1.7's aggregate resource owner and complete R0.4.i/R0.4.k guard rerun, every DAG node on exact reviewed `main` to pass within its unchanged <=45-minute/<=20-GiB worker bound, the complete workflow and five-minute aggregate to terminate successfully within sixty minutes, named target dispositions and append-only incident evidence to verify, and the disjoint watchdog to recognize a successful exact-main standard disposition plus successful full evidence no older than forty-eight hours.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gate_resource_telemetry.sh",
        "scripts/check_generated_artifact_policy.sh",
        "scripts/check_test_execution_profile_matrix.sh",
        "scripts/check_roadmap_execution_manifest.sh"
      ],
      "id": "R0.4.j",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject self-generated evidence, unbounded nested execution, hidden cache-class changes, incomplete lifecycle cleanup, and watchdogs that omit a claimed profile"
      ],
      "objective": "This is an M0/M1-A/M1-B critical-path refinement of R0.4.f, not a new release or platform scope. Give the serialized release evidence bundle one closed manifest whose report identities, semantic inputs, runtime/toolchain identities, and freshness are validated by every direct and nested consumer; source-decomposition and other aggregate checks may reuse a report only when the invoked gate, complete inputs, environment profile, and required evidence class match exactly, otherwise they rerun. Eliminate repeated native/WASI gauntlets, backend matrices, and other proven duplicate work without replacing execution with stale `.genesis/perf` state or weakening parity. Provision and document a named reference CI shard set with real iOS simulator, Android emulator, edge runtime, and service/container commands; bind each command, runtime class, SDK/image/device identity, artifact hash, logs, and lifecycle result. Until R6.3.f/R6.6 make the emitted packages genuinely installable and executable, strict target qualification must stop at a typed `unsupported-product`/readiness blocker and may not call a synthetic launcher non-synthetic; infrastructure/configuration failures remain distinct hard failures. Make the CI control plane fail boundedly: PR-only supersession may cancel an older run for the same PR, but default-branch pushes, schedules, and dispatches cannot silently replace one another; a hosted preflight binds exact self-hosted runner labels and prevents impossible 24-hour queues; unavailable optional pack runners produce typed non-claiming dispositions while unavailable runners required by a claimed profile fail; and a disjoint watchdog enforces latest-`main` standard disposition within two hours, full-run termination within sixty minutes, and successful full freshness within forty-eight hours. Replace the impossible v0.1 serial cold/warm pair with a closed v0.2 release-evidence DAG: execute exact-revision invariant nodes once with manifest-bound same-run fan-out, run independently matched odd cohorts of at least three cold and three deterministically prewarmed cache-sensitive workers plus separately declared odd stress/performance cohorts, and have one read-only aggregate reject missing or undeclared duplicate execution, cross-class reuse, forged cache state, overlapping exclusive lanes, identity drift, incomplete cleanup, or any failed node. Completion requires P1.7's aggregate resource owner and complete R0.4.i/R0.4.k guard rerun, every DAG node on exact reviewed `main` to pass within its unchanged <=45-minute/<=20-GiB worker bound, the complete workflow and five-minute aggregate to terminate successfully within sixty minutes, named target dispositions and append-only incident evidence to verify, and the disjoint watchdog to recognize a successful exact-main standard disposition plus successful full evidence no older than forty-eight hours.",
      "owner_paths": [
        ".github",
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "docs/program",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.2.a",
        "R0.3.a",
        "R0.4.k"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 870,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Restore an authentic, hermetic release-full profile within GB-4",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_reference_host_profiles.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "reference-host-profile-bundle-sha256:41b7156b78e63cf10d3462d7a1618ae84c1827af7b4480469b3bd0fa9556a9d9"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.3.b",
          "R0.4.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Record tier-1 macOS arm64 and Linux x86_64; add Linux arm64 and Windows x86_64 as tier-2 until promoted. Include CPU, memory, filesystem, OS, compiler, and power-mode metadata.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_root_lock_policy.sh",
        "scripts/check_versioning_release_hygiene.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R0.5.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject undeclared tools, network inputs, rebuild islands, and benchmark environments"
      ],
      "objective": "Record tier-1 macOS arm64 and Linux x86_64; add Linux arm64 and Windows x86_64 as tier-2 until promoted. Include CPU, memory, filesystem, OS, compiler, and power-mode metadata.",
      "owner_paths": [
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.3.b",
        "R0.4.d"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 889,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Establish reference host profiles",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.5"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_roadmap_workloads.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "roadmap-workload-bundle-sha256:a14f98d85c198c2743873d94ee50eb0ad4a954c9e922e36a3f0d0b1c3136241f"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.3.b",
          "R0.4.d",
          "R0.5.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Fix exact source terms, input sizes, expected hashes, warmup, sample count, timeout, cache state, and statistical treatment for PB-1 through PB-10.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_root_lock_policy.sh",
        "scripts/check_versioning_release_hygiene.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R0.5.b",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject undeclared tools, network inputs, rebuild islands, and benchmark environments"
      ],
      "objective": "Fix exact source terms, input sizes, expected hashes, warmup, sample count, timeout, cache state, and statistical treatment for PB-1 through PB-10.",
      "owner_paths": [
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.3.b",
        "R0.4.d",
        "R0.5.a"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 891,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Normalize benchmark workloads",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.5"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_roadmap_baseline.sh"
          ],
          "completed_date": "2026-07-10",
          "input_identity": "roadmap-baseline-bundle-sha256:712576d0f8f7975f63c8379119a38001f19e637f73319619457faf6b88378976"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.3.b",
          "R0.4.d",
          "R0.5.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Preserve raw samples and current failures without rewriting history; label local 2026-07-10 numbers E0 until reproduced under the new harness.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_root_lock_policy.sh",
        "scripts/check_versioning_release_hygiene.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R0.5.c",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject undeclared tools, network inputs, rebuild islands, and benchmark environments"
      ],
      "objective": "Preserve raw samples and current failures without rewriting history; label local 2026-07-10 numbers E0 until reproduced under the new harness.",
      "owner_paths": [
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.3.b",
        "R0.4.d",
        "R0.5.b"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 893,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Capture a signed baseline",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.5"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_release_notes.sh"
          ],
          "completed_date": "2026-07-11",
          "input_identity": "release-notes-bundle-sha256:5ef01ad2e7c4b9be665998b062264d19be751c235410fdb01a382e1f0dacbd00"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "Cargo.toml",
          "Cargo.lock",
          "genesis.lock",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.3.b",
          "R0.4.d",
          "R0.5.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Generate compatibility, migration, known-gap, evidence, dependency, and security sections from canonical inputs; reject unsupported claims.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_root_lock_policy.sh",
        "scripts/check_versioning_release_hygiene.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R0.5.d",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject undeclared tools, network inputs, rebuild islands, and benchmark environments"
      ],
      "objective": "Generate compatibility, migration, known-gap, evidence, dependency, and security sections from canonical inputs; reject unsupported claims.",
      "owner_paths": [
        "Cargo.toml",
        "Cargo.lock",
        "genesis.lock",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R0",
      "prerequisites": [
        "R0.3.b",
        "R0.4.d",
        "R0.5.c"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 895,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Add release-note automation",
      "unsatisfied_prerequisites": [],
      "workstream": "R0.5"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_gc_agent_profile.sh"
          ],
          "completed_date": "2026-07-11",
          "input_identity": "gc-agent-profile-bundle-sha256:0c1fdf1f041602cb9e6d58a89819229db059597ed13a7e8f06e030580e7745d8"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.e",
          "R0.3.e",
          "R0.5.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Freeze the supported surface for agent training: lexical grammar, CoreForm mapping, evaluation, values, contracts, modules, effects, packages, errors, resource limits, and compatibility identifiers.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.1.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Freeze the supported surface for agent training: lexical grammar, CoreForm mapping, evaluation, values, contracts, modules, effects, packages, errors, resource limits, and compatibility identifiers.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R0.2.e",
        "R0.3.e",
        "R0.5.d"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 908,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Define `GC-AGENT-v0.3`",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_gc_agent_core_card.sh"
          ],
          "completed_date": "2026-07-11",
          "input_identity": "gc-agent-core-card-bundle-sha256:8be7f276d116df8d70fd0fdaa7816b51d3ae4aa7d89c1dd62ae96f8a3a4db914"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.e",
          "R0.3.e",
          "R0.5.d",
          "R1.1.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Produce a <=4k-token core card from normative schemas/spec anchors, with canonical positive and negative examples. A drift gate proves every symbol/example parses against the current profile.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.1.b",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Produce a <=4k-token core card from normative schemas/spec anchors, with canonical positive and negative examples. A drift gate proves every symbol/example parses against the current profile.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R0.2.e",
        "R0.3.e",
        "R0.5.d",
        "R1.1.a"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 910,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Generate a compact language card",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_gc_agent_task_cards.sh"
          ],
          "completed_date": "2026-07-11",
          "input_identity": "gc-agent-task-cards-bundle-sha256:9eda4ffa6b9afd6f98121b7cae945ec634f752e9c55b809c5cb703cc73743afa"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.e",
          "R0.3.e",
          "R0.5.d",
          "R1.1.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Create capability, package, patch, replay, testing, deployment, and troubleshooting cards selected by declared task intent, each with a token budget and source hash.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.1.c",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Create capability, package, patch, replay, testing, deployment, and troubleshooting cards selected by declared task intent, each with a token budget and source hash.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R0.2.e",
        "R0.3.e",
        "R0.5.d",
        "R1.1.b"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 912,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Generate task-specific cards",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_gc_agent_symbol_index.sh"
          ],
          "completed_date": "2026-07-11",
          "input_identity": "gc-agent-symbol-index-bundle-sha256:25754cf52a47e735abcc667cb2bf43284702d8a304f9b05b4fc539e38ed240cf"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.e",
          "R0.3.e",
          "R0.5.d",
          "R1.1.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Include signatures, effects, capabilities, contracts, examples, diagnostics, deprecations, and source links. Support exact lookup without embedding the entire doc tree.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.1.d",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Include signatures, effects, capabilities, contracts, examples, diagnostics, deprecations, and source links. Support exact lookup without embedding the entire doc tree.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R0.2.e",
        "R0.3.e",
        "R0.5.d",
        "R1.1.c"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 914,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Publish a machine-readable symbol index",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_gc_agent_profile.sh",
            "scripts/check_gc_agent_core_card.sh"
          ],
          "completed_date": "2026-07-11",
          "input_identity": "gc-agent-unsupported-behavior-bundle-sha256:b96ffc3ef48e79c837383c9f4febecc7662b58d64d5ed700400127226678c558"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.e",
          "R0.3.e",
          "R0.5.d",
          "R1.1.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "The card and schema must name experimental syntax, host-only operations, unavailable targets, nondeterministic facilities, and capabilities outside the selected profile.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.1.e",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "The card and schema must name experimental syntax, host-only operations, unavailable targets, nondeterministic facilities, and capabilities outside the selected profile.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R0.2.e",
        "R0.3.e",
        "R0.5.d",
        "R1.1.d"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 916,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Define unsupported behavior",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_cli_diagnostics_contract.sh"
          ],
          "completed_date": "2026-07-11",
          "input_identity": "gc-diagnostic-catalog-bundle-sha256:356bd19b37f25bb8f3ab0d001b9cec88613ab095841573cdec0b689c5596c36a"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Assign versioned IDs, severity, phase, primary span, related spans, structured parameters, likely causes, safe repair actions, and documentation anchors.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.2.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Assign versioned IDs, severity, phase, primary span, related spans, structured parameters, likely causes, safe repair actions, and documentation anchors.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 921,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Create a stable diagnostic catalog",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_cli_diagnostics_contract.sh"
          ],
          "completed_date": "2026-07-11",
          "input_identity": "structured-failure-contract-bundle-sha256:b32f803da6513570233bca0aaa59bfc5989b976c14086a3a66a73a6a5a6473f3"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Parser, typechecker, evaluator, package, policy, replay, patch, build, and deployment errors expose structured JSON while retaining concise human rendering.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.2.b",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Parser, typechecker, evaluator, package, policy, replay, patch, build, and deployment errors expose structured JSON while retaining concise human rendering.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.a"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 923,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Eliminate string-only failure contracts",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_cli_diagnostics_contract.sh"
          ],
          "completed_date": "2026-07-11",
          "input_identity": "guarded-repair-hints-bundle-sha256:19a1c623a02cfae36bf4d87f6857128b86a9973460830d37a349c464eda60d52"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Hints may propose syntax/contract/capability changes but never silently broaden policy or suppress an obligation. Capability broadening is a separately reviewable policy diff.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.2.c",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Hints may propose syntax/contract/capability changes but never silently broaden policy or suppress an obligation. Capability broadening is a separately reviewable policy diff.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.b"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 925,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Add repair hints with guardrails",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_cli_diagnostics_contract.sh"
          ],
          "completed_date": "2026-07-11",
          "input_identity": "diagnostic-goldens-bundle-sha256:cd20894adc89f2b19e951f68444a4b9f2ceb721b4e86e1f5ce7a6184fba0180d"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Cover malformed syntax, type/effect mismatch, unhandled effects, seal misuse, replay tampering, path normalization, exhausted budgets, invalid packages, stale patches, and incompatible profiles.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.2.d",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Cover malformed syntax, type/effect mismatch, unhandled effects, seal misuse, replay tampering, path normalization, exhausted budgets, invalid packages, stale patches, and incompatible profiles.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.c"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 927,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Build diagnostic goldens",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_cli_diagnostics_contract.sh"
          ],
          "completed_date": "2026-07-11",
          "input_identity": "diagnostic-repair-utility-bundle-sha256:8833cd125f585fc5a397be592a7e5e84ba1553f7f3a8cfe87716190db1926e14"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Run deterministic mutation families plus pinned reference agents; report exact recovery, over-repair, policy broadening, regression, and token cost.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.2.e",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Run deterministic mutation families plus pinned reference agents; report exact recovery, over-repair, policy broadening, regression, and token cost.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.d"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 929,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Measure repair utility",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_cli_diagnostics_contract.sh"
          ],
          "completed_date": "2026-07-14",
          "input_identity": "human-diagnostic-rendering-bundle-sha256:c05c0b1d7fa7c3937b2719301901866d66352e89b60ada9757e2343a013bd64c"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Render every stable structured diagnostic as a concise message that includes the failed operation, safe normalized subject, primary cause, and one next action without requiring `--json`. Generate human text from the catalog/context rather than maintaining parallel prose, preserve redaction and deterministic ordering, and test terse terminals, color/no-color, narrow widths, nested causes, and unknown-safe fallback.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.2.f",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Render every stable structured diagnostic as a concise message that includes the failed operation, safe normalized subject, primary cause, and one next action without requiring `--json`. Generate human text from the catalog/context rather than maintaining parallel prose, preserve redaction and deterministic ordering, and test terse terminals, color/no-color, narrow widths, nested causes, and unknown-safe fallback.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.e"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 931,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Make human diagnostics independently useful",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_warm_protocol_contract.sh"
          ],
          "completed_date": "2026-07-11",
          "input_identity": "warm-protocol-bundle-sha256:6dc3459c77f4f981cb100dd2584d5e75fb33aebc7a0ab2f545a8ae704104a304"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Version framing, request IDs, cancellation, deadlines, bounded queues, per-workspace isolation, graceful restart, crash recovery, idle eviction, and protocol-level typed errors.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.3.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Version framing, request IDs, cancellation, deadlines, bounded queues, per-workspace isolation, graceful restart, crash recovery, idle eviction, and protocol-level typed errors.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 936,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Harden the existing `warm` protocol",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.3"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_host_bridge_fault_injection.sh"
          ],
          "completed_date": "2026-07-11",
          "input_identity": "hard-cancellation-bundle-sha256:77c8248ddc73c009077f31b41ba90a4a96a9c16ba948897aaf911aa388a6a2ef"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.3.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Killing a timed-out host/process/bridge operation must terminate and reap the child or isolate it in a killable worker. Add repeated-hang stress tests and prove no worker/thread leak.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.3.b",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Killing a timed-out host/process/bridge operation must terminate and reap the child or isolate it in a killable worker. Add repeated-hang stress tests and prove no worker/thread leak.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.3.a"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 938,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Make cancellation real",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.3"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_warm_protocol_contract.sh",
            "scripts/check_cli_diagnostics_contract.sh"
          ],
          "completed_date": "2026-07-14",
          "input_identity": "mcp-interface-bundle-sha256:009249478ef3d2ae188ecb653a7ab54318f922735352d84d4c3ac47d80963388"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Implement the MCP 2025-11-25 profile over stdio first, including lifecycle, version/capability negotiation, cancellation, progress, errors, roots, resources, and tools. Expose parse, format, check, run, test, explain, search-symbol, get-card, diff, apply-patch, verify, replay, package, build, and the transactional session lifecycle without hand-maintaining a second semantic API. MCP Tasks remain an experimental, explicitly negotiated extension mapped onto Genesis durable-job semantics; core interoperability cannot depend on them.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.3.c",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Implement the MCP 2025-11-25 profile over stdio first, including lifecycle, version/capability negotiation, cancellation, progress, errors, roots, resources, and tools. Expose parse, format, check, run, test, explain, search-symbol, get-card, diff, apply-patch, verify, replay, package, build, and the transactional session lifecycle without hand-maintaining a second semantic API. MCP Tasks remain an experimental, explicitly negotiated extension mapped onto Genesis durable-job semantics; core interoperability cannot depend on them.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.3.b"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 940,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Generate a pinned MCP interface from CLI schemas",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.3"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_warm_protocol_contract.sh",
            "scripts/check_agent_authoring_bundle.sh",
            "scripts/check_cli_diagnostics_contract.sh",
            "scripts/check_write_genesiscode_skill_conformance.sh"
          ],
          "completed_date": "2026-07-14",
          "input_identity": "transactional-agent-session-bundle-sha256:c0d40938b12d5a930ceb9e9c0f302268ef3232a9a76e1163e2ee21a9e55ff709"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.3.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Agents operate on content-addressed workspace snapshots; writes produce semantic patches, tests run against the snapshot, and commit/apply is explicit.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.3.d",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Agents operate on content-addressed workspace snapshots; writes produce semantic patches, tests run against the snapshot, and commit/apply is explicit.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.3.c"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 942,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Add transactional sessions",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.3"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_warm_protocol_contract.sh",
            "scripts/check_no_user_panics.sh",
            "scripts/check_cli_diagnostics_contract.sh"
          ],
          "completed_date": "2026-07-14",
          "input_identity": "agent-session-resources-bundle-sha256:26ceb2214bbaff7c710ce851158d8757ec83847d757a7e233739d0d43ee55654"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.3.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Enforce CPU, wall, steps, heap, output, effects, processes, and disk. Emit provenance and an audit summary without collecting mandatory remote telemetry. On stdin EOF or client disconnect, stop admission, drain an explicitly bounded set of already accepted responses when transport permits, cancel and reap the rest, and report deterministic completion/cancellation provenance so accepted work is never silently dropped.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.3.e",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Enforce CPU, wall, steps, heap, output, effects, processes, and disk. Emit provenance and an audit summary without collecting mandatory remote telemetry. On stdin EOF or client disconnect, stop admission, drain an explicitly bounded set of already accepted responses when transport permits, cancel and reap the rest, and report deterministic completion/cancellation provenance so accepted work is never silently dropped.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.3.d"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 944,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Bound and observe sessions",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R2.2.f",
          "R1.3.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Benchmark cold, warm, cache-hit, cache-miss, 100-module, 10k-module, parallel-agent, cancellation, and daemon-restart cases.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.3.f",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Benchmark cold, warm, cache-hit, cache-miss, 100-module, 10k-module, parallel-agent, cancellation, and daemon-restart cases.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R2.2.f",
        "R1.3.e"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 946,
        "path": "ROADMAP.md"
      },
      "start_ready": true,
      "state": "open",
      "title": "Meet AB-3 and AB-4",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.3"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_agent_authoring_bundle.sh",
            "crates/gc_cli/tests/cli_agent_index.rs"
          ],
          "completed_date": "2026-07-14",
          "input_identity": "gc-agent-corpus-bundle-sha256:8c4783aeaa8dd5794560c88613f19fb48c735d941c1b37b655e11aa30f5df917"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Version source provenance, license, generator identity, language profile, capability requirements, expected hashes, tests, difficulty, and intended train/dev/public-test/held-out role.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Version source provenance, license, generator identity, language profile, capability requirements, expected hashes, tests, difficulty, and intended train/dev/public-test/held-out role.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 950,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Publish a corpus manifest",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_agent_authoring_bundle.sh",
            "crates/gc_cli/tests/cli_canonical_language_examples.rs"
          ],
          "completed_date": "2026-07-15",
          "input_identity": "gc-canonical-examples-bundle-sha256:9c097f95002d9ab9572b6a893bc305dd9330e03083a6677b35c30ba30693b0d5"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Include pure functions, persistent collections, contracts, modules, sealed errors, effects, replay, packages, patches, tests, and resource failures. Pair valid examples with minimal invalid counterexamples.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.b",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Include pure functions, persistent collections, contracts, modules, sealed errors, effects, replay, packages, patches, tests, and resource failures. Pair valid examples with minimal invalid counterexamples.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 952,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Build canonical language examples",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_agent_authoring_bundle.sh",
            "crates/gc_cli/tests/cli_agent_task_benchmarks.rs"
          ],
          "completed_date": "2026-07-15",
          "input_identity": "gc-agent-task-benchmark-bundle-sha256:ed98f729a379239fa4a07c92b905ae5072450cee77595a19b12038dc4fe8189d"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Cover generation, completion, repair, refactor, policy minimization, replay investigation, performance repair, package migration, and deployment across increasing context sizes.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.c",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Cover generation, completion, repair, refactor, policy minimization, replay investigation, performance repair, package migration, and deployment across increasing context sizes.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 954,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Build task benchmarks",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_agent_authoring_bundle.sh",
            "crates/gc_cli/tests/cli_agent_index.rs"
          ],
          "completed_date": "2026-07-15",
          "input_identity": "gc-agent-held-out-evaluation-bundle-sha256:0dccf9375e5c92f28ba07b4f3b4f830462ef6a6fa9760b1492a63e94c6236bfc"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Keep test inputs or oracle details outside distributed training packs, publish hashes and later disclosure rules, rotate compromised sets, and label any contaminated model result.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.d",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Keep test inputs or oracle details outside distributed training packs, publish hashes and later disclosure rules, rotate compromised sets, and label any contaminated model result.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 956,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Protect held-out evaluation",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_agent_authoring_bundle.sh",
            "crates/gc_cli/tests/cli_agent_benchmark_scoring.rs"
          ],
          "completed_date": "2026-07-15",
          "input_identity": "gc-agent-benchmark-scoring-bundle-sha256:e25788308b596fef6a235324eed15194a5749579c6ace8dbec1b3572d1625e01"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Deterministic tests score semantics, obligations, effects, patch minimality, resource use, and policy scope. Model-specific latency/cost is a separate dimension.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.e",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Deterministic tests score semantics, obligations, effects, patch minimality, resource use, and policy scope. Model-specific latency/cost is a separate dimension.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 958,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Make scoring model-agnostic",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_agent_authoring_bundle.sh",
            "crates/gc_cli/tests/cli_agent_benchmark_run.rs"
          ],
          "completed_date": "2026-07-15",
          "input_identity": "gc-agent-benchmark-run-bundle-sha256:c300e478cd1a4ac67487ab8e41ea12c362929290fe5695a1d112e246a500a474"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Record model/runtime, prompt/card hashes, decoding, retries, tool protocol, host, and every candidate artifact. Permit fully local model runners through explicit effects.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.f",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Record model/runtime, prompt/card hashes, decoding, retries, tool protocol, host, and every candidate artifact. Permit fully local model runners through explicit effects.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 960,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Add benchmark reproducibility",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_agent_authoring_bundle.sh",
            "crates/gc_cli/tests/cli_agent_index.rs",
            "crates/gc_cli/tests/cli_agent_benchmark_run.rs"
          ],
          "completed_date": "2026-07-15",
          "input_identity": "genesisbench-protocol-bundle-sha256:5024d7ef7e9da3698f7e9cf4b3c775c2d449575636b5713240e2d4e43ae000dd"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Define a versioned, self-hostable benchmark profile that freezes the repository/runtime/docs snapshot, allowed context assembly, tool surface, capability policy, attempt policy, model disclosure, task visibility, scoring authority, contamination label, and ranked/unranked eligibility. A run may claim only the strongest label its evidence proves; unknown training provenance defaults to `unknown`, and judge-model preference never contributes to the deterministic quality score.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.g",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Define a versioned, self-hostable benchmark profile that freezes the repository/runtime/docs snapshot, allowed context assembly, tool surface, capability policy, attempt policy, model disclosure, task visibility, scoring authority, contamination label, and ranked/unranked eligibility. A run may claim only the strongest label its evidence proves; unknown training provenance defaults to `unknown`, and judge-model preference never contributes to the deterministic quality score.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 962,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Publish the GenesisBench protocol",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_agent_authoring_bundle.sh",
            "crates/gc_cli/tests/cli_agent_index.rs",
            "crates/gc_cli/tests/cli_agent_benchmark_run.rs"
          ],
          "completed_date": "2026-07-15",
          "input_identity": "genesisbench-protocol-bundle-sha256:5024d7ef7e9da3698f7e9cf4b3c775c2d449575636b5713240e2d4e43ae000dd"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Define `cold-acquisition` as the headline model-comparison track with no GenesisCode-specific training and one fixed reference scaffold; `open-agent` permits arbitrary disclosed retrieval/orchestration under the same external authority and resource ceilings; `genesis-adapted` permits only declared, lineage-audited public adaptation material; `embedded-local` requires offline inference and versioned hardware classes, initially S/M/L at <=4/16/64 GiB combined model/runtime resident footprint. Track, scaffold, profile, epoch, context/tool condition, attempt policy, and hardware class are cohort keys. A raw model, a scaffolded system, an adapted specialist, and a local appliance never share one rank or aggregate.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.h",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Define `cold-acquisition` as the headline model-comparison track with no GenesisCode-specific training and one fixed reference scaffold; `open-agent` permits arbitrary disclosed retrieval/orchestration under the same external authority and resource ceilings; `genesis-adapted` permits only declared, lineage-audited public adaptation material; `embedded-local` requires offline inference and versioned hardware classes, initially S/M/L at <=4/16/64 GiB combined model/runtime resident footprint. Track, scaffold, profile, epoch, context/tool condition, attempt policy, and hardware class are cohort keys. A raw model, a scaffolded system, an adapted specialist, and a local appliance never share one rank or aggregate.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 964,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Freeze four non-combinable benchmark tracks",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_agent_authoring_bundle.sh",
            "scripts/lib/genesisbench_analysis.py",
            "crates/gc_cli/tests/cli_agent_task_benchmarks.rs",
            "crates/gc_cli/tests/cli_agent_benchmark_run.rs",
            "crates/gc_cli/tests/cli_agent_index.rs"
          ],
          "completed_date": "2026-07-15",
          "input_identity": "genesisbench-lineage-analysis-bundle-sha256:2b9d229342a9d58d338c79f20e30bffcf6e1c20e2bcd6d3f78d252d27bd13b20"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Give every task family an immutable lineage ID and every context, tool, repair, scaffold, and mutation condition a child condition ID. Reclassify the current 27 public cases truthfully as nine independent lineages times three context conditions; calculate solve rates, confidence intervals, saturation, and significance over lineages or declared hierarchical models, never over repeated conditions. Publish exact denominators, missingness, invalids, abstentions, clustering, multiple-comparison policy, effect sizes, and uncertainty; prohibit pairwise decimal-rank claims unsupported by the predeclared analysis.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.i",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Give every task family an immutable lineage ID and every context, tool, repair, scaffold, and mutation condition a child condition ID. Reclassify the current 27 public cases truthfully as nine independent lineages times three context conditions; calculate solve rates, confidence intervals, saturation, and significance over lineages or declared hierarchical models, never over repeated conditions. Publish exact denominators, missingness, invalids, abstentions, clustering, multiple-comparison policy, effect sizes, and uncertainty; prohibit pairwise decimal-rank claims unsupported by the predeclared analysis.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 966,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Make task lineage and statistical independence first-class",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_agent_authoring_bundle.sh",
            "scripts/lib/gc_held_out_evaluation.py",
            "scripts/lib/gc_capability_lease.py",
            "crates/gc_cli/tests/cli_agent_index.rs"
          ],
          "completed_date": "2026-07-15",
          "input_identity": "genesisbench-temporal-epochs-bundle-sha256:e4b586f057ddd4d633e3db4e034905325bd6f90cb7153cc76e96beb8f268ce16"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Reach BQ-11 with >=45 independent held-out lineages for Preview and >=90 for mature release, balanced by class, difficulty, author/generator, domain, and acceptance shape. Precommit private tasks after target model releases, enforce custody separation, reserve BQ-4 fresh weight, rotate on schedule/leakage/saturation, and disclose retired epochs under delayed-opening rules. At least one challenge family per epoch introduces a useful post-release package, protocol, data structure, capability, or semantic-patch operation that remains maintained after ranking weight retires; arbitrary riddles and benchmark-only APIs are ineligible.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.j",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Reach BQ-11 with >=45 independent held-out lineages for Preview and >=90 for mature release, balanced by class, difficulty, author/generator, domain, and acceptance shape. Precommit private tasks after target model releases, enforce custody separation, reserve BQ-4 fresh weight, rotate on schedule/leakage/saturation, and disclose retired epochs under delayed-opening rules. At least one challenge family per epoch introduces a useful post-release package, protocol, data structure, capability, or semantic-patch operation that remains maintained after ranking weight retires; arbitrary riddles and benchmark-only APIs are ineligible.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 968,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Build scaled temporal epochs and useful post-release overlays",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/lib/genesisbench_reference_agent.py",
            "scripts/check_agent_authoring_bundle.sh",
            "crates/gc_cli/tests/cli_agent_index.rs"
          ],
          "completed_date": "2026-07-15",
          "input_identity": "genesisbench-reference-agent-bundle-sha256:b404c705af26241348c86e9bcca9a575ab4a4a76cf64b4d7e9edc63217fd5cac"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Version and hash the system prompt, typed prompt assembly, retrieval algorithm, core/task cards, MCP catalog, semantic transaction flow, execution/diagnostic/repair loop, stop policy, budgets, and adapter behavior so the model revision is the only meaningful Cold Acquisition variable. Publish predeclared core-card-only, fixed-context, retrieval, diagnostics, semantic-patch, grammar-constraint, one-attempt, and bounded-repair ablations as separate conditions under the same lineage. Model-specific prompt tricks require a new scaffold cohort; hidden retries, subagents, and provider tools are rejected in this track.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.k",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Version and hash the system prompt, typed prompt assembly, retrieval algorithm, core/task cards, MCP catalog, semantic transaction flow, execution/diagnostic/repair loop, stop policy, budgets, and adapter behavior so the model revision is the only meaningful Cold Acquisition variable. Publish predeclared core-card-only, fixed-context, retrieval, diagnostics, semantic-patch, grammar-constraint, one-attempt, and bounded-repair ablations as separate conditions under the same lineage. Model-specific prompt tricks require a new scaffold cohort; hidden retries, subagents, and provider tools are rejected in this track.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 970,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Ship a fixed reference agent and controlled ablations",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/lib/genesisbench_front_door.py",
            "crates/gc_cli/tests/cli_genesisbench_front_door.rs",
            "scripts/check_agent_authoring_bundle.sh"
          ],
          "completed_date": "2026-07-15",
          "input_identity": "genesisbench-front-door-profile-sha256:df18ea902400c39c6d145efe6f9886f40baade8950ff89b47131adb2eb5481c6"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Implement `genesis bench inspect`, `run`, `validate-run`, `score`, `replay`, `bundle`, and `submit` over existing authorities rather than duplicating semantics. Define closed, capability-minimal adapters for hosted APIs, local OpenAI-compatible servers, direct local runtimes, command/plugin runners, and a deterministic mock. Adapters normalize requests/responses without semantic rewriting, disclose provider transport and mutable service facts, retain all attempts, redact secrets by policy, cannot acquire ambient tools/network/filesystem authority, and pass identical conformance, timeout, cancellation, and replay suites.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.l",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Implement `genesis bench inspect`, `run`, `validate-run`, `score`, `replay`, `bundle`, and `submit` over existing authorities rather than duplicating semantics. Define closed, capability-minimal adapters for hosted APIs, local OpenAI-compatible servers, direct local runtimes, command/plugin runners, and a deterministic mock. Adapters normalize requests/responses without semantic rewriting, disclose provider transport and mutable service facts, retain all attempts, redact secrets by policy, cannot acquire ambient tools/network/filesystem authority, and pass identical conformance, timeout, cancellation, and replay suites.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 972,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Provide one canonical benchmark front door and adapter contract",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/lib/genesisbench_registry.py",
            "crates/gc_cli/tests/cli_genesisbench_registry.rs",
            "scripts/check_agent_authoring_bundle.sh"
          ],
          "completed_date": "2026-07-15",
          "input_identity": "genesisbench-signed-registry-bundle-sha256:200a90d0ef3596844f30fd3aeaa643ae219a9b0a1e3b7466cbcedb3f18f1063a"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Accept only closed run bundles that validate, deterministically and independently rescore, carry submitter provenance, and satisfy the exact track/profile. Rank within one compatible cohort by verified solve rate first, conditional quality among valid solutions second, then capability excess, context/tool efficiency, repair efficiency, and finally separately reported cost/latency; never let invalid partial quality or financial spend outrank a verified solve. Publish per-lineage and per-class results, all validity failures/attempts/abstentions, confidence treatment, model/runtime identity, contamination, hardware facts, and replay instructions. The locally hostable registry is append-only by result identity, independently rebuildable, and cannot rewrite or silently hide history.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.m",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Accept only closed run bundles that validate, deterministically and independently rescore, carry submitter provenance, and satisfy the exact track/profile. Rank within one compatible cohort by verified solve rate first, conditional quality among valid solutions second, then capability excess, context/tool efficiency, repair efficiency, and finally separately reported cost/latency; never let invalid partial quality or financial spend outrank a verified solve. Publish per-lineage and per-class results, all validity failures/attempts/abstentions, confidence treatment, model/runtime identity, contamination, hardware facts, and replay instructions. The locally hostable registry is append-only by result identity, independently rebuildable, and cannot rewrite or silently hide history.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 974,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Build a signed result registry and lexicographic static leaderboard",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_agent_authoring_bundle.sh",
            "scripts/lib/genesisbench_construct_validity.py",
            "crates/gc_cli/tests/cli_genesisbench_construct_validity.rs",
            "crates/gc_cli/tests/cli_agent_benchmark_scoring.rs"
          ],
          "completed_date": "2026-07-16",
          "input_identity": "genesisbench-construct-validity-bundle-sha256:4e28308f159277a4e77db12d8f798f1b16a48608f84bd1e743b3a291a953aa39"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Prove that results track semantic correctness, obligations, minimal authority, maintainable patch quality, bounded resources, repository localization, and diagnostic recovery rather than syntax imitation, formatting, prompt length, provider latency, model identity, task-specific runtime recognizers, or oracle leakage. Accept alternative correct designs through behavioral/property/metamorphic tests, resource/capability/API envelopes, and hidden hand-reviewed verifiers rather than exact reference-patch equality. Add seeded follow-on requirements, profile migrations, defects, policy tightening, and performance constraints; source-equivalent anti-overfit variants; scorer/evaluator mutation; bootstrap confidence intervals; saturation tests; and independent stratified audits without making model or human preference the quality oracle.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.n",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Prove that results track semantic correctness, obligations, minimal authority, maintainable patch quality, bounded resources, repository localization, and diagnostic recovery rather than syntax imitation, formatting, prompt length, provider latency, model identity, task-specific runtime recognizers, or oracle leakage. Accept alternative correct designs through behavioral/property/metamorphic tests, resource/capability/API envelopes, and hidden hand-reviewed verifiers rather than exact reference-patch equality. Add seeded follow-on requirements, profile migrations, defects, policy tightening, and performance constraints; source-equivalent anti-overfit variants; scorer/evaluator mutation; bootstrap confidence intervals; saturation tests; and independent stratified audits without making model or human preference the quality oracle.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 976,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Validate construct, alternatives, maintenance, and anti-gaming behavior",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f",
          "R0.4.k",
          "R1.4.n",
          "F2.r",
          "R8.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Freeze one clean GenesisBench snapshot and predeclaration before execution. Campaign A runs Codex CLI with provider-catalog model `gpt-5.6-luna` and reasoning effort `xhigh` through a versioned Open Agent workspace harness: pin the CLI executable digest/version and invocation, bind the observed provider catalog without falsely claiming immutable revision identity, use an ephemeral isolated copy-on-write checkout, disclose its exact system/rules/tool/scaffold/capability/resource configuration, prohibit private held-out access and ambient user instructions, retain JSONL events and final artifacts, and perform no hidden retry or between-case tuning. It first attempts one public case from every core task class; only after all nine successes, failures, invalids, abstentions, capability requests, resource facts, and costs validate, replay, and independently rescore does it expand to all 27 public conditions. Campaign B runs at least two digest-pinned, license-compatible local model classes through the same frozen semantic acceptance authority: the smallest viable model and the strongest model that fits the host, using offline MLX/OpenAI-compatible or direct-runtime adapters with weights/tokenizer/runtime digests, measured combined resident memory, and no server fallback. Report local fixed-scaffold Cold Acquisition separately from agentic or Embedded Local runs; do not compare across track, scaffold, model-identity, context, hardware, or attempt-policy cohorts. Then expand to pinned frontier-general, code-specialized, and open-weight families under predeclared complete matrices. Report pass@1 and bounded pass@k separately, keep conditions clustered by nine independent lineages, select potential teachers per task class and verified trajectory rather than aggregate rank, and make no temporal-clean claim without proven release/precommit chronology. Publish every expected attempt or explicit missing cell as a closed bundle plus machine-readable benchmark/model cards, typed failure-to-owner dispositions, failure taxonomy, and a reproducible methods paper covering construct, non-claims, tracks, lineages, context conditions, scoring, contamination, custody, statistics, adapters, limitations, economics as non-ranking facts, and exact regeneration from accepted bundles. A deterministic mock, an unresolved mutable model alias, or a hand-copied candidate remains unranked and cannot satisfy the reality gate.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.o",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Freeze one clean GenesisBench snapshot and predeclaration before execution. Campaign A runs Codex CLI with provider-catalog model `gpt-5.6-luna` and reasoning effort `xhigh` through a versioned Open Agent workspace harness: pin the CLI executable digest/version and invocation, bind the observed provider catalog without falsely claiming immutable revision identity, use an ephemeral isolated copy-on-write checkout, disclose its exact system/rules/tool/scaffold/capability/resource configuration, prohibit private held-out access and ambient user instructions, retain JSONL events and final artifacts, and perform no hidden retry or between-case tuning. It first attempts one public case from every core task class; only after all nine successes, failures, invalids, abstentions, capability requests, resource facts, and costs validate, replay, and independently rescore does it expand to all 27 public conditions. Campaign B runs at least two digest-pinned, license-compatible local model classes through the same frozen semantic acceptance authority: the smallest viable model and the strongest model that fits the host, using offline MLX/OpenAI-compatible or direct-runtime adapters with weights/tokenizer/runtime digests, measured combined resident memory, and no server fallback. Report local fixed-scaffold Cold Acquisition separately from agentic or Embedded Local runs; do not compare across track, scaffold, model-identity, context, hardware, or attempt-policy cohorts. Then expand to pinned frontier-general, code-specialized, and open-weight families under predeclared complete matrices. Report pass@1 and bounded pass@k separately, keep conditions clustered by nine independent lineages, select potential teachers per task class and verified trajectory rather than aggregate rank, and make no temporal-clean claim without proven release/precommit chronology. Publish every expected attempt or explicit missing cell as a closed bundle plus machine-readable benchmark/model cards, typed failure-to-owner dispositions, failure taxonomy, and a reproducible methods paper covering construct, non-claims, tracks, lineages, context conditions, scoring, contamination, custody, statistics, adapters, limitations, economics as non-ranking facts, and exact regeneration from accepted bundles. A deterministic mock, an unresolved mutable model alias, or a hand-copied candidate remains unranked and cannot satisfy the reality gate.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f",
        "R0.4.k",
        "R1.4.n",
        "F2.r",
        "R8.3.b"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 978,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Run named real-model campaigns, then publish reproducible baselines, benchmark card, and methods paper",
      "unsatisfied_prerequisites": [
        "F2.r",
        "R8.3.b"
      ],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f",
          "R1.4.j",
          "F2.r",
          "R8.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "This is an M1-B critical-path refinement of the completed R1.4.j protocol/commitment machinery, not a new task class or larger headline sample. Materialize at least 45 useful private lineages, at least five per core class, from at least two independently disclosed author or generator authorities; no family controls more than 25% of ranking weight, and model-generated proposals require independent human or organizational admission. Each payload binds its secret salt/commitment, authorship and license/consent, post-release chronology where claimed, difficulty rationale, editable/protected scope, capability/resource envelope, deterministic oracle plus alternative-solution policy, maintenance follow-on, leakage canaries, and custody chain. Keep payloads and oracles outside distributed source, model context, logs, and training stores; execute a blind deterministic reference and non-target pilots from at least two materially different model families through role-separated custody without exposing answers; prove every public commitment opens exactly; and retain rejected, duplicate, leaked, invalid, or unsound proposals with typed dispositions. Predeclare the structural rubric and empirical calibration method, assign every lineage an immutable epoch-local `easy`, `medium`, or `hard` band, and publish class-by-difficulty composition without exposing payloads. Freeze at least two content-addressed lineage-stratified `fast` forms before target access; publish their sampling frame, coverage gaps, and directional-only non-claims. `private_verified=false`, placeholder payloads, metadata-only balance, one project-controlled author identity, post-hoc difficulty, score-selected fast cases, or a generator label without independently reviewable bytes cannot satisfy BQ-11, BQ-15, BQ-16, or M1-B. Publish only commitments, aggregate composition, audit evidence, limitations, and later disclosure schedule until retirement; R1.4.p still governs public admission and independence. Capacity decision: prioritize this work over adding public-small variants because the commissioned small tier is weakly discriminative; use the existing R1.4.j/M1-B corpus allocation and do not delay the Qwen3 reality gate, first-results report, R0.4.j, or R2.3 startup work.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.q",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "This is an M1-B critical-path refinement of the completed R1.4.j protocol/commitment machinery, not a new task class or larger headline sample. Materialize at least 45 useful private lineages, at least five per core class, from at least two independently disclosed author or generator authorities; no family controls more than 25% of ranking weight, and model-generated proposals require independent human or organizational admission. Each payload binds its secret salt/commitment, authorship and license/consent, post-release chronology where claimed, difficulty rationale, editable/protected scope, capability/resource envelope, deterministic oracle plus alternative-solution policy, maintenance follow-on, leakage canaries, and custody chain. Keep payloads and oracles outside distributed source, model context, logs, and training stores; execute a blind deterministic reference and non-target pilots from at least two materially different model families through role-separated custody without exposing answers; prove every public commitment opens exactly; and retain rejected, duplicate, leaked, invalid, or unsound proposals with typed dispositions. Predeclare the structural rubric and empirical calibration method, assign every lineage an immutable epoch-local `easy`, `medium`, or `hard` band, and publish class-by-difficulty composition without exposing payloads. Freeze at least two content-addressed lineage-stratified `fast` forms before target access; publish their sampling frame, coverage gaps, and directional-only non-claims. `private_verified=false`, placeholder payloads, metadata-only balance, one project-controlled author identity, post-hoc difficulty, score-selected fast cases, or a generator label without independently reviewable bytes cannot satisfy BQ-11, BQ-15, BQ-16, or M1-B. Publish only commitments, aggregate composition, audit evidence, limitations, and later disclosure schedule until retirement; R1.4.p still governs public admission and independence. Capacity decision: prioritize this work over adding public-small variants because the commissioned small tier is weakly discriminative; use the existing R1.4.j/M1-B corpus allocation and do not delay the Qwen3 reality gate, first-results report, R0.4.j, or R2.3 startup work.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f",
        "R1.4.j",
        "F2.r",
        "R8.3.b"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 989,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Commission and audit a genuinely private discriminative Preview epoch",
      "unsatisfied_prerequisites": [
        "F2.r",
        "R8.3.b"
      ],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f",
          "R1.4.o",
          "R1.4.q",
          "R1.4.r",
          "F2.r",
          "R8.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Publish one signed, versioned policy for benchmark-task proposals, independent authorship/generator disclosure, duplicate/near-duplicate detection, useful-work and alternative-solution review, private-custody transfer, difficulty calibration, smoke/fast/standard/full form construction, anchor/equating policy, conflict recusal, embargo and prospective ranking-weight retirement, coordinated vulnerability/oracle-leak disclosure, result admission, appeals, operator-key rotation, and evaluator/scorer defect handling. Untrusted submissions enter quarantine; no proposer, solver, model provider, registry operator, scorer author, or custody holder may unilaterally admit its own task or result. Corrections, exclusions, supersessions, and retractions append signed status records and preserve the originally published cohort, bundle, rationale, labels, weights, and leaderboard history. Provide contributor templates, deterministic preflight tools, service SLOs, an escalation path, and adversarial exercises for collusion, Sybil authors, malicious archives, hidden duplicates, leaked oracles, conflicts, compromised keys, invalidated runs, disputed alternative solutions, post-hoc difficulty changes, score-selected fast forms, and missing strata. The policy reserves open-ended repository improvements, bounties, and prizes for the separately governed non-ranking GenesisChallenge surface in R8.5.u-v; they cannot enter a benchmark cohort or change benchmark rank. Before dropping the `project-controlled Preview` label, obtain at least one disclosed independent non-project human or organizational reviewer/operator, record scope/conflicts/dissent, and separate at least one admission, signing, or mirror authority from the project author. Agent-family diversity may satisfy generator-balance experiments but not this independence requirement. Meet BQ-14 through BQ-16 and BQ-18 through BQ-20 before calling GenesisBench a public benchmark.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.p",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Publish one signed, versioned policy for benchmark-task proposals, independent authorship/generator disclosure, duplicate/near-duplicate detection, useful-work and alternative-solution review, private-custody transfer, difficulty calibration, smoke/fast/standard/full form construction, anchor/equating policy, conflict recusal, embargo and prospective ranking-weight retirement, coordinated vulnerability/oracle-leak disclosure, result admission, appeals, operator-key rotation, and evaluator/scorer defect handling. Untrusted submissions enter quarantine; no proposer, solver, model provider, registry operator, scorer author, or custody holder may unilaterally admit its own task or result. Corrections, exclusions, supersessions, and retractions append signed status records and preserve the originally published cohort, bundle, rationale, labels, weights, and leaderboard history. Provide contributor templates, deterministic preflight tools, service SLOs, an escalation path, and adversarial exercises for collusion, Sybil authors, malicious archives, hidden duplicates, leaked oracles, conflicts, compromised keys, invalidated runs, disputed alternative solutions, post-hoc difficulty changes, score-selected fast forms, and missing strata. The policy reserves open-ended repository improvements, bounties, and prizes for the separately governed non-ranking GenesisChallenge surface in R8.5.u-v; they cannot enter a benchmark cohort or change benchmark rank. Before dropping the `project-controlled Preview` label, obtain at least one disclosed independent non-project human or organizational reviewer/operator, record scope/conflicts/dissent, and separate at least one admission, signing, or mirror authority from the project author. Agent-family diversity may satisfy generator-balance experiments but not this independence requirement. Meet BQ-14 through BQ-16 and BQ-18 through BQ-20 before calling GenesisBench a public benchmark.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f",
        "R1.4.o",
        "R1.4.q",
        "R1.4.r",
        "F2.r",
        "R8.3.b"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 990,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Establish public benchmark-task and result governance",
      "unsatisfied_prerequisites": [
        "R1.4.o",
        "R1.4.q",
        "R1.4.r",
        "F2.r",
        "R8.3.b"
      ],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f",
          "R1.4.l",
          "R1.4.n",
          "F2.r",
          "R8.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "This is an M1-B refinement of the completed scoring, protocol, reference-agent, adapter, and construct-validity authorities, not a new track or provider campaign. Publish a transport-neutral request/content/artifact contract; `artifact-text` and `canonical-tools` interaction profiles; adapter capability negotiation; tokenizer-neutral byte/structure budgets; plural non-repairing candidate extraction; and the closed terminal-owner taxonomy from section 3.17. Add a one-manifest JSON-stdio or endpoint onboarding path plus `genesis bench adapter inspect`, `conformance`, and `dry-run`. Prove one scripted model is semantically invariant across completion-only, chat, streaming/non-streaming, native-tool, JSON-text-tool, direct local, HTTP, and JSON-stdio fixtures; reject prompt/role/content mutation, hidden system text, tokenizer-driven truncation, undeclared retrieval/tools, retries, output repair, secret leakage, and model-blame laundering. Before M1-B, execute the common public `artifact-text` smoke/fast matrix through at least two independently implemented interface stacks and two materially different model families; before GenesisBench Trust, require at least three of each plus native/JSON-text tool equivalence. Codex CLI, Responses, MLX, Qwen, and every future provider remain named adapter/scaffold instances only. Historical campaigns retain their original validity and cohort labels. Meet BQ-18 through BQ-20 before claiming portable model comparison.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.4.r",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "This is an M1-B refinement of the completed scoring, protocol, reference-agent, adapter, and construct-validity authorities, not a new track or provider campaign. Publish a transport-neutral request/content/artifact contract; `artifact-text` and `canonical-tools` interaction profiles; adapter capability negotiation; tokenizer-neutral byte/structure budgets; plural non-repairing candidate extraction; and the closed terminal-owner taxonomy from section 3.17. Add a one-manifest JSON-stdio or endpoint onboarding path plus `genesis bench adapter inspect`, `conformance`, and `dry-run`. Prove one scripted model is semantically invariant across completion-only, chat, streaming/non-streaming, native-tool, JSON-text-tool, direct local, HTTP, and JSON-stdio fixtures; reject prompt/role/content mutation, hidden system text, tokenizer-driven truncation, undeclared retrieval/tools, retries, output repair, secret leakage, and model-blame laundering. Before M1-B, execute the common public `artifact-text` smoke/fast matrix through at least two independently implemented interface stacks and two materially different model families; before GenesisBench Trust, require at least three of each plus native/JSON-text tool equivalence. Codex CLI, Responses, MLX, Qwen, and every future provider remain named adapter/scaffold instances only. Historical campaigns retain their original validity and cohort labels. Meet BQ-18 through BQ-20 before claiming portable model comparison.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f",
        "R1.4.l",
        "R1.4.n",
        "F2.r",
        "R8.3.b"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 991,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Prove model-neutral adapter portability and failure attribution",
      "unsatisfied_prerequisites": [
        "F2.r",
        "R8.3.b"
      ],
      "workstream": "R1.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_agent_authoring_bundle.sh",
            "scripts/check_cli_diagnostics_contract.sh",
            "scripts/check_write_genesiscode_skill_conformance.sh",
            "scripts/check_generated_artifact_policy.sh"
          ],
          "completed_date": "2026-08-06",
          "input_identity": "authoring-skill-bundle-sha256:81109b0f3a179c7f2879a0d8afe7150d94d298a65d9dcf0392fd29c3402dfd66"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f",
          "R0.4.k",
          "R1.4.a",
          "R1.4.b",
          "R1.4.c",
          "R1.4.d",
          "R1.4.e",
          "R1.4.f",
          "R1.4.g",
          "R1.4.h",
          "R1.4.i",
          "R1.4.j",
          "R1.4.k",
          "R1.4.l",
          "R1.4.m",
          "R1.4.n"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [
          ".agents/skills/genesiscode-authoring",
          "docs/write_genesisCode_skill.md"
        ],
        "deliverable": "Replace duplicated prose across `.agents/skills/genesiscode-authoring`, `docs/write_genesisCode_skill.md`, and the versioned pack with generated cards plus a small hand-owned workflow policy.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.5.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Replace duplicated prose across `.agents/skills/genesiscode-authoring`, `docs/write_genesisCode_skill.md`, and the versioned pack with generated cards plus a small hand-owned workflow policy.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f",
        "R0.4.k",
        "R1.4.a",
        "R1.4.b",
        "R1.4.c",
        "R1.4.d",
        "R1.4.e",
        "R1.4.f",
        "R1.4.g",
        "R1.4.h",
        "R1.4.i",
        "R1.4.j",
        "R1.4.k",
        "R1.4.l",
        "R1.4.m",
        "R1.4.n"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 996,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Generate the skill from canonical inputs",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.5"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_genesiscode_authoring_skill.sh",
            "scripts/check_write_genesiscode_skill_pack.sh",
            "scripts/check_write_genesiscode_skill_distribution.sh",
            "scripts/check_agent_authoring_bundle.sh"
          ],
          "completed_date": "2026-08-06",
          "input_identity": "authoring-skill-bundle-sha256:81109b0f3a179c7f2879a0d8afe7150d94d298a65d9dcf0392fd29c3402dfd66"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f",
          "R0.4.k",
          "R1.5.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Do not direct agents to an empty `upgrade_plan.md` as their ordinary work queue. Route active defects, roadmap tasks, user tasks, and exploratory work explicitly.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.5.b",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Do not direct agents to an empty `upgrade_plan.md` as their ordinary work queue. Route active defects, roadmap tasks, user tasks, and exploratory work explicitly.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f",
        "R0.4.k",
        "R1.5.a"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 998,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Remove dead planning guidance",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f",
          "R0.4.k",
          "R1.5.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "The skill identifies CLI/language/card versions, supported capabilities, target platform, available resources, and strictness before writing code.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.5.c",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "The skill identifies CLI/language/card versions, supported capabilities, target platform, available resources, and strictness before writing code.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f",
        "R0.4.k",
        "R1.5.b"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1000,
        "path": "ROADMAP.md"
      },
      "start_ready": true,
      "state": "open",
      "title": "Add profile negotiation",
      "unsatisfied_prerequisites": [],
      "workstream": "R1.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f",
          "R0.4.k",
          "R1.5.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Provide author, repair, refactor, package, replay-debug, optimize, deploy, and self-host migration flows with exact stop/fail conditions.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.5.d",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Provide author, repair, refactor, package, replay-debug, optimize, deploy, and self-host migration flows with exact stop/fail conditions.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f",
        "R0.4.k",
        "R1.5.c"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1001,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add compact workflows",
      "unsatisfied_prerequisites": [
        "R1.5.c"
      ],
      "workstream": "R1.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f",
          "R0.4.k",
          "R1.5.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "The skill never edits policy, signing roots, generated evidence, bootstrap trust, or format versions incidentally.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.5.e",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "The skill never edits policy, signing roots, generated evidence, bootstrap trust, or format versions incidentally.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f",
        "R0.4.k",
        "R1.5.d"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1002,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add safety invariants to tool calls",
      "unsatisfied_prerequisites": [
        "R1.5.d"
      ],
      "workstream": "R1.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f",
          "R0.4.k",
          "R1.5.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Test clean install, offline use, stale-card rejection, token budgets, links, examples, and behavior with at least two independent agent/model families.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.5.f",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Test clean install, offline use, stale-card rejection, token budgets, links, examples, and behavior with at least two independent agent/model families.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f",
        "R0.4.k",
        "R1.5.e"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1003,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Validate distribution",
      "unsatisfied_prerequisites": [
        "R1.5.e"
      ],
      "workstream": "R1.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.1.e",
          "R1.2.f",
          "R0.4.k",
          "R0.1.h",
          "R1.5.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Build compact cards from the product/target capability ledger, package index, BSP/component catalogs, authentic artifact predicates, and unsupported-feature diagnostics. The skill retrieves only the selected web/service/desktop/mobile/game/data/embedded profile, never invents an unavailable API or board, never treats generated foreign glue as an editable fallback, and proposes an extension-package gap when first-party coverage is absent.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.5.g",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Build compact cards from the product/target capability ledger, package index, BSP/component catalogs, authentic artifact predicates, and unsupported-feature diagnostics. The skill retrieves only the selected web/service/desktop/mobile/game/data/embedded profile, never invents an unavailable API or board, never treats generated foreign glue as an editable fallback, and proposes an extension-package gap when first-party coverage is absent.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.1.e",
        "R1.2.f",
        "R0.4.k",
        "R0.1.h",
        "R1.5.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1004,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Generate domain and target guidance on demand",
      "unsatisfied_prerequisites": [
        "R1.5.f"
      ],
      "workstream": "R1.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R1.3.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Use content-addressed snapshots and copy-on-write overlays so multiple candidates do not duplicate build trees or mutate one another.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.6.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Use content-addressed snapshots and copy-on-write overlays so multiple candidates do not duplicate build trees or mutate one another.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R0.2.h",
        "R1.3.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1008,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Implement O(1)-logical workspace forks",
      "unsatisfied_prerequisites": [
        "R1.3.f"
      ],
      "workstream": "R1.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R1.3.f",
          "R1.6.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Rank by required-test pass, obligation strength, capability minimization, semantic patch size, resource delta, and risk; tie-break by canonical patch hash.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.6.b",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Rank by required-test pass, obligation strength, capability minimization, semantic patch size, resource delta, and risk; tie-break by canonical patch hash.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R0.2.h",
        "R1.3.f",
        "R1.6.a"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1009,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Define deterministic candidate comparison",
      "unsatisfied_prerequisites": [
        "R1.3.f",
        "R1.6.a"
      ],
      "workstream": "R1.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R1.3.f",
          "R1.6.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Provenance records role, tool/model version, context bundle, and evidence. One agent may fill roles in development, but release profiles require independent verification for high-risk changes.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.6.c",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Provenance records role, tool/model version, context bundle, and evidence. One agent may fill roles in development, but release profiles require independent verification for high-risk changes.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R0.2.h",
        "R1.3.f",
        "R1.6.b"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1010,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Separate proposer, reviewer, and verifier identities",
      "unsatisfied_prerequisites": [
        "R1.3.f",
        "R1.6.b"
      ],
      "workstream": "R1.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R1.3.f",
          "R1.6.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Cards, diagnostics, logs, model effects, and evidence redact or seal secret material; add canary negative tests.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.6.d",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Cards, diagnostics, logs, model effects, and evidence redact or seal secret material; add canary negative tests.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R0.2.h",
        "R1.3.f",
        "R1.6.c"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1011,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Prevent secret/context leakage",
      "unsatisfied_prerequisites": [
        "R1.3.f",
        "R1.6.c"
      ],
      "workstream": "R1.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R1.3.f",
          "R1.6.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Source comments, package docs, diagnostics, logs, registry metadata, model output, and retrieved files carry provenance/trust labels and cannot silently become agent policy. Add prompt-injection, confused-deputy, and indirect tool-instruction corpora.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.6.e",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Source comments, package docs, diagnostics, logs, registry metadata, model output, and retrieved files carry provenance/trust labels and cannot silently become agent policy. Add prompt-injection, confused-deputy, and indirect tool-instruction corpora.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R0.2.h",
        "R1.3.f",
        "R1.6.d"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1012,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Separate instructions from untrusted content",
      "unsatisfied_prerequisites": [
        "R1.3.f",
        "R1.6.d"
      ],
      "workstream": "R1.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R1.3.f",
          "R1.6.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Each mutating or effectful agent call carries workspace identity, requested operation, capability scope, budget, and confirmation policy; stale, cross-workspace, broadened, or replayed requests fail closed.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.6.f",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Each mutating or effectful agent call carries workspace identity, requested operation, capability scope, budget, and confirmation policy; stale, cross-workspace, broadened, or replayed requests fail closed.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R0.2.h",
        "R1.3.f",
        "R1.6.e"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1013,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Bind tools to explicit intent and authority",
      "unsatisfied_prerequisites": [
        "R1.3.f",
        "R1.6.e"
      ],
      "workstream": "R1.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.3.f",
          "R1.6.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Translate an English request into a closed, versioned record of deliverables, constraints, accepted inputs, editable scope, target profiles, capabilities, budgets, acceptance tests/obligations, uncertainty, and explicit unsupported assumptions. Translation is an untrusted proposal; malformed, ambiguous, over-authorized, or untestable goals produce typed questions or abstention rather than executable authority.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.7.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Translate an English request into a closed, versioned record of deliverables, constraints, accepted inputs, editable scope, target profiles, capabilities, budgets, acceptance tests/obligations, uncertainty, and explicit unsupported assumptions. Translation is an untrusted proposal; malformed, ambiguous, over-authorized, or untestable goals produce typed questions or abstention rather than executable authority.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.3.f",
        "R1.6.f"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1017,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Define Goal/Intent IR",
      "unsatisfied_prerequisites": [
        "R1.3.f",
        "R1.6.f"
      ],
      "workstream": "R1.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.3.f",
          "R1.6.f",
          "R1.4.l",
          "R1.7.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "A general model may propose the Goal/Intent IR, retrieval plan, and GenesisCode changes through the versioned agent interface; every mutation occurs in an isolated semantic transaction and reaches accepted state only through deterministic parsing, types/effects, obligations, policy, tests, resource checks, replay, and user/release confirmation. The preview may use R1.4's benchmark model-runner adapter but does not claim R5.4.e's production model-effect profile.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.7.b",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "A general model may propose the Goal/Intent IR, retrieval plan, and GenesisCode changes through the versioned agent interface; every mutation occurs in an isolated semantic transaction and reaches accepted state only through deterministic parsing, types/effects, obligations, policy, tests, resource checks, replay, and user/release confirmation. The preview may use R1.4's benchmark model-runner adapter but does not claim R5.4.e's production model-effect profile.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.3.f",
        "R1.6.f",
        "R1.4.l",
        "R1.7.a"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1018,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Ship a transactional `genesis ask` preview",
      "unsatisfied_prerequisites": [
        "R1.3.f",
        "R1.6.f",
        "R1.7.a"
      ],
      "workstream": "R1.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.3.f",
          "R1.6.f",
          "R1.7.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Support one general model for English/domain planning and an optional separate GenesisCode specialist for source, patches, policies, tests, and repairs, with explicit content-addressed handoff records. Routing is versioned and benchmarked against a single-model baseline; no architecture is made permanent without measured quality, cost, privacy, and local-deployment benefit.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.7.c",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Support one general model for English/domain planning and an optional separate GenesisCode specialist for source, patches, policies, tests, and repairs, with explicit content-addressed handoff records. Routing is versioned and benchmarked against a single-model baseline; no architecture is made permanent without measured quality, cost, privacy, and local-deployment benefit.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.3.f",
        "R1.6.f",
        "R1.7.b"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1019,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Keep planning and specialization replaceable",
      "unsatisfied_prerequisites": [
        "R1.3.f",
        "R1.6.f",
        "R1.7.b"
      ],
      "workstream": "R1.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.3.f",
          "R1.6.f",
          "R1.7.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Retain authorized English request, typed intent, retrievals, model calls, tool actions, attempts, diagnostics, repairs, accepted/rejected patches, capability decisions, evidence, and final outcome under AB-12. Raw trajectories are user-owned/quarantined by default and are not examples, packages, training data, or benchmark authority until a separate R8.5 promotion record proves consent/license, privacy, lineage, verification, deduplication, and held-out isolation.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.7.d",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Retain authorized English request, typed intent, retrievals, model calls, tool actions, attempts, diagnostics, repairs, accepted/rejected patches, capability decisions, evidence, and final outcome under AB-12. Raw trajectories are user-owned/quarantined by default and are not examples, packages, training data, or benchmark authority until a separate R8.5 promotion record proves consent/license, privacy, lineage, verification, deduplication, and held-out isolation.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.3.f",
        "R1.6.f",
        "R1.7.c"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1020,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Capture complete quarantined trajectories",
      "unsatisfied_prerequisites": [
        "R1.3.f",
        "R1.6.f",
        "R1.7.c"
      ],
      "workstream": "R1.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.3.f",
          "R1.6.f",
          "R1.7.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Measure typed-goal validity, clarification/abstention calibration, acceptance-test completeness, capability excess, unsupported invention, transaction escape, repair recovery, user correction burden, and end-to-end verified completion across at least two general-model families. Prompt injection, retrieved instruction confusion, secret exfiltration, evaluator tampering, and direct-mutation attempts fail closed.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.7.e",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Measure typed-goal validity, clarification/abstention calibration, acceptance-test completeness, capability excess, unsupported invention, transaction escape, repair recovery, user correction burden, and end-to-end verified completion across at least two general-model families. Prompt injection, retrieved instruction confusion, secret exfiltration, evaluator tampering, and direct-mutation attempts fail closed.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.3.f",
        "R1.6.f",
        "R1.7.d"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1021,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Evaluate intent safety and usefulness",
      "unsatisfied_prerequisites": [
        "R1.3.f",
        "R1.6.f",
        "R1.7.d"
      ],
      "workstream": "R1.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".agents",
          "docs/skill_pack",
          "docs/spec",
          "examples",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.3.f",
          "R1.6.f",
          "R0.1.h",
          "R1.7.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Decompose requests such as a website, game, mobile app, service, data pipeline, Raspberry Pi system, or MCU device into product features, target profiles, domain packages, assets, capabilities, resource/SLO budgets, real-runtime/device tests, deployment/update/rollback, and one-language source obligations. Unknown domain knowledge triggers typed retrieval or clarification; an unavailable target produces a truthful staged plan rather than foreign code or a fake artifact.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_authoring_bundle.sh",
        "scripts/check_cli_diagnostics_contract.sh",
        "scripts/check_write_genesiscode_skill_conformance.sh"
      ],
      "id": "R1.7.f",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject stale cards, prompt-injected authority, policy broadening, and training/evaluation leakage"
      ],
      "objective": "Decompose requests such as a website, game, mobile app, service, data pipeline, Raspberry Pi system, or MCU device into product features, target profiles, domain packages, assets, capabilities, resource/SLO budgets, real-runtime/device tests, deployment/update/rollback, and one-language source obligations. Unknown domain knowledge triggers typed retrieval or clarification; an unavailable target produces a truthful staged plan rather than foreign code or a fake artifact.",
      "owner_paths": [
        ".agents",
        "docs/skill_pack",
        "docs/spec",
        "examples",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R1",
      "prerequisites": [
        "R1.3.f",
        "R1.6.f",
        "R0.1.h",
        "R1.7.e"
      ],
      "resource_class": "build",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1022,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Compile product intents into closed acceptance graphs",
      "unsatisfied_prerequisites": [
        "R1.3.f",
        "R1.6.f",
        "R1.7.e"
      ],
      "workstream": "R1.7"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test --workspace --offline",
            "cargo clippy -p gc_kernel --offline --all-targets -- -D warnings",
            "scripts/check_no_user_panics.sh",
            "scripts/check_agent_authoring_bundle.sh"
          ],
          "completed_date": "2026-07-16",
          "input_identity": "minimal-closure-capture-sha256:b00f5c04686265185fe6aaa99d7ac413d5b635eab90e09a7dbd277ca69a7f0ae"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.5.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Closures retain only needed bindings; differential tests cover shadowing, recursion, nested patterns, and long-lived closure graphs.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.1.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Closures retain only needed bindings; differential tests cover shadowing, recursion, nested patterns, and long-lived closure graphs.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R0.5.d"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1036,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Implement free-variable analysis and minimal closure capture",
      "unsatisfied_prerequisites": [],
      "workstream": "R2.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test --workspace --offline",
            "cargo clippy -p gc_kernel --offline --all-targets -- -D warnings",
            "cargo test -p gc_cli --test cli_run_replay_engine --profile selfhost-strict --offline",
            "gc_runtime_bench --mode workloads",
            "selfhost-strict"
          ],
          "completed_date": "2026-07-16",
          "input_identity": "compiled-flat-lexical-slots-sha256:9558bf04201df493f44a7eaa13b226efd4cb90e6c87c6de285519f6426ac08be"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.5.d",
          "R2.1.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Resolve lexical locals to slots/frames where semantics permit; remove avoidable `Rc` frame walks and per-`let` environment allocation.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.1.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Resolve lexical locals to slots/frames where semantics permit; remove avoidable `Rc` frame walks and per-`let` environment allocation.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R0.5.d",
        "R2.1.a"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1038,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Replace linked lookup on hot paths",
      "unsatisfied_prerequisites": [],
      "workstream": "R2.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "bash scripts/test_perf_gates.sh --kernel-tail-stress",
            "env -u CI cargo test --workspace --profile selfhost-strict --locked --offline",
            "cargo clippy --workspace --all-targets --locked --offline -- -D warnings",
            "scripts/check_no_user_panics.sh",
            "scripts/check_source_decomposition_progress.sh"
          ],
          "completed_date": "2026-07-16",
          "input_identity": "bounded-tail-proof-sha256:e2bd3e2ec5103329fa685a6db548e39328dfd8fbe84716e27f61c9d5dec42b66"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.5.d",
          "R2.1.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Test at least 10 million bounded tail iterations in treewalk and compiled modes with constant host stack and declared step accounting.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.1.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Test at least 10 million bounded tail iterations in treewalk and compiled modes with constant host stack and declared step accounting.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R0.5.d",
        "R2.1.b"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1040,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Close tail behavior",
      "unsatisfied_prerequisites": [],
      "workstream": "R2.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test -p gc_kernel --lib --locked --offline",
            "cargo clippy -p gc_kernel --all-targets --locked --offline -- -D warnings",
            "scripts/check_kernel_tcb_contract.sh",
            "scripts/check_no_user_panics.sh",
            "scripts/check_perf_budgets.sh",
            "scripts/check_runtime_workload_budgets.sh"
          ],
          "completed_date": "2026-07-16",
          "input_identity": "primitive-call-normalization-sha256:7ac5dcee3c18e2c235b37cef832262756e55c23e0f51bdc2dba2806f9593a575"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.5.d",
          "R2.1.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Preserve n-ary uncurried paths, partial application behavior, error spans, and hashes without wrapper allocation regressions.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.1.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Preserve n-ary uncurried paths, partial application behavior, error spans, and hashes without wrapper allocation regressions.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R0.5.d",
        "R2.1.c"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1042,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Finish primitive call normalization",
      "unsatisfied_prerequisites": [],
      "workstream": "R2.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "gc_runtime_bench --mode workloads --roadmap-sample PB-5",
            "env -u CI cargo test --workspace --profile selfhost-strict --locked --offline",
            "cargo clippy --workspace --all-targets --locked --offline -- -D warnings",
            "scripts/check_foundation_stdlib_conformance.sh",
            "scripts/check_perf_budgets.sh",
            "scripts/check_runtime_workload_budgets.sh",
            "scripts/check_roadmap_workloads.sh",
            "scripts/check_kernel_tcb_contract.sh",
            "scripts/check_no_user_panics.sh"
          ],
          "completed_date": "2026-07-16",
          "input_identity": "persistent-collection-closure-sha256:afdccea7c9dead8f85dca7adc2b74a114732cde6b7c3faa0178fdc23f36914ca"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.5.d",
          "R2.1.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Bring normative map construction under PB-5, specify order/sharing, and test adversarial hash/shape/update workloads.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.1.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Bring normative map construction under PB-5, specify order/sharing, and test adversarial hash/shape/update workloads.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R0.5.d",
        "R2.1.d"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1044,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Close persistent collection budgets",
      "unsatisfied_prerequisites": [],
      "workstream": "R2.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_kernel_tcb_contract.sh",
            "cargo test -p gc_kernel --lib --locked --offline",
            "cargo clippy -p gc_kernel --all-targets --locked --offline -- -D warnings",
            "scripts/check_no_user_panics.sh",
            "scripts/check_source_decomposition_progress.sh",
            "scripts/check_doc_hygiene.sh",
            "scripts/check_doc_complexity_budget.sh",
            "scripts/check_doc_topology_drift.sh"
          ],
          "completed_date": "2026-07-16",
          "input_identity": "kernel-tier-boundary-sha256:8b9786f17e28d80b6657e5cd751106cb7af0656f6387529668719d43d3f28ef2"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.5.d",
          "R2.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Optimization-specific code remains separated from the semantic evaluator and is continuously differential-tested.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.1.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Optimization-specific code remains separated from the semantic evaluator and is continuously differential-tested.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R0.5.d",
        "R2.1.e"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1046,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Keep the reference path readable",
      "unsatisfied_prerequisites": [],
      "workstream": "R2.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_kernel_tcb_contract.sh",
            "cargo test -p gc_kernel --lib --locked --offline",
            "cargo clippy -p gc_kernel --all-targets --locked --offline -- -D warnings",
            "scripts/check_runtime_workload_budgets.sh",
            "scripts/check_perf_budgets.sh",
            "scripts/check_no_user_panics.sh",
            "scripts/check_source_decomposition_progress.sh"
          ],
          "completed_date": "2026-07-16",
          "input_identity": "recognizer-retirement-sha256:a18f73bff7504a26c0e243db59ecf98a858e92f3afed5f8c64d640ecf5a2f134"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.5.d",
          "R2.1.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [
          "crates/gc_kernel/src/compiled_runtime/patterns.rs"
        ],
        "deliverable": "Delete `crates/gc_kernel/src/compiled_runtime/patterns.rs` from production dispatch and prohibit replacement recognizers keyed to benchmark source shape, symbol names, literal constants, or expected results. General optimizations must trigger from documented semantic properties, improve a diverse anti-overfit corpus, and preserve exact behavior under source-equivalent rewrites that defeat syntactic recognition.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.1.g",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Delete `crates/gc_kernel/src/compiled_runtime/patterns.rs` from production dispatch and prohibit replacement recognizers keyed to benchmark source shape, symbol names, literal constants, or expected results. General optimizations must trigger from documented semantic properties, improve a diverse anti-overfit corpus, and preserve exact behavior under source-equivalent rewrites that defeat syntactic recognition.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R0.5.d",
        "R2.1.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1048,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Retire workload-specific recognizers",
      "unsatisfied_prerequisites": [],
      "workstream": "R2.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.5.d",
          "R2.1.g"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Profile allocation, cycle-collector overhead, evaluation dispatch, hashing, shape transitions, parser/frontend routing, self-host dispatch, and process/startup contribution with normalized workloads; fix general data-structure, evaluator, and parser costs before benchmark-specific tuning. Meet the signed PB-4 vector, PB-5 map, and PB-7 throughput bounds with confidence intervals, anti-overfit variants, cold/warm separation, and no semantic fast-path bypass. Capture a new signed PB-1 distribution on the same conformant hosts after cycle-collection and runtime changes, compare it to the retained historical baseline, attribute statistically and by profile rather than resetting the target, and assign startup-owned cost to R2.3.b. PB-4 closure must recover the honest post-recognizer ordinary-execution baseline through a general optimization that benefits semantically varied vector-building programs; restoring source-shape dispatch is not an eligible improvement.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.1.h",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Profile allocation, cycle-collector overhead, evaluation dispatch, hashing, shape transitions, parser/frontend routing, self-host dispatch, and process/startup contribution with normalized workloads; fix general data-structure, evaluator, and parser costs before benchmark-specific tuning. Meet the signed PB-4 vector, PB-5 map, and PB-7 throughput bounds with confidence intervals, anti-overfit variants, cold/warm separation, and no semantic fast-path bypass. Capture a new signed PB-1 distribution on the same conformant hosts after cycle-collection and runtime changes, compare it to the retained historical baseline, attribute statistically and by profile rather than resetting the target, and assign startup-owned cost to R2.3.b. PB-4 closure must recover the honest post-recognizer ordinary-execution baseline through a general optimization that benefits semantically varied vector-building programs; restoring source-shape dispatch is not an eligible improvement.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R0.5.d",
        "R2.1.g"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1050,
        "path": "ROADMAP.md"
      },
      "start_ready": true,
      "state": "open",
      "title": "Close PB-4, PB-5, and PB-7 and rebaseline PB-1 without hiding drift",
      "unsatisfied_prerequisites": [],
      "workstream": "R2.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "docs/spec/VALUE_EFFECT_HASH.md",
            "scripts/check_doc_topology_drift.sh",
            "scripts/check_doc_hygiene.sh",
            "scripts/check_doc_complexity_budget.sh",
            "scripts/check_planning_docs_fresh.sh"
          ],
          "completed_date": "2026-07-16",
          "input_identity": "runtime-value-graph-sha256:c796c66e7f79d489d458f003b2b7ca1eab2c978b301017c12a20857a24e3d378"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Document ownership, sharing, closure environments, cycles, finalization prohibition or semantics, weak references if any, and host-handle lifetime.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.2.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Document ownership, sharing, closure environments, cycles, finalization prohibition or semantics, weak references if any, and host-handle lifetime.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R0.2.h"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1056,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Specify the value graph",
      "unsatisfied_prerequisites": [],
      "workstream": "R2.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test --workspace --all-targets --locked",
            "cargo clippy -p gc_kernel --all-targets --locked -- -D warnings",
            "scripts/check_kernel_tcb_contract.sh",
            "scripts/check_no_user_panics.sh",
            "scripts/check_supply_chain.sh",
            "scripts/check_dependency_mirror_contract.sh"
          ],
          "completed_date": "2026-07-16",
          "input_identity": "runtime-cycle-collection-sha256:a4f4c5a327fc6f9408aec3a4a4dad890996216d3009875da351efb08af580587"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R2.2.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Prove structural cycle prevention or add deterministic cycle collection/tracing. Long-lived warm sessions may not leak recursive closures or host handles.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.2.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Prove structural cycle prevention or add deterministic cycle collection/tracing. Long-lived warm sessions may not leak recursive closures or host handles.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R0.2.h",
        "R2.2.a"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1058,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Choose and implement cycle handling",
      "unsatisfied_prerequisites": [],
      "workstream": "R2.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test --workspace --all-targets --locked --offline",
            "cargo clippy -p gc_kernel -p gc_pkg -p gc_prelude -p gc_obligations -p gc_cli_driver --all-targets --locked --offline -- -D warnings",
            "scripts/check_kernel_tcb_contract.sh",
            "scripts/check_no_user_panics.sh",
            "scripts/check_source_decomposition_progress.sh"
          ],
          "completed_date": "2026-07-17",
          "input_identity": "logical-resource-metering-sha256:5b6f83aafca9f05d5624cc204af6feef0e39d8e29fe0bc72469d7bd24b995c2f"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R2.2.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Charge deterministic logical units independent of allocator internals; expose policy limits and sealed exhaustion errors.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.2.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Charge deterministic logical units independent of allocator internals; expose policy limits and sealed exhaustion errors.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R0.2.h",
        "R2.2.b"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1060,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Add allocation and heap metering",
      "unsatisfied_prerequisites": [],
      "workstream": "R2.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test --workspace --all-targets --locked --offline",
            "cargo clippy -p gc_kernel -p gc_cli_driver -p gc_cli --all-targets --locked --offline -- -D warnings",
            "scripts/check_warm_protocol_contract.sh",
            "scripts/check_kernel_tcb_contract.sh",
            "scripts/check_no_user_panics.sh"
          ],
          "completed_date": "2026-07-17",
          "input_identity": "oom-containment-bundle-sha256:fbff64649b3109767f8ec5a8963f9dcf9902084c2dff5a4d5d9e73c109f3ed4c"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R2.2.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Preflight bounded allocations where possible, catch recoverable host allocation failures, and isolate workloads so an untrusted program cannot terminate the daemon.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.2.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Preflight bounded allocations where possible, catch recoverable host allocation failures, and isolate workloads so an untrusted program cannot terminate the daemon.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R0.2.h",
        "R2.2.c"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1062,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Define out-of-memory behavior",
      "unsatisfied_prerequisites": [],
      "workstream": "R2.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test -p gc_kernel --lib --locked --offline",
            "cargo test -p gc_cli --test persistent_sharing_stress --locked --offline",
            "bash scripts/test_perf_gates.sh --test persistent_sharing_stress",
            "cargo clippy -p gc_kernel -p gc_cli --all-targets --locked --offline -- -D warnings",
            "scripts/check_kernel_tcb_contract.sh"
          ],
          "completed_date": "2026-07-17",
          "input_identity": "persistent-sharing-bounds-sha256:a893c104ed9ad1bf6e85ff894427295c4078f4c6befcf85bda2cbd5111623a54"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R2.2.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Add stress tests for adversarial update chains, retained roots, maps/vectors/strings, package graphs, logs, and snapshots.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.2.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Add stress tests for adversarial update chains, retained roots, maps/vectors/strings, package graphs, logs, and snapshots.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R0.2.h",
        "R2.2.d"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1065,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Bound persistent sharing",
      "unsatisfied_prerequisites": [],
      "workstream": "R2.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "31456950564",
            "31456839013",
            "release_evidence_execution.py verify-aggregate"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "host-handle-lifecycle-closure-sha256:f8dd0073bf8820d3a2935bab30f0858781b0dd5021b63e8af69a114b3a022327"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_cli",
          "crates/gc_cli_driver",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R2.2.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Files, sockets, processes, bridges, graphics, GPU, and model sessions close on success, malformed response, disconnection, error, cancellation, timeout, owner drop, and daemon restart; any failed stop, join, reap, or residual-group verification crosses the public boundary as a typed cleanup failure rather than being discarded.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_host_bridge_fault_injection.sh",
        "scripts/check_no_user_panics.sh",
        "scripts/check_host_abi_conformance.sh"
      ],
      "id": "R2.2.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject discarded cleanup failures, surviving descendants, detached I/O pumps, cooperative-only cancellation, producer-authored closure, and cross-host lifecycle identity drift"
      ],
      "objective": "Files, sockets, processes, bridges, graphics, GPU, and model sessions close on success, malformed response, disconnection, error, cancellation, timeout, owner drop, and daemon restart; any failed stop, join, reap, or residual-group verification crosses the public boundary as a typed cleanup failure rather than being discarded.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_cli",
        "crates/gc_cli_driver",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R0.2.h",
        "R2.2.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1067,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Prove host-handle cleanup",
      "unsatisfied_prerequisites": [],
      "workstream": "R2.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_kernel",
          "crates/gc_obligations",
          "crates/gc_prelude",
          "prelude",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Version and hash the compiled Prelude/environment plus separately addressable frontend, type/effect, patch/refactor, package/VCS, compiler, and orchestration self-host components. A closed composition manifest binds exact component, dependency, semantic-profile, target, and stage0 identities; commands load only the components in their declared dependency closure, rebuild every component from source reproducibly, and reject wrong, missing, duplicate, reordered, cyclic, platform-incompatible, or profile-incompatible identities. A combined artifact may remain a distribution envelope, but it cannot force unrelated parse/fmt/hash commands to initialize the typechecker or another unused authority.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_artifact_fresh.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.3.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject component identity or dependency drift, monolithic unrelated-command loading, cache-dependent semantics, source/snapshot divergence, profile confusion, unbounded validation, and startup improvements obtained by skipping required authority checks"
      ],
      "objective": "Version and hash the compiled Prelude/environment plus separately addressable frontend, type/effect, patch/refactor, package/VCS, compiler, and orchestration self-host components. A closed composition manifest binds exact component, dependency, semantic-profile, target, and stage0 identities; commands load only the components in their declared dependency closure, rebuild every component from source reproducibly, and reject wrong, missing, duplicate, reordered, cyclic, platform-incompatible, or profile-incompatible identities. A combined artifact may remain a distribution envelope, but it cannot force unrelated parse/fmt/hash commands to initialize the typechecker or another unused authority.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_kernel",
        "crates/gc_obligations",
        "crates/gc_prelude",
        "prelude",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R2.1.h",
        "R2.2.f"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1083,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Build deterministic component snapshots",
      "unsatisfied_prerequisites": [
        "R2.1.h"
      ],
      "workstream": "R2.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_kernel",
          "crates/gc_obligations",
          "crates/gc_prelude",
          "prelude",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.2.f",
          "R2.3.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Attribute process creation and dynamic loading, per-component self-host artifact loading, catalog/card/schema loading, Prelude construction, snapshot validation, cycle-collector initialization, evaluator-only `fib(25)`, and teardown separately under cold and warm profiles; reconcile these measurements with R2.1.h's signed PB-1 distribution. Measure unrelated-command working-set and latency deltas when each semantic authority is added, and reject dependency-theater loading or a monolithic snapshot that hides those costs. Remove or defer nonessential work before adding caches. Load deterministic snapshots with bounded validation and no semantic dependence on cache state; preserve a source-bootstrap mode for verification and prove both modes agree. Ratchet PB-1/PB-6 only from conformant retained samples and never relabel runtime regression as startup improvement.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_artifact_fresh.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.3.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject component identity or dependency drift, monolithic unrelated-command loading, cache-dependent semantics, source/snapshot divergence, profile confusion, unbounded validation, and startup improvements obtained by skipping required authority checks"
      ],
      "objective": "Attribute process creation and dynamic loading, per-component self-host artifact loading, catalog/card/schema loading, Prelude construction, snapshot validation, cycle-collector initialization, evaluator-only `fib(25)`, and teardown separately under cold and warm profiles; reconcile these measurements with R2.1.h's signed PB-1 distribution. Measure unrelated-command working-set and latency deltas when each semantic authority is added, and reject dependency-theater loading or a monolithic snapshot that hides those costs. Remove or defer nonessential work before adding caches. Load deterministic snapshots with bounded validation and no semantic dependence on cache state; preserve a source-bootstrap mode for verification and prove both modes agree. Ratchet PB-1/PB-6 only from conformant retained samples and never relabel runtime regression as startup improvement.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_kernel",
        "crates/gc_obligations",
        "crates/gc_prelude",
        "prelude",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R2.1.h",
        "R2.2.f",
        "R2.3.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1084,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Meet PB-6 and reverse startup/PB-1 drift",
      "unsatisfied_prerequisites": [
        "R2.1.h",
        "R2.3.a"
      ],
      "workstream": "R2.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.2.f",
          "R2.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Cache parse, canonicalization, type/effect inference, obligations, compiled AST, and tests by complete semantic inputs.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.3.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Cache parse, canonicalization, type/effect inference, obligations, compiled AST, and tests by complete semantic inputs.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R2.1.h",
        "R2.2.f",
        "R2.3.b"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1085,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Content-address frontend stages",
      "unsatisfied_prerequisites": [
        "R2.1.h",
        "R2.3.b"
      ],
      "workstream": "R2.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.2.f",
          "R2.3.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Track imports, capability schemas, contracts, profile versions, and generated cards. Negative tests prove stale results cannot be reused.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.3.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Track imports, capability schemas, contracts, profile versions, and generated cards. Negative tests prove stale results cannot be reused.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R2.1.h",
        "R2.2.f",
        "R2.3.c"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1086,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add precise invalidation",
      "unsatisfied_prerequisites": [
        "R2.1.h",
        "R2.3.c"
      ],
      "workstream": "R2.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.2.f",
          "R2.3.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Incremental check/test and symbol/card retrieval meet AB-4 at 100 modules and have explicit SLOs at 10k modules.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.3.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Incremental check/test and symbol/card retrieval meet AB-4 at 100 modules and have explicit SLOs at 10k modules.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R2.1.h",
        "R2.2.f",
        "R2.3.d"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1087,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Optimize large workspaces",
      "unsatisfied_prerequisites": [
        "R2.1.h",
        "R2.3.d"
      ],
      "workstream": "R2.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R2.1.h"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Count calls, steps, allocations, collection operations, effects, and cache decisions without embedding host addresses or unstable clocks in artifacts.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.4.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Count calls, steps, allocations, collection operations, effects, and cache decisions without embedding host addresses or unstable clocks in artifacts.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R2.1.h"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1091,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add deterministic logical profiles",
      "unsatisfied_prerequisites": [
        "R2.1.h"
      ],
      "workstream": "R2.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.4.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Performance reports may include host time as metadata, but semantic logs and hashes remain deterministic.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.4.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Performance reports may include host time as metadata, but semantic logs and hashes remain deterministic.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R2.1.h",
        "R2.4.a"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1092,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Keep wall-clock telemetry out of replay identity",
      "unsatisfied_prerequisites": [
        "R2.1.h",
        "R2.4.a"
      ],
      "workstream": "R2.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "prelude",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.4.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Map profile sites back to stable module/term IDs and generate optimization suggestions that require evidence before application.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_runtime_workload_budgets.sh",
        "scripts/check_perf_budgets.sh"
      ],
      "id": "R2.4.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject tier divergence, resource-accounting bypass, host leaks, unbounded allocation, user-reachable panic, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Map profile sites back to stable module/term IDs and generate optimization suggestions that require evidence before application.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "prelude",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R2",
      "prerequisites": [
        "R2.1.h",
        "R2.4.b"
      ],
      "resource_class": "benchmark",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1093,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Provide explainable hot paths",
      "unsatisfied_prerequisites": [
        "R2.1.h",
        "R2.4.b"
      ],
      "workstream": "R2.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Define instructions, constants, frames, closures, tail calls, spans, resource charges, serialization, validation, and compatibility/migration.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.1.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "Define instructions, constants, frames, closures, tail calls, spans, resource charges, serialization, validation, and compatibility/migration.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.1.h",
        "R2.2.f"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1105,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Specify a versioned bytecode",
      "unsatisfied_prerequisites": [
        "R2.1.h"
      ],
      "workstream": "R3.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.2.f",
          "R3.1.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Reject malformed control flow, stack/type errors, invalid constants, out-of-range indices, forged seals, unsupported effects, oversized artifacts, and version confusion before execution.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.1.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "Reject malformed control flow, stack/type errors, invalid constants, out-of-range indices, forged seals, unsupported effects, oversized artifacts, and version confusion before execution.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.1.h",
        "R2.2.f",
        "R3.1.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1106,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Implement an independent verifier",
      "unsatisfied_prerequisites": [
        "R2.1.h",
        "R3.1.a"
      ],
      "workstream": "R3.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.2.f",
          "R3.1.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "The bytecode producer and optimizer are untrusted; only verified artifacts execute, and authoritative semantics remain comparison oracle.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.1.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "The bytecode producer and optimizer are untrusted; only verified artifacts execute, and authoritative semantics remain comparison oracle.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.1.h",
        "R2.2.f",
        "R3.1.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1107,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Build the VM outside TCB-A",
      "unsatisfied_prerequisites": [
        "R2.1.h",
        "R3.1.b"
      ],
      "workstream": "R3.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.2.f",
          "R3.1.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Step/allocation/effect/heap budgets map to documented logical units; tier switching cannot evade a limit.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.1.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "Step/allocation/effect/heap budgets map to documented logical units; tier switching cannot evade a limit.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.1.h",
        "R2.2.f",
        "R3.1.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1108,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Match resource semantics",
      "unsatisfied_prerequisites": [
        "R2.1.h",
        "R3.1.c"
      ],
      "workstream": "R3.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.2.f",
          "R3.1.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Generate and mutate pure/effectful programs; compare values, canonical hashes, sealed errors, logs, scheduling, and limits across treewalk, compiled AST, and bytecode.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.1.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "Generate and mutate pure/effectful programs; compare values, canonical hashes, sealed errors, logs, scheduling, and limits across treewalk, compiled AST, and bytecode.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.1.h",
        "R2.2.f",
        "R3.1.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1109,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add complete differential coverage",
      "unsatisfied_prerequisites": [
        "R2.1.h",
        "R3.1.d"
      ],
      "workstream": "R3.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.2.f",
          "R3.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Publish workload-normalized samples and regression thresholds without compromising PB-9.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.1.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "Publish workload-normalized samples and regression thresholds without compromising PB-9.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.1.h",
        "R2.2.f",
        "R3.1.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1110,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Meet PB-2",
      "unsatisfied_prerequisites": [
        "R2.1.h",
        "R3.1.e"
      ],
      "workstream": "R3.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Generate a per-form/per-primitive/per-effect matrix and replace unsupported silent fallback with explicit profile negotiation or failure.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.2.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "Generate a per-form/per-primitive/per-effect matrix and replace unsupported silent fallback with explicit profile negotiation or failure.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.1.h",
        "R2.2.f"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1114,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Audit existing `wasmi` coverage",
      "unsatisfied_prerequisites": [
        "R2.1.h"
      ],
      "workstream": "R3.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.2.f",
          "R3.2.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Compare source/CoreForm semantics with emitted module behavior and independently validate embedded source/artifact hashes.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.2.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "Compare source/CoreForm semantics with emitted module behavior and independently validate embedded source/artifact hashes.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.1.h",
        "R2.2.f",
        "R3.2.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1115,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Validate translation",
      "unsatisfied_prerequisites": [
        "R2.1.h",
        "R3.2.a"
      ],
      "workstream": "R3.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.2.f",
          "R3.2.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "WASI imports and host functions use the same deny-by-default policy, path normalization, cancellation, payload, and log contracts.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.2.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "WASI imports and host functions use the same deny-by-default policy, path normalization, cancellation, payload, and log contracts.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.1.h",
        "R2.2.f",
        "R3.2.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1116,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Unify resource/capability enforcement",
      "unsatisfied_prerequisites": [
        "R2.1.h",
        "R3.2.b"
      ],
      "workstream": "R3.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.1.h",
          "R2.2.f",
          "R3.2.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Mutate modules, imports, memories, tables, traps, resource limits, and host responses; no malformed artifact reaches a panic or capability bypass.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.2.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "Mutate modules, imports, memories, tables, traps, resource limits, and host responses; no malformed artifact reaches a panic or capability bypass.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.1.h",
        "R2.2.f",
        "R3.2.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1117,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Fuzz the boundary",
      "unsatisfied_prerequisites": [
        "R2.1.h",
        "R3.2.c"
      ],
      "workstream": "R3.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.4.c",
          "R3.1.f",
          "R3.2.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Rewrites are pure, versioned, independently testable, and disabled when their proof/precondition cannot be established.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.3.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "Rewrites are pure, versioned, independently testable, and disabled when their proof/precondition cannot be established.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.4.c",
        "R3.1.f",
        "R3.2.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1121,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Give every rewrite an identity and precondition",
      "unsatisfied_prerequisites": [
        "R2.4.c",
        "R3.1.f",
        "R3.2.d"
      ],
      "workstream": "R3.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.4.c",
          "R3.1.f",
          "R3.2.d",
          "R3.3.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Use equivalence checks, property tests, replay comparison, and bounded proof methods appropriate to the unit; fall back safely on uncertainty.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.3.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "Use equivalence checks, property tests, replay comparison, and bounded proof methods appropriate to the unit; fall back safely on uncertainty.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.4.c",
        "R3.1.f",
        "R3.2.d",
        "R3.3.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1122,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Translation-validate optimized units",
      "unsatisfied_prerequisites": [
        "R2.4.c",
        "R3.1.f",
        "R3.2.d",
        "R3.3.a"
      ],
      "workstream": "R3.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.4.c",
          "R3.1.f",
          "R3.2.d",
          "R3.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Inputs are deterministic logical profiles and versioned thresholds, not hidden wall-clock races. Record decisions outside semantic identity where appropriate.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.3.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "Inputs are deterministic logical profiles and versioned thresholds, not hidden wall-clock races. Record decisions outside semantic identity where appropriate.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.4.c",
        "R3.1.f",
        "R3.2.d",
        "R3.3.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1123,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Make tier decisions reproducible",
      "unsatisfied_prerequisites": [
        "R2.4.c",
        "R3.1.f",
        "R3.2.d",
        "R3.3.b"
      ],
      "workstream": "R3.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.4.c",
          "R3.1.f",
          "R3.2.d",
          "R3.3.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Unsupported or failed optimization returns to a verified lower tier without duplicated effects or changed errors.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.3.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "Unsupported or failed optimization returns to a verified lower tier without duplicated effects or changed errors.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.4.c",
        "R3.1.f",
        "R3.2.d",
        "R3.3.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1124,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add deoptimization/fallback tests",
      "unsatisfied_prerequisites": [
        "R2.4.c",
        "R3.1.f",
        "R3.2.d",
        "R3.3.c"
      ],
      "workstream": "R3.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.3.e",
          "R3.3.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Use flagship and agent workloads, not only `fib`, to determine whether bytecode/snapshot/warm execution misses v1 latency or throughput SLOs.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.4.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "Use flagship and agent workloads, not only `fib`, to determine whether bytecode/snapshot/warm execution misses v1 latency or throughput SLOs.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.3.e",
        "R3.3.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1128,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Measure the product gap after R2/R3",
      "unsatisfied_prerequisites": [
        "R2.3.e",
        "R3.3.d"
      ],
      "workstream": "R3.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.3.e",
          "R3.3.d",
          "R3.4.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Compare no JIT, Wasmtime/Cranelift, native AOT, and specialization by binary size, startup, platform reach, memory, compile time, trust, maintenance, and measured gain.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.4.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "Compare no JIT, Wasmtime/Cranelift, native AOT, and specialization by binary size, startup, platform reach, memory, compile time, trust, maintenance, and measured gain.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.3.e",
        "R3.3.d",
        "R3.4.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1129,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Write an architecture decision record",
      "unsatisfied_prerequisites": [
        "R2.3.e",
        "R3.3.d",
        "R3.4.a"
      ],
      "workstream": "R3.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.3.e",
          "R3.3.d",
          "R3.4.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "A JIT is feature-gated, optional on constrained targets, translation-validated, sandboxed, and excluded from canonical outputs. Bytecode and `wasmi` remain complete fallbacks.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.4.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "A JIT is feature-gated, optional on constrained targets, translation-validated, sandboxed, and excluded from canonical outputs. Bytecode and `wasmi` remain complete fallbacks.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.3.e",
        "R3.3.d",
        "R3.4.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1130,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Implement only if justified",
      "unsatisfied_prerequisites": [
        "R2.3.e",
        "R3.3.d",
        "R3.4.b"
      ],
      "workstream": "R3.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_effects",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "crates/gc_wasi_cli",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R2.3.e",
          "R3.3.d",
          "R3.4.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Include code-cache integrity, W^X, architecture fuzzing, deterministic tier decisions, and safe deoptimization.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_wasm_production_surface.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_fuzz_differential_hardening.sh"
      ],
      "id": "R3.4.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject malformed artifacts, undeclared fallback, duplicated effects, forged seals, and optimizer-only success"
      ],
      "objective": "Include code-cache integrity, W^X, architecture fuzzing, deterministic tier decisions, and safe deoptimization.",
      "owner_paths": [
        "crates/gc_effects",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "crates/gc_wasi_cli",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R3",
      "prerequisites": [
        "R2.3.e",
        "R3.3.d",
        "R3.4.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1131,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "If implemented, meet PB-3",
      "unsatisfied_prerequisites": [
        "R2.3.e",
        "R3.3.d",
        "R3.4.c"
      ],
      "workstream": "R3.4"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_selfhost_boundary.sh --strict",
            "scripts/check_selfhost_readiness_scorecard.sh",
            "scripts/check_source_decomposition_progress.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "stage0-trust-contract-sha256:9e59cb97538ffbb39156085a1e71997ba00f759c277a51724527795ac6f31651"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.f",
          "R0.2.h"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Keep TCB-A limited to the pure evaluator, immutable values/primitives, and seal machinery. Enumerate bytecode/artifact verification and the effect-host ABI as separate, explicitly layered trust domains; state exactly which host semantics remain trusted and why.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.1.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "Keep TCB-A limited to the pure evaluator, immutable values/primitives, and seal machinery. Enumerate bytecode/artifact verification and the effect-host ABI as separate, explicitly layered trust domains; state exactly which host semantics remain trusted and why.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R0.1.f",
        "R0.2.h"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1145,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Publish the stage0 contract",
      "unsatisfied_prerequisites": [],
      "workstream": "R4.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_selfhost_boundary.sh --strict",
            "scripts/check_selfhost_readiness_scorecard.sh",
            "scripts/check_source_decomposition_progress.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "selfhost-closure-levels-sha256:93c437824ac6d5a8f6b022f66b898b0cca8d56ef317a99db710fe8ecb53eebdc"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.f",
          "R0.2.h",
          "R4.1.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "`H0 routed`, `H1 GenesisCode implementation`, `H2 GenesisCode production authority`, `H3 reproducible bootstrap fixpoint`, `H4 independently reimplemented/conformant`.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.1.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "`H0 routed`, `H1 GenesisCode implementation`, `H2 GenesisCode production authority`, `H3 reproducible bootstrap fixpoint`, `H4 independently reimplemented/conformant`.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R0.1.f",
        "R0.2.h",
        "R4.1.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1147,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Define closure levels",
      "unsatisfied_prerequisites": [],
      "workstream": "R4.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_selfhost_boundary.sh --strict",
            "scripts/check_selfhost_readiness_scorecard.sh",
            "scripts/check_source_decomposition_progress.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "semantic-ownership-ledger-sha256:3e1ae2f6d6bf0e2565712de4c177f9067f692aa72f2181febd7e79d054a2145b"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.f",
          "R0.2.h",
          "R4.1.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "For every command and semantic decision, name spec authority, producing implementation, production authority, host binding, verifier, fallback reachability, tests, and H-level.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.1.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "For every command and semantic decision, name spec authority, producing implementation, production authority, host binding, verifier, fallback reachability, tests, and H-level.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R0.1.f",
        "R0.2.h",
        "R4.1.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1149,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Build a semantic-ownership ledger",
      "unsatisfied_prerequisites": [],
      "workstream": "R4.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_selfhost_boundary.sh --strict",
            "scripts/check_selfhost_readiness_scorecard.sh",
            "scripts/check_source_decomposition_progress.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "semantic-ownership-ledger-sha256:3e1ae2f6d6bf0e2565712de4c177f9067f692aa72f2181febd7e79d054a2145b"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.f",
          "R0.2.h",
          "R4.1.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "`SELFHOST_CUTOVER`, module-boundary migration tables, scorecards, and dashboards must never equate a `.gc` wrapper or route with H2/H3 closure.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.1.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "`SELFHOST_CUTOVER`, module-boundary migration tables, scorecards, and dashboards must never equate a `.gc` wrapper or route with H2/H3 closure.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R0.1.f",
        "R0.2.h",
        "R4.1.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1151,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Correct status documents",
      "unsatisfied_prerequisites": [],
      "workstream": "R4.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_selfhost_boundary.sh --strict",
            "scripts/check_selfhost_readiness_scorecard.sh",
            "scripts/check_source_decomposition_progress.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "stage0-dependency-boundary-sha256:379d9a5a41c886829413ed3010d681a3d12bbff70c98a4978ada9c2326f2574c"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.1.f",
          "R0.2.h",
          "R4.1.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Crate dependency rules prevent stage0 from importing CLI, package, registry, optimizer, self-host frontend, or ambient effect semantics.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.1.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "Crate dependency rules prevent stage0 from importing CLI, package, registry, optimizer, self-host frontend, or ambient effect semantics.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R0.1.f",
        "R0.2.h",
        "R4.1.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1153,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Enforce the boundary structurally",
      "unsatisfied_prerequisites": [],
      "workstream": "R4.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test -p gc_cli_driver frontend_hash_transport_requires_canonical_lowercase_hex -- --nocapture",
            "cargo test -p gc_obligations selfhost_frontend -- --nocapture",
            "scripts/selfhost_frontend_authority_guard.sh",
            "scripts/check_selfhost_boundary.sh --strict",
            "scripts/check_selfhost_readiness_scorecard.sh",
            "scripts/check_source_decomposition_progress.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "selfhost-frontend-authority-sha256:763f89ec2fa28eecc628130cf3a996dd490a4e18cdd2ba7455fd349502c6be39"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts",
          "crates/gc_cli/Cargo.toml",
          "crates/gc_cli/tests",
          "crates/gc_wasi_cli/Cargo.toml"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R5.1.e",
          "R5.3.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Source parsing, formatting, source-to-CoreForm lowering/printing, frontend module identity/hash, exact source spans, and the production frontend profile become GenesisCode-produced with a minimal independent verifier for those identity-critical frontend artifacts. Non-frontend canonical term, VCS, semantic-patch, package, compiled, and bootstrap artifact identities remain assigned to their later authority and bootstrap tasks.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.2.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "Source parsing, formatting, source-to-CoreForm lowering/printing, frontend module identity/hash, exact source spans, and the production frontend profile become GenesisCode-produced with a minimal independent verifier for those identity-critical frontend artifacts. Non-frontend canonical term, VCS, semantic-patch, package, compiled, and bootstrap artifact identities remain assigned to their later authority and bootstrap tasks.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts",
        "crates/gc_cli/Cargo.toml",
        "crates/gc_cli/tests",
        "crates/gc_wasi_cli/Cargo.toml"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R5.1.e",
        "R5.3.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1160,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Frontend source canonicalization",
      "unsatisfied_prerequisites": [],
      "workstream": "R4.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test -p gc_types inferred_record_rows_only_promote_parseable_symbol_labels",
            "cargo test -p gc_obligations --features parity-oracle selfhost_typecheck_matches_real_failure_corpus_regressions -- --nocapture",
            "scripts/check_selfhost_artifact_fresh.sh",
            "scripts/selfhost_typecheck_authority_guard.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "selfhost-typecheck-authority-sha256:6fad624ec15f652dad561cd8b332e7f1aa87560d396568bd9cb0281c167313a4"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_obligations",
          "crates/gc_prelude",
          "crates/gc_types",
          "crates/gc_wasi_cli",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts",
          "tests",
          "crates/gc_cli/Cargo.toml",
          "crates/gc_cli/tests",
          "crates/gc_wasi_cli/Cargo.toml"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R5.1.e",
          "R5.3.e",
          "R4.2.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [
          "docs/spec/SELFHOST_TYPECHECK_AUTHORITY_v0.1.md",
          "policies/selfhost_typecheck_authority_v0.1.json",
          "scripts/lib/selfhost_typecheck_authority.py",
          "scripts/selfhost_typecheck_authority_guard.sh",
          "scripts/check_selfhost_boundary.sh"
        ],
        "deliverable": "Publish the normative decision inventory and closed authority contract in `docs/spec/SELFHOST_TYPECHECK_AUTHORITY_v0.1.md`, its machine profile in `policies/selfhost_typecheck_authority_v0.1.json`, the independent static verifier in `scripts/lib/selfhost_typecheck_authority.py`, and the native/WASI runtime harness at `scripts/selfhost_typecheck_authority_guard.sh`. Bind the static verifier into the governed `scripts/check_selfhost_boundary.sh` execution-profile gate and run the runtime harness before closure, because generic readiness/decomposition observations cannot authorize the switch. The inventory covers every production call site and observable fact for constraint generation, type constructors and compatibility, row/effect polymorphism, typed and syntactic effect inference, contracts and blame, unknown imported signatures, package context/exports, deterministic module resolution, contract composition, profile negotiation/migration, diagnostics and repair identities, capability summaries, ABI generation, determinism obligations, incremental dependency keys/invalidation, native/WASI routes, and resource accounting. Execute the normative pipeline in one frozen order equivalent to context collection -> profile negotiation -> contract composition -> module resolution -> module checking; bind each response to the exact ordered request module set, paths, forms/meta identities, profile offer, checker artifact, and semantic-profile identities. Decoders reject omitted, extra, duplicate, renamed, or reordered modules; duplicate or undeclared exports; nonclosed schemas; contradictory aggregate/module/export/profile `:ok` and error facts; incoherent active/identity/requirements/selection profile reports; and any missing report rather than synthesizing empty effects, gradual types, or `unknown=false`. Incremental results use complete content-addressed semantic inputs and are byte-equivalent to clean full recomputation after source, import, contract, capability, profile, card/schema, or dependency changes; stale, partial, cross-profile, and cyclic state fails closed. Differential coverage spans the complete normative corpus and generated/property cases, with minimized permanent counterexamples and mutations for malformed constructors/rows/contracts, shadowing, imported signatures, report tampering, request/report inventory attacks, resource exhaustion, and restored fallback. Native and WASI production observations agree on canonical reports, diagnostics, hashes, limits, and failure behavior. The independent verifier consumes the closed request/report bundle without `gc_types`, the producing self-host artifact, or mutable cache state. Rust checker code is removed from production dependencies or isolated in a compile-time parity-only crate/binary with no ordinary library setter, environment flag, CLI route, obligation path, ABI path, or release-graph reachability; no Rust effect inference or report default remains hidden outside the named oracle. Record checker and unrelated-command cold/warm latency, peak RSS, artifact size, step/allocation bounds, and component-loading closure; meet existing budgets or assign optimization to R2.3 without claiming authority completion. The task cannot close until every manifest-listed production `.gc` source is discovered by the decomposition guard, unknown over-budget files fail, each module is within the budget or has a bounded non-expired waiver, all declared authority artifacts are fresh, and the ledger reaches H2 for the exact type/effect decision set. Rust then remains only an independently invoked oracle for a bounded compatibility window or is removed.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh",
        "scripts/check_selfhost_artifact_fresh.sh",
        "scripts/check_selfhost_doc_runtime_parity.sh",
        "scripts/check_selfhost_symbol_ownership.sh"
      ],
      "id": "R4.2.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject request/report module or export inventory drift, contradictory report facts, profile incoherence, stale incremental results, hidden Rust type/effect decisions, ordinary-build oracle reachability, cross-target divergence, unbounded checker resources, unrelated-command artifact-loading regressions, and decomposition coverage that omits manifest-listed GenesisCode sources"
      ],
      "objective": "Publish the normative decision inventory and closed authority contract in `docs/spec/SELFHOST_TYPECHECK_AUTHORITY_v0.1.md`, its machine profile in `policies/selfhost_typecheck_authority_v0.1.json`, the independent static verifier in `scripts/lib/selfhost_typecheck_authority.py`, and the native/WASI runtime harness at `scripts/selfhost_typecheck_authority_guard.sh`. Bind the static verifier into the governed `scripts/check_selfhost_boundary.sh` execution-profile gate and run the runtime harness before closure, because generic readiness/decomposition observations cannot authorize the switch. The inventory covers every production call site and observable fact for constraint generation, type constructors and compatibility, row/effect polymorphism, typed and syntactic effect inference, contracts and blame, unknown imported signatures, package context/exports, deterministic module resolution, contract composition, profile negotiation/migration, diagnostics and repair identities, capability summaries, ABI generation, determinism obligations, incremental dependency keys/invalidation, native/WASI routes, and resource accounting. Execute the normative pipeline in one frozen order equivalent to context collection -> profile negotiation -> contract composition -> module resolution -> module checking; bind each response to the exact ordered request module set, paths, forms/meta identities, profile offer, checker artifact, and semantic-profile identities. Decoders reject omitted, extra, duplicate, renamed, or reordered modules; duplicate or undeclared exports; nonclosed schemas; contradictory aggregate/module/export/profile `:ok` and error facts; incoherent active/identity/requirements/selection profile reports; and any missing report rather than synthesizing empty effects, gradual types, or `unknown=false`. Incremental results use complete content-addressed semantic inputs and are byte-equivalent to clean full recomputation after source, import, contract, capability, profile, card/schema, or dependency changes; stale, partial, cross-profile, and cyclic state fails closed. Differential coverage spans the complete normative corpus and generated/property cases, with minimized permanent counterexamples and mutations for malformed constructors/rows/contracts, shadowing, imported signatures, report tampering, request/report inventory attacks, resource exhaustion, and restored fallback. Native and WASI production observations agree on canonical reports, diagnostics, hashes, limits, and failure behavior. The independent verifier consumes the closed request/report bundle without `gc_types`, the producing self-host artifact, or mutable cache state. Rust checker code is removed from production dependencies or isolated in a compile-time parity-only crate/binary with no ordinary library setter, environment flag, CLI route, obligation path, ABI path, or release-graph reachability; no Rust effect inference or report default remains hidden outside the named oracle. Record checker and unrelated-command cold/warm latency, peak RSS, artifact size, step/allocation bounds, and component-loading closure; meet existing budgets or assign optimization to R2.3 without claiming authority completion. The task cannot close until every manifest-listed production `.gc` source is discovered by the decomposition guard, unknown over-budget files fail, each module is within the budget or has a bounded non-expired waiver, all declared authority artifacts are fresh, and the ledger reaches H2 for the exact type/effect decision set. Rust then remains only an independently invoked oracle for a bounded compatibility window or is removed.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_obligations",
        "crates/gc_prelude",
        "crates/gc_types",
        "crates/gc_wasi_cli",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts",
        "tests",
        "crates/gc_cli/Cargo.toml",
        "crates/gc_cli/tests",
        "crates/gc_wasi_cli/Cargo.toml"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R5.1.e",
        "R5.3.e",
        "R4.2.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1162,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Type and effect checker authority",
      "unsatisfied_prerequisites": [],
      "workstream": "R4.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test -p gc_cli --features parity-harness --test cli_typecheck_apply_patch_engine apply_patch_selfhost_frontend_matches_rust_frontend_artifacts --locked --offline --quiet",
            "scripts/selfhost_patch_authority_guard.sh",
            "scripts/selfhost_typecheck_authority_guard.sh",
            "scripts/check_selfhost_boundary.sh --strict",
            "scripts/check_selfhost_readiness_scorecard.sh",
            "scripts/check_source_decomposition_progress.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "selfhost-patch-authority-sha256:de3f539333313b3019c2bbea6a73fdd57612241751d537e4380d5b783365861d"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts",
          "crates/gc_cli/Cargo.toml",
          "crates/gc_cli/tests",
          "crates/gc_wasi_cli/Cargo.toml"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R5.1.e",
          "R5.3.e",
          "R4.2.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Semantic diff/apply/merge, preconditions, conflict explanations, patch minimization, and semantic-patch canonical identities become GenesisCode-authoritative; patch identity ownership cannot remain attributed to completed R4.2.a.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.2.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "Semantic diff/apply/merge, preconditions, conflict explanations, patch minimization, and semantic-patch canonical identities become GenesisCode-authoritative; patch identity ownership cannot remain attributed to completed R4.2.a.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts",
        "crates/gc_cli/Cargo.toml",
        "crates/gc_cli/tests",
        "crates/gc_wasi_cli/Cargo.toml"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R5.1.e",
        "R5.3.e",
        "R4.2.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1164,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Patch and refactor engine",
      "unsatisfied_prerequisites": [],
      "workstream": "R4.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "python3 scripts/lib/selfhost_evidence_verify_authority.py --root . --profile policies/selfhost_evidence_verify_authority_v0.1.json --schema docs/spec/SELFHOST_EVIDENCE_VERIFY_AUTHORITY_v0.1.schema.json --artifact selfhost/toolchain.gc --self-test",
            "bash scripts/test_fast_full.sh",
            "scripts/check_selfhost_boundary.sh",
            "scripts/check_selfhost_readiness_scorecard.sh",
            "scripts/check_source_decomposition_progress.sh"
          ],
          "completed_date": "2026-08-13",
          "input_identity": "selfhost-evidence-verify-authority-sha256:f226266c6cb496a3ffca74d7a6e8ea35a8afead1b0206f7541edba2609ec6596"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts",
          "crates/gc_cli/Cargo.toml",
          "crates/gc_cli/tests",
          "crates/gc_wasi_cli/Cargo.toml"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R5.1.e",
          "R5.3.e",
          "R4.2.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Obligation generation/evaluation and policy composition become GenesisCode-authored. Host code enforces already-authorized effects but does not invent policy outcomes.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.2.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "Obligation generation/evaluation and policy composition become GenesisCode-authored. Host code enforces already-authorized effects but does not invent policy outcomes.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts",
        "crates/gc_cli/Cargo.toml",
        "crates/gc_cli/tests",
        "crates/gc_wasi_cli/Cargo.toml"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R5.1.e",
        "R5.3.e",
        "R4.2.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1166,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Obligation and policy decision logic",
      "unsatisfied_prerequisites": [],
      "workstream": "R4.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts",
          "crates/gc_cli/Cargo.toml",
          "crates/gc_cli/tests",
          "crates/gc_wasi_cli/Cargo.toml"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R5.1.e",
          "R5.3.e",
          "R4.2.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Manifest/lock resolution, graph solving, evidence verification, publish decisions, snapshot/diff/merge, migration, and package/lock/VCS object canonical identities become GenesisCode-authoritative; no non-frontend identity remains attributed to completed R4.2.a.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.2.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "Manifest/lock resolution, graph solving, evidence verification, publish decisions, snapshot/diff/merge, migration, and package/lock/VCS object canonical identities become GenesisCode-authoritative; no non-frontend identity remains attributed to completed R4.2.a.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts",
        "crates/gc_cli/Cargo.toml",
        "crates/gc_cli/tests",
        "crates/gc_wasi_cli/Cargo.toml"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R5.1.e",
        "R5.3.e",
        "R4.2.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1199,
        "path": "ROADMAP.md"
      },
      "start_ready": true,
      "state": "open",
      "title": "Package, registry, and VCS logic",
      "unsatisfied_prerequisites": [],
      "workstream": "R4.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts",
          "crates/gc_cli/Cargo.toml",
          "crates/gc_cli/tests",
          "crates/gc_wasi_cli/Cargo.toml"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R5.1.e",
          "R5.3.e",
          "R3.1.f",
          "R3.2.d",
          "R3.3.d",
          "R4.2.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Bytecode/Wasm production, translation-validation orchestration, snapshots, target builds, and artifact manifests become GenesisCode-authored.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.2.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "Bytecode/Wasm production, translation-validation orchestration, snapshots, target builds, and artifact manifests become GenesisCode-authored.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts",
        "crates/gc_cli/Cargo.toml",
        "crates/gc_cli/tests",
        "crates/gc_wasi_cli/Cargo.toml"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R5.1.e",
        "R5.3.e",
        "R3.1.f",
        "R3.2.d",
        "R3.3.d",
        "R4.2.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1209,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Compiler, optimizer, linker, and builder",
      "unsatisfied_prerequisites": [
        "R3.1.f",
        "R3.2.d",
        "R3.3.d",
        "R4.2.e"
      ],
      "workstream": "R4.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts",
          "crates/gc_cli/Cargo.toml",
          "crates/gc_cli/tests",
          "crates/gc_wasi_cli/Cargo.toml"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R5.1.e",
          "R5.3.e",
          "R4.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Command dispatch, warm/MCP schemas, card/docs generation, gate planning, and release assembly run from self-host artifacts without hidden Rust command semantics.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.2.g",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "Command dispatch, warm/MCP schemas, card/docs generation, gate planning, and release assembly run from self-host artifacts without hidden Rust command semantics.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts",
        "crates/gc_cli/Cargo.toml",
        "crates/gc_cli/tests",
        "crates/gc_wasi_cli/Cargo.toml"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R5.1.e",
        "R5.3.e",
        "R4.2.f"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1210,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "CLI and agent orchestration",
      "unsatisfied_prerequisites": [
        "R4.2.f"
      ],
      "workstream": "R4.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_obligations",
          "crates/gc_patches",
          "crates/gc_prelude",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [
          "selfhost/toolchain_manifest.gc"
        ],
        "deliverable": "Decompose `gc_effects` and `gc_cli_driver` by generated capability/command interfaces and shrink them as R4.2 migrates authority; meet GB-7. Replace fixed-list decomposition coverage with closed discovery of every production Rust source plus every `.gc` source reachable from `selfhost/toolchain_manifest.gc` and other production package/component manifests. The guard rejects missing, duplicate, symlinked, escaping, unknown over-budget, or policy-untracked modules and reports the true repository maximum; generated, fixture, test, example, and vendored exclusions are explicit and mutation-tested. R4.2 tasks must repair coverage for their newly introduced modules before their own authority switch rather than deferring a false-green guard to this later cleanup task.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_source_decomposition_progress.sh",
        "scripts/check_source_decomposition_tracked_parity.sh",
        "scripts/check_selfhost_boundary.sh"
      ],
      "id": "R4.3.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject fixed-list false greens, omitted manifest-listed GenesisCode sources, unknown over-budget production modules, symlink or path escapes, unowned exclusions, stale parity rows, and a reported maximum smaller than the discovered production maximum"
      ],
      "objective": "Decompose `gc_effects` and `gc_cli_driver` by generated capability/command interfaces and shrink them as R4.2 migrates authority; meet GB-7. Replace fixed-list decomposition coverage with closed discovery of every production Rust source plus every `.gc` source reachable from `selfhost/toolchain_manifest.gc` and other production package/component manifests. The guard rejects missing, duplicate, symlinked, escaping, unknown over-budget, or policy-untracked modules and reports the true repository maximum; generated, fixture, test, example, and vendored exclusions are explicit and mutation-tested. R4.2 tasks must repair coverage for their newly introduced modules before their own authority switch rather than deferring a false-green guard to this later cleanup task.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_obligations",
        "crates/gc_patches",
        "crates/gc_prelude",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e"
      ],
      "resource_class": "static",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1214,
        "path": "ROADMAP.md"
      },
      "start_ready": true,
      "state": "open",
      "title": "Split oversized production modules and make coverage complete",
      "unsatisfied_prerequisites": [],
      "workstream": "R4.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R4.3.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "One schema produces Rust host bindings, Prelude wrappers, capability docs/cards, MCP schemas, codecs, and parity tests.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.3.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "One schema produces Rust host bindings, Prelude wrappers, capability docs/cards, MCP schemas, codecs, and parity tests.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R4.3.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1215,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Generate repetitive bridges",
      "unsatisfied_prerequisites": [
        "R4.3.a"
      ],
      "workstream": "R4.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R4.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Inventory FFI, process, dynamic library, WASI, GPU/UI, plugin, and model bridges; require capability and deterministic boundary contracts.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.3.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "Inventory FFI, process, dynamic library, WASI, GPU/UI, plugin, and model bridges; require capability and deterministic boundary contracts.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R4.3.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1216,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Audit all host escapes",
      "unsatisfied_prerequisites": [
        "R4.3.b"
      ],
      "workstream": "R4.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R4.3.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Delete or archive `old_bootstrap/` and obsolete Rust paths only after the release profile proves no production/test dependency and history preserves recovery instructions.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.3.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "Delete or archive `old_bootstrap/` and obsolete Rust paths only after the release profile proves no production/test dependency and history preserves recovery instructions.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R4.3.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1217,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Remove legacy authorities",
      "unsatisfied_prerequisites": [
        "R4.3.c"
      ],
      "workstream": "R4.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_coreform",
          "crates/gc_kernel",
          "crates/gc_prelude",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Stage0 builds stage1 from pinned source; stage1 builds stage2; stage2 builds stage3. Define and independently verify canonical self-host source, component, composition, compiled, and bootstrap artifact identities plus admission rules; these non-frontend identities are not inherited from R4.2.a. Compare canonical artifacts and explain every intentionally host-specific envelope field.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_artifact_fresh.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_selfhost_readiness_scorecard.sh"
      ],
      "id": "R4.4.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject inherited frontend identity claims for non-frontend artifacts, unbound component or composition identities, host-specific envelope facts presented as canonical, unverified admission, bootstrap stage confusion, and a widened stage0 trust boundary"
      ],
      "objective": "Stage0 builds stage1 from pinned source; stage1 builds stage2; stage2 builds stage3. Define and independently verify canonical self-host source, component, composition, compiled, and bootstrap artifact identities plus admission rules; these non-frontend identities are not inherited from R4.2.a. Compare canonical artifacts and explain every intentionally host-specific envelope field.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_coreform",
        "crates/gc_kernel",
        "crates/gc_prelude",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1221,
        "path": "ROADMAP.md"
      },
      "start_ready": true,
      "state": "open",
      "title": "Define stages and bootstrap artifact identity",
      "unsatisfied_prerequisites": [],
      "workstream": "R4.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R4.4.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Pin source, dependencies, profiles, environment, locale, paths, ordering, numeric behavior, and timestamps. Normalize or exclude nondeterministic container metadata.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.4.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "Pin source, dependencies, profiles, environment, locale, paths, ordering, numeric behavior, and timestamps. Normalize or exclude nondeterministic container metadata.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R4.4.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1222,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Make builds hermetic",
      "unsatisfied_prerequisites": [
        "R4.4.a"
      ],
      "workstream": "R4.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R4.2.g",
          "R4.3.d",
          "R4.4.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "macOS arm64 and Linux x86_64 are tier-1 minimum; add a second independent builder implementation and tier-2 hosts before v1. A one-host R4.4.b rehearsal is diagnostic only and cannot satisfy this task.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.4.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "macOS arm64 and Linux x86_64 are tier-1 minimum; add a second independent builder implementation and tier-2 hosts before v1. A one-host R4.4.b rehearsal is diagnostic only and cannot satisfy this task.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R4.2.g",
        "R4.3.d",
        "R4.4.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1223,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Require cross-host fixpoint after authority cutover",
      "unsatisfied_prerequisites": [
        "R4.2.g",
        "R4.3.d",
        "R4.4.b"
      ],
      "workstream": "R4.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R4.4.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Rebuild critical toolchain artifacts through independently built stage0/verifier paths and investigate any mismatch before release.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.4.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "Rebuild critical toolchain artifacts through independently built stage0/verifier paths and investigate any mismatch before release.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R4.4.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1224,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add diverse double compilation",
      "unsatisfied_prerequisites": [
        "R4.4.c"
      ],
      "workstream": "R4.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R4.4.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Include source tree hash, stage hashes, build graph, toolchain identity, commands, environment, and independent verification result.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.4.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "Include source tree hash, stage hashes, build graph, toolchain identity, commands, environment, and independent verification result.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R4.4.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1225,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Publish bootstrap witnesses",
      "unsatisfied_prerequisites": [
        "R4.4.d"
      ],
      "workstream": "R4.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Cover evaluation, seals, errors, canonical values/hashes, resource limits, and malformed/adversarial inputs independent of Rust implementation details.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.5.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "Cover evaluation, seals, errors, canonical values/hashes, resource limits, and malformed/adversarial inputs independent of Rust implementation details.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1229,
        "path": "ROADMAP.md"
      },
      "start_ready": true,
      "state": "open",
      "title": "Publish a kernel conformance suite",
      "unsatisfied_prerequisites": [],
      "workstream": "R4.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R4.5.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Cover capability decisions, normalized paths, logs/replay, cancellation/kill/reap, payload limits, scheduling, and host errors.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.5.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "Cover capability decisions, normalized paths, logs/replay, cancellation/kill/reap, payload limits, scheduling, and host errors.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R4.5.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1230,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Publish effect-host conformance",
      "unsatisfied_prerequisites": [
        "R4.5.a"
      ],
      "workstream": "R4.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "selfhost",
          "crates/gc_cli_driver",
          "crates/gc_effects",
          "crates/gc_patches",
          "crates/gc_obligations",
          "docs/INDEX.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.1.e",
          "R4.2.g",
          "R4.5.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "At least one independently authored stage0 or verifier passes the normative suite before the strongest replaceability claim.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_selfhost_boundary.sh",
        "scripts/check_selfhost_readiness_scorecard.sh",
        "scripts/check_source_decomposition_progress.sh"
      ],
      "id": "R4.5.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject routed-only selfhost claims, hidden Rust semantic fallback, non-fixpoint bootstrap, and trusting-trust blind spots"
      ],
      "objective": "At least one independently authored stage0 or verifier passes the normative suite before the strongest replaceability claim.",
      "owner_paths": [
        "selfhost",
        "crates/gc_cli_driver",
        "crates/gc_effects",
        "crates/gc_patches",
        "crates/gc_obligations",
        "docs/INDEX.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R4",
      "prerequisites": [
        "R4.1.e",
        "R4.2.g",
        "R4.5.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1231,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Validate an independent implementation",
      "unsatisfied_prerequisites": [
        "R4.2.g",
        "R4.5.b"
      ],
      "workstream": "R4.5"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "scripts/check_foundation_stdlib_conformance.sh",
            "scripts/check_host_abi_conformance.sh",
            "scripts/check_no_user_panics.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "normative-form-matrix-sha256:b3265433eff8c885fa769348c6a88f0df0ba02c06ae0ef6c720b7db9d29c2ff8"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "prelude",
          "selfhost"
        ],
        "prerequisite_task_ids": [
          "R0.3.e",
          "R2.1.g",
          "R2.2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Generate a normative-form matrix and reject undocumented behavior.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_wasm_production_surface.sh"
      ],
      "id": "R5.1.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift",
        "reject undocumented semantics, profile confusion, tier divergence, noncanonical encodings, backend-specific behavior, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Generate a normative-form matrix and reject undocumented behavior.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "prelude",
        "selfhost"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.3.e",
        "R2.1.g",
        "R2.2.f"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1243,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Reconcile paper, handoff, specs, parser, Prelude, types, and all execution tiers",
      "unsatisfied_prerequisites": [],
      "workstream": "R5.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test -p gc_types --lib",
            "scripts/check_foundation_stdlib_conformance.sh",
            "scripts/check_host_abi_conformance.sh",
            "scripts/check_no_user_panics.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "effect-row-contract-sha256:8db875db9ef8a5d1dfd5fb7ce41ddbc28e14dd119e228ff50a069f55717bd9f3"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "prelude",
          "selfhost"
        ],
        "prerequisite_task_ids": [
          "R0.3.e",
          "R2.1.g",
          "R2.2.f",
          "R5.1.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Audit existing `gc_types` row inference, polymorphism, strictness, diagnostics, and module boundaries; close unsoundness/completeness gaps before declaring GA.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_wasm_production_surface.sh"
      ],
      "id": "R5.1.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift",
        "reject undocumented semantics, profile confusion, tier divergence, noncanonical encodings, backend-specific behavior, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Audit existing `gc_types` row inference, polymorphism, strictness, diagnostics, and module boundaries; close unsoundness/completeness gaps before declaring GA.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "prelude",
        "selfhost"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.3.e",
        "R2.1.g",
        "R2.2.f",
        "R5.1.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1245,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Promote effect rows deliberately",
      "unsatisfied_prerequisites": [],
      "workstream": "R5.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test -p gc_coreform --all-targets",
            "cargo test -p gc_types --all-targets",
            "cargo test -p gc_prelude --test selfhost_parse_equivalence",
            "scripts/check_foundation_stdlib_conformance.sh",
            "scripts/check_host_abi_conformance.sh",
            "scripts/check_no_user_panics.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "error-pattern-contract-sha256:787f6fefc3e9661ba809b7332f3b4b19bf1664cfb9d7e7b60d8ec88a9dc2ee49"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "prelude",
          "selfhost"
        ],
        "prerequisite_task_ids": [
          "R0.3.e",
          "R2.1.g",
          "R2.2.f",
          "R5.1.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Exhaustiveness, duplicate bindings, guards if supported, sealed errors, and span provenance must match across tiers.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_wasm_production_surface.sh"
      ],
      "id": "R5.1.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift",
        "reject undocumented semantics, profile confusion, tier divergence, noncanonical encodings, backend-specific behavior, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Exhaustiveness, duplicate bindings, guards if supported, sealed errors, and span provenance must match across tiers.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "prelude",
        "selfhost"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.3.e",
        "R2.1.g",
        "R2.2.f",
        "R5.1.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1247,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Freeze error and pattern behavior",
      "unsatisfied_prerequisites": [],
      "workstream": "R5.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test -p gc_coreform --all-targets",
            "cargo test -p gc_kernel --lib",
            "cargo test -p gc_types --all-targets",
            "cargo test -p gc_opt --all-targets",
            "cargo test -p gc_prelude --test prelude_numeric_profile_conformance",
            "scripts/check_kernel_tcb_contract.sh",
            "scripts/check_wasm_production_surface.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "numeric-profile-content-sha256:e1bc94ca7620944fe7a40ab9b628eefb642bb8bf5d41b1fd8920c6226dbac74d"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "prelude",
          "selfhost"
        ],
        "prerequisite_task_ids": [
          "R0.3.e",
          "R2.1.g",
          "R2.2.f",
          "R5.1.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Integers, overflow, division, floats/NaN, decimal/bigint if included, serialization, hashing, and GPU/backend differences must be deterministic or explicitly profile-scoped.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_wasm_production_surface.sh"
      ],
      "id": "R5.1.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift",
        "reject undocumented semantics, profile confusion, tier divergence, noncanonical encodings, backend-specific behavior, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Integers, overflow, division, floats/NaN, decimal/bigint if included, serialization, hashing, and GPU/backend differences must be deterministic or explicitly profile-scoped.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "prelude",
        "selfhost"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.3.e",
        "R2.1.g",
        "R2.2.f",
        "R5.1.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1249,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Specify numeric profiles",
      "unsatisfied_prerequisites": [],
      "workstream": "R5.1"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test -p gc_prelude --test prelude_text_path_profile_conformance",
            "cargo test -p gc_effects runner_io_ops::tests --lib",
            "cargo test -p gc_types unicode_text_primitives --lib",
            "scripts/check_foundation_stdlib_conformance.sh",
            "scripts/check_host_abi_conformance.sh",
            "scripts/check_no_user_panics.sh",
            "scripts/check_kernel_tcb_contract.sh",
            "scripts/check_wasm_production_surface.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "text-path-profile-content-sha256:3b46f02f0d61eef89f2895134f3a05c77a8a4a38acdf80ce274b58bc993d1cab"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude",
          "crates/gc_kernel",
          "crates/gc_opt",
          "crates/gc_wasm",
          "prelude",
          "selfhost"
        ],
        "prerequisite_task_ids": [
          "R0.3.e",
          "R2.1.g",
          "R2.2.f",
          "R5.1.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Unicode normalization, byte strings, graphemes, path separators, case sensitivity, locale independence, and base-relative error payloads are explicit.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh",
        "scripts/check_kernel_tcb_contract.sh",
        "scripts/check_wasm_production_surface.sh"
      ],
      "id": "R5.1.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift",
        "reject undocumented semantics, profile confusion, tier divergence, noncanonical encodings, backend-specific behavior, implicit text normalization, Unicode-table drift, locale-dependent identity, and lossy or nonrelative path material"
      ],
      "objective": "Unicode normalization, byte strings, graphemes, path separators, case sensitivity, locale independence, and base-relative error payloads are explicit.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude",
        "crates/gc_kernel",
        "crates/gc_opt",
        "crates/gc_wasm",
        "prelude",
        "selfhost"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.3.e",
        "R2.1.g",
        "R2.2.f",
        "R5.1.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1251,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Specify text/path behavior",
      "unsatisfied_prerequisites": [],
      "workstream": "R5.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R5.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Reconcile `CONCURRENCY_v0.1.md`, schedule logs, task IDs, cancellation, joins, errors, and resource accounting.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.2.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Reconcile `CONCURRENCY_v0.1.md`, schedule logs, task IDs, cancellation, joins, errors, and resource accounting.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R5.1.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1256,
        "path": "ROADMAP.md"
      },
      "start_ready": true,
      "state": "open",
      "title": "Audit the existing concurrency contract/runtime",
      "unsatisfied_prerequisites": [],
      "workstream": "R5.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R5.1.e",
          "R5.2.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "No orphan tasks; parent cancellation and failure propagation are deterministic and replayable.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.2.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "No orphan tasks; parent cancellation and failure propagation are deterministic and replayable.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R5.1.e",
        "R5.2.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1257,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add structured scopes",
      "unsatisfied_prerequisites": [
        "R5.2.a"
      ],
      "workstream": "R5.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R5.1.e",
          "R5.2.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Channels/select/races, backpressure, fairness, ordering, deadlines, and closed-channel behavior have deterministic schedule facts.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.2.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Channels/select/races, backpressure, fairness, ordering, deadlines, and closed-channel behavior have deterministic schedule facts.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R5.1.e",
        "R5.2.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1258,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Specify communication",
      "unsatisfied_prerequisites": [
        "R5.2.b"
      ],
      "workstream": "R5.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R5.1.e",
          "R5.2.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Task count, queue depth, messages, bytes, steps, effects, processes, and host workers cannot bypass parent policy.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.2.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Task count, queue depth, messages, bytes, steps, effects, processes, and host workers cannot bypass parent policy.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R5.1.e",
        "R5.2.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1259,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Enforce global and per-scope bounds",
      "unsatisfied_prerequisites": [
        "R5.2.c"
      ],
      "workstream": "R5.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R5.1.e",
          "R5.2.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Explore bounded interleavings and replay every accepted trace across tiers/hosts.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.2.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Explore bounded interleavings and replay every accepted trace across tiers/hosts.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R5.1.e",
        "R5.2.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1260,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Differential/model-check schedules",
      "unsatisfied_prerequisites": [
        "R5.2.d"
      ],
      "workstream": "R5.2"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test -p gc_types --all-targets",
            "cargo clippy -p gc_types --all-targets -- -D warnings",
            "scripts/check_foundation_stdlib_conformance.sh",
            "scripts/check_host_abi_conformance.sh",
            "scripts/check_no_user_panics.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "module-resolution-profile-content-sha256:b186e589bc5b6e466496f224c694712e411dac47c0f46e7ecdde6a6ce36ef8e1"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.3.e",
          "R5.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Content identity, imports/exports, visibility, cycles, profile constraints, workspace overrides, and package boundaries are deterministic.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.3.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Content identity, imports/exports, visibility, cycles, profile constraints, workspace overrides, and package boundaries are deterministic.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.3.e",
        "R5.1.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1264,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Freeze module resolution",
      "unsatisfied_prerequisites": [],
      "workstream": "R5.3"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test -p gc_types --all-targets",
            "cargo test -p gc_prelude --lib",
            "cargo clippy -p gc_types -p gc_prelude --all-targets -- -D warnings",
            "scripts/check_foundation_stdlib_conformance.sh",
            "scripts/check_host_abi_conformance.sh",
            "scripts/check_no_user_panics.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "contract-composition-profile-content-sha256:066940da54751062e56fd093e8f76434c71fc3c6a7bc510810b57201c841d736"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.3.e",
          "R5.1.e",
          "R5.3.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Define blame, refinement/shape identity, effect interaction, generics/parametricity where supported, and optimization preconditions.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.3.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Define blame, refinement/shape identity, effect interaction, generics/parametricity where supported, and optimization preconditions.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.3.e",
        "R5.1.e",
        "R5.3.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1266,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Complete contract composition",
      "unsatisfied_prerequisites": [],
      "workstream": "R5.3"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test -p gc_types --all-targets",
            "cargo clippy -p gc_types --all-targets -- -D warnings",
            "scripts/check_foundation_stdlib_conformance.sh",
            "scripts/check_host_abi_conformance.sh",
            "scripts/check_no_user_panics.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "profile-negotiation-content-sha256:3f088f61f86a8a8d5bc2306521005c7cf35562ed1c08220836a3851df534564e"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.3.e",
          "R5.1.e",
          "R5.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Packages declare minimum/exact compatible language, capability, artifact, and target profiles; unsupported combinations fail before execution.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.3.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Packages declare minimum/exact compatible language, capability, artifact, and target profiles; unsupported combinations fail before execution.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.3.e",
        "R5.1.e",
        "R5.3.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1268,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Add profile negotiation",
      "unsatisfied_prerequisites": [],
      "workstream": "R5.3"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test -p gc_types --all-targets",
            "cargo clippy -p gc_types --all-targets -- -D warnings",
            "MIGRATION_PROFILE_v0.1",
            "scripts/check_foundation_stdlib_conformance.sh",
            "scripts/check_host_abi_conformance.sh",
            "scripts/check_no_user_panics.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "migration-profile-content-sha256:d3c96d807a62f0a4144b5b1d293f6dbdfec538fa40f49ec43d58b0cf8f5db0b1"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.3.e",
          "R5.1.e",
          "R5.3.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Canonical semantic patches upgrade syntax/APIs/formats; dry-run explains identity/effect changes and preserves provenance.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.3.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Canonical semantic patches upgrade syntax/APIs/formats; dry-run explains identity/effect changes and preserves provenance.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.3.e",
        "R5.1.e",
        "R5.3.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1270,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Ship migration tooling",
      "unsatisfied_prerequisites": [],
      "workstream": "R5.3"
    },
    {
      "acceptance": {
        "evidence": {
          "commands": [
            "cargo test -p gc_types --all-targets",
            "cargo clippy -p gc_types --all-targets -- -D warnings",
            "SUPPORT_POLICY_v0.1",
            "scripts/check_foundation_stdlib_conformance.sh",
            "scripts/check_host_abi_conformance.sh",
            "scripts/check_no_user_panics.sh"
          ],
          "completed_date": "2026-08-11",
          "input_identity": "support-policy-content-sha256:ff05236d7536f36db376ac8533fb3321889e96a1715ef5a8e908a799b83ed061"
        },
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "satisfied"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.3.e",
          "R5.1.e",
          "R5.3.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "v1.x compatibility, deprecation windows, security exceptions, format readers, and end-of-life are explicit.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.3.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "v1.x compatibility, deprecation windows, security exceptions, format readers, and end-of-life are explicit.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.3.e",
        "R5.1.e",
        "R5.3.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1272,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "done",
      "title": "Publish support policy",
      "unsatisfied_prerequisites": [],
      "workstream": "R5.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R5.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Pure data/text/encoding/math/testing plus capability-backed filesystem, process, network, time, randomness, crypto, data, service, and model operations.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.4.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Pure data/text/encoding/math/testing plus capability-backed filesystem, process, network, time, randomness, crypto, data, service, and model operations.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R5.1.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1277,
        "path": "ROADMAP.md"
      },
      "start_ready": true,
      "state": "open",
      "title": "Define the v1 stdlib matrix",
      "unsatisfied_prerequisites": [],
      "workstream": "R5.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R5.1.e",
          "R5.4.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "No ambient global handles; resources use scoped ownership, bounded streams, explicit closure, and sealed host errors.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.4.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "No ambient global handles; resources use scoped ownership, bounded streams, explicit closure, and sealed host errors.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R5.1.e",
        "R5.4.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1278,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Keep effect APIs capability-shaped",
      "unsatisfied_prerequisites": [
        "R5.4.a"
      ],
      "workstream": "R5.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R5.1.e",
          "R5.4.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Canonical JSON/CBOR or selected formats, HTTP, WebSocket, streaming, TLS policy, and package/evidence codecs have fuzzed incremental parsers.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.4.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Canonical JSON/CBOR or selected formats, HTTP, WebSocket, streaming, TLS policy, and package/evidence codecs have fuzzed incremental parsers.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R5.1.e",
        "R5.4.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1279,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Finish robust codecs/protocols",
      "unsatisfied_prerequisites": [
        "R5.4.b"
      ],
      "workstream": "R5.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R5.1.e",
          "R5.4.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Use audited host/provider primitives behind explicit capabilities; never invent cryptography in the kernel; expose algorithm/profile/version and deterministic test vectors.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.4.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Use audited host/provider primitives behind explicit capabilities; never invent cryptography in the kernel; expose algorithm/profile/version and deterministic test vectors.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R5.1.e",
        "R5.4.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1280,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Define crypto correctly",
      "unsatisfied_prerequisites": [
        "R5.4.c"
      ],
      "workstream": "R5.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R5.1.e",
          "R5.4.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Version provider/model/weights identity, prompt/input hash, sampling, token/resource budget, secret policy, output provenance, and replay mode. Fully local providers are first-class.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.4.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Version provider/model/weights identity, prompt/input hash, sampling, token/resource budget, secret policy, output provenance, and replay mode. Fully local providers are first-class.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R5.1.e",
        "R5.4.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1281,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Treat model inference as an effect",
      "unsatisfied_prerequisites": [
        "R5.4.d"
      ],
      "workstream": "R5.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R3.2.d",
          "R5.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Use the WebAssembly Component Model and WIT with an explicitly pinned WASI 0.3 profile for native async, streams, futures, and cancellation, plus a tested WASI 0.2 compatibility/virtualization path where ecosystem reach requires it. Define the exact Genesis value/effect/resource mapping and treat native escape hatches as higher-risk profiles.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.5.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Use the WebAssembly Component Model and WIT with an explicitly pinned WASI 0.3 profile for native async, streams, futures, and cancellation, plus a tested WASI 0.2 compatibility/virtualization path where ecosystem reach requires it. Define the exact Genesis value/effect/resource mapping and treat native escape hatches as higher-risk profiles.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R3.2.d",
        "R5.1.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1285,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Adopt a component boundary",
      "unsatisfied_prerequisites": [
        "R3.2.d"
      ],
      "workstream": "R5.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R3.2.d",
          "R5.1.e",
          "R5.5.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Types, ownership, errors, resources, limits, and evidence derive from one schema.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.5.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Types, ownership, errors, resources, limits, and evidence derive from one schema.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R3.2.d",
        "R5.1.e",
        "R5.5.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1286,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Generate bindings and capability manifests",
      "unsatisfied_prerequisites": [
        "R3.2.d",
        "R5.5.a"
      ],
      "workstream": "R5.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R3.2.d",
          "R5.1.e",
          "R5.5.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Memory, CPU, calls, effects, filesystem/network, cancellation, and lifecycle are bounded; malformed components cannot panic the host.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.5.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Memory, CPU, calls, effects, filesystem/network, cancellation, and lifecycle are bounded; malformed components cannot panic the host.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R3.2.d",
        "R5.1.e",
        "R5.5.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1287,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Sandbox extensions",
      "unsatisfied_prerequisites": [
        "R3.2.d",
        "R5.5.b"
      ],
      "workstream": "R5.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R3.2.d",
          "R5.1.e",
          "R5.5.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Pure components are content-addressed; effectful calls log canonical request/response or an explicit non-replayable policy decision.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.5.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Pure components are content-addressed; effectful calls log canonical request/response or an explicit non-replayable policy decision.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R3.2.d",
        "R5.1.e",
        "R5.5.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1288,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Make extension behavior replayable",
      "unsatisfied_prerequisites": [
        "R3.2.d",
        "R5.5.c"
      ],
      "workstream": "R5.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R3.2.d",
          "R5.1.e",
          "R5.5.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Import pinned WIT, OpenAPI/JSON Schema, Protocol Buffers, SQL schemas, C header metadata, and selected platform interface descriptions into one typed Genesis binding IR. Generated wrappers, ownership shims, codecs, capability manifests, cards, tests, and SBOM edges are deterministic and carry source identity; unsupported constructs fail with an exact adapter gap rather than producing unsafe bindings.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.5.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Import pinned WIT, OpenAPI/JSON Schema, Protocol Buffers, SQL schemas, C header metadata, and selected platform interface descriptions into one typed Genesis binding IR. Generated wrappers, ownership shims, codecs, capability manifests, cards, tests, and SBOM edges are deterministic and carry source identity; unsupported constructs fail with an exact adapter gap rather than producing unsafe bindings.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R3.2.d",
        "R5.1.e",
        "R5.5.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1289,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Generate foreign-schema adapters without foreign application code",
      "unsatisfied_prerequisites": [
        "R3.2.d",
        "R5.5.d"
      ],
      "workstream": "R5.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R3.2.d",
          "R5.1.e",
          "R5.5.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Where Component Model isolation is unavailable, package native libraries behind a separately signed high-risk adapter profile with ABI/SDK/architecture identity, memory/lifetime rules, thread/callback policy, hard resource isolation where possible, and platform-specific negative controls. Application packages consume only Genesis APIs; handwritten foreign glue cannot hide in the application tree or acquire ambient authority.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.5.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Where Component Model isolation is unavailable, package native libraries behind a separately signed high-risk adapter profile with ABI/SDK/architecture identity, memory/lifetime rules, thread/callback policy, hard resource isolation where possible, and platform-specific negative controls. Application packages consume only Genesis APIs; handwritten foreign glue cannot hide in the application tree or acquire ambient authority.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R2.2.f",
        "R3.2.d",
        "R5.1.e",
        "R5.5.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1290,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Govern native and legacy ecosystem packages",
      "unsatisfied_prerequisites": [
        "R3.2.d",
        "R5.5.e"
      ],
      "workstream": "R5.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R5.2.e",
          "R5.3.e",
          "R5.4.e",
          "R5.5.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Specify deterministic lifecycle, immutable state/update/view/effect boundaries, component identity, routing/navigation, dependency injection, configuration, localization, theming, error boundaries, hot replacement, and server/client/native ownership without adding UI semantics to the kernel.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.6.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Specify deterministic lifecycle, immutable state/update/view/effect boundaries, component identity, routing/navigation, dependency injection, configuration, localization, theming, error boundaries, hot replacement, and server/client/native ownership without adding UI semantics to the kernel.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R5.2.e",
        "R5.3.e",
        "R5.4.e",
        "R5.5.f"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1294,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Define one application architecture",
      "unsatisfied_prerequisites": [
        "R5.2.e",
        "R5.4.e",
        "R5.5.f"
      ],
      "workstream": "R5.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R5.2.e",
          "R5.3.e",
          "R5.4.e",
          "R5.5.f",
          "R5.6.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "GenesisCode owns document structure, components, layout, typography, color, responsive constraints, animation, focus, semantics, forms, validation, canvas/scene embedding, and design tokens. Invalid trees, inaccessible interactions, unbounded layout, unsupported target features, and style conflicts produce structured diagnostics.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.6.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "GenesisCode owns document structure, components, layout, typography, color, responsive constraints, animation, focus, semantics, forms, validation, canvas/scene embedding, and design tokens. Invalid trees, inaccessible interactions, unbounded layout, unsupported target features, and style conflicts produce structured diagnostics.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R5.2.e",
        "R5.3.e",
        "R5.4.e",
        "R5.5.f",
        "R5.6.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1295,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Build a typed presentation and style IR",
      "unsatisfied_prerequisites": [
        "R5.2.e",
        "R5.4.e",
        "R5.5.f",
        "R5.6.a"
      ],
      "workstream": "R5.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R5.2.e",
          "R5.3.e",
          "R5.4.e",
          "R5.5.f",
          "R5.6.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Compile Genesis routes/views/styles to deterministic static HTML, scoped CSS, browser Wasm/JavaScript adapters, assets, source maps, CSP/integrity metadata, workers, service workers, and manifests. Support static sites, SPA, SSR/streaming, hydration, forms/actions, API routes, WebSocket, storage, offline/PWA, and progressive enhancement without application-authored HTML/CSS/JavaScript.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.6.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Compile Genesis routes/views/styles to deterministic static HTML, scoped CSS, browser Wasm/JavaScript adapters, assets, source maps, CSP/integrity metadata, workers, service workers, and manifests. Support static sites, SPA, SSR/streaming, hydration, forms/actions, API routes, WebSocket, storage, offline/PWA, and progressive enhancement without application-authored HTML/CSS/JavaScript.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R5.2.e",
        "R5.3.e",
        "R5.4.e",
        "R5.5.f",
        "R5.6.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1296,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Implement the web product stack",
      "unsatisfied_prerequisites": [
        "R5.2.e",
        "R5.4.e",
        "R5.5.f",
        "R5.6.b"
      ],
      "workstream": "R5.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R5.2.e",
          "R5.3.e",
          "R5.4.e",
          "R5.5.f",
          "R5.6.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Text shaping, images, lists, tables, controls, dialogs, menus, navigation, virtualized content, drag/drop, clipboard, accessibility trees, keyboard/touch/pointer/gamepad input, IME, reduced motion, high contrast, and screen-reader semantics behave consistently or expose explicit target limitations.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.6.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Text shaping, images, lists, tables, controls, dialogs, menus, navigation, virtualized content, drag/drop, clipboard, accessibility trees, keyboard/touch/pointer/gamepad input, IME, reduced motion, high contrast, and screen-reader semantics behave consistently or expose explicit target limitations.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R5.2.e",
        "R5.3.e",
        "R5.4.e",
        "R5.5.f",
        "R5.6.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1297,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Implement accessible cross-target widgets",
      "unsatisfied_prerequisites": [
        "R5.2.e",
        "R5.4.e",
        "R5.5.f",
        "R5.6.c"
      ],
      "workstream": "R5.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R5.2.e",
          "R5.3.e",
          "R5.4.e",
          "R5.5.f",
          "R5.6.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Incremental dependency tracking, keyed diffing, layout/paint invalidation, batching, retained resources, streaming SSR, and target-specific rendering are outside semantic trust but translation-validated against the presentation IR. Devtools expose state, effects, layout, accessibility, frame work, and source spans without hidden mutation.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.6.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Incremental dependency tracking, keyed diffing, layout/paint invalidation, batching, retained resources, streaming SSR, and target-specific rendering are outside semantic trust but translation-validated against the presentation IR. Devtools expose state, effects, layout, accessibility, frame work, and source spans without hidden mutation.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R5.2.e",
        "R5.3.e",
        "R5.4.e",
        "R5.5.f",
        "R5.6.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1298,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Make UI rendering efficient and inspectable",
      "unsatisfied_prerequisites": [
        "R5.2.e",
        "R5.4.e",
        "R5.5.f",
        "R5.6.d"
      ],
      "workstream": "R5.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R5.2.e",
          "R5.3.e",
          "R5.4.e",
          "R5.5.f",
          "R5.6.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Pure state/update tests, semantic-tree goldens, screenshot/pixel tolerances, accessibility audits, browser/native interaction replay, responsive matrices, network/offline faults, and performance traces share one Genesis test API and deterministic fixture format.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.6.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Pure state/update tests, semantic-tree goldens, screenshot/pixel tolerances, accessibility audits, browser/native interaction replay, responsive matrices, network/offline faults, and performance traces share one Genesis test API and deterministic fixture format.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R5.2.e",
        "R5.3.e",
        "R5.4.e",
        "R5.5.f",
        "R5.6.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1299,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Ship product-grade UI testing",
      "unsatisfied_prerequisites": [
        "R5.2.e",
        "R5.4.e",
        "R5.5.f",
        "R5.6.e"
      ],
      "workstream": "R5.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R5.2.e",
          "R5.3.e",
          "R5.4.e",
          "R5.5.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Provide routing, middleware, request/response streaming, TLS termination policy, compression, cookies, sessions, CSRF/CORS, authentication, authorization, OIDC/OAuth integration, rate limits, idempotency, health/readiness, graceful drain, and generated API schemas/clients under explicit capabilities.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.7.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Provide routing, middleware, request/response streaming, TLS termination policy, compression, cookies, sessions, CSRF/CORS, authentication, authorization, OIDC/OAuth integration, rate limits, idempotency, health/readiness, graceful drain, and generated API schemas/clients under explicit capabilities.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R5.2.e",
        "R5.3.e",
        "R5.4.e",
        "R5.5.f"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1303,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Complete typed service construction",
      "unsatisfied_prerequisites": [
        "R5.2.e",
        "R5.4.e",
        "R5.5.f"
      ],
      "workstream": "R5.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R5.2.e",
          "R5.3.e",
          "R5.4.e",
          "R5.5.f",
          "R5.7.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Add typed schemas, queries, transactions, pools, migrations, fixtures, pagination, change streams, backup/restore, and deterministic local test stores across an embedded database plus profiled SQL, KV, and object-store adapters. Query generation is injection-safe and migration plans are reviewable and reversible where declared.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.7.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Add typed schemas, queries, transactions, pools, migrations, fixtures, pagination, change streams, backup/restore, and deterministic local test stores across an embedded database plus profiled SQL, KV, and object-store adapters. Query generation is injection-safe and migration plans are reviewable and reversible where declared.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R5.2.e",
        "R5.3.e",
        "R5.4.e",
        "R5.5.f",
        "R5.7.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1304,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Complete durable data APIs",
      "unsatisfied_prerequisites": [
        "R5.2.e",
        "R5.4.e",
        "R5.5.f",
        "R5.7.a"
      ],
      "workstream": "R5.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R5.2.e",
          "R5.3.e",
          "R5.4.e",
          "R5.5.f",
          "R5.7.a",
          "R5.7.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Bounded queues, jobs, schedules, cache, pub/sub, email, object storage, distributed locks/leases, workflow checkpoints, and retry/idempotency policies expose exact delivery/order/failure semantics and replayable local substitutes.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.7.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Bounded queues, jobs, schedules, cache, pub/sub, email, object storage, distributed locks/leases, workflow checkpoints, and retry/idempotency policies expose exact delivery/order/failure semantics and replayable local substitutes.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R5.2.e",
        "R5.3.e",
        "R5.4.e",
        "R5.5.f",
        "R5.7.a",
        "R5.7.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1305,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add production coordination primitives",
      "unsatisfied_prerequisites": [
        "R5.2.e",
        "R5.4.e",
        "R5.5.f",
        "R5.7.a",
        "R5.7.b"
      ],
      "workstream": "R5.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R5.2.e",
          "R5.3.e",
          "R5.4.e",
          "R5.5.f",
          "R5.7.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Structured logs, metrics, traces, profiles, audit events, correlation/context propagation, redaction, sampling, retention, SLOs, alerts, and incident bundles are capability-scoped and portable to self-hosted open telemetry/storage components without entering deterministic application semantics.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.7.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Structured logs, metrics, traces, profiles, audit events, correlation/context propagation, redaction, sampling, retention, SLOs, alerts, and incident bundles are capability-scoped and portable to self-hosted open telemetry/storage components without entering deterministic application semantics.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R5.2.e",
        "R5.3.e",
        "R5.4.e",
        "R5.5.f",
        "R5.7.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1306,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Unify observability and operations",
      "unsatisfied_prerequisites": [
        "R5.2.e",
        "R5.4.e",
        "R5.5.f",
        "R5.7.a"
      ],
      "workstream": "R5.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R5.2.e",
          "R5.3.e",
          "R5.4.e",
          "R5.5.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Add typed arrays/tensors, tables/dataframes, streaming transforms, statistics, linear algebra, signal/image/audio operations, dataset manifests, checkpointed pipelines, and local model inference/training adapters with CPU/GPU backends, deterministic profiles, resource accounting, and no Python requirement for users.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.7.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Add typed arrays/tensors, tables/dataframes, streaming transforms, statistics, linear algebra, signal/image/audio operations, dataset manifests, checkpointed pipelines, and local model inference/training adapters with CPU/GPU backends, deterministic profiles, resource accounting, and no Python requirement for users.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R5.2.e",
        "R5.3.e",
        "R5.4.e",
        "R5.5.f"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1307,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Build first-party data/numeric/ML libraries",
      "unsatisfied_prerequisites": [
        "R5.2.e",
        "R5.4.e",
        "R5.5.f"
      ],
      "workstream": "R5.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R5.2.e",
          "R5.3.e",
          "R5.4.e",
          "R5.5.f",
          "R5.7.a",
          "R5.7.b",
          "R5.7.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Password/key handling, account/session lifecycle, tenancy, authorization policy, schema validation, file upload, content scanning hooks, audit trails, privacy retention/deletion, and abuse controls ship as reviewed packages and threat-modeled reference architectures rather than ad hoc snippets.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.7.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Password/key handling, account/session lifecycle, tenancy, authorization policy, schema validation, file upload, content scanning hooks, audit trails, privacy retention/deletion, and abuse controls ship as reviewed packages and threat-modeled reference architectures rather than ad hoc snippets.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R5.2.e",
        "R5.3.e",
        "R5.4.e",
        "R5.5.f",
        "R5.7.a",
        "R5.7.b",
        "R5.7.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1308,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Provide secure application foundations",
      "unsatisfied_prerequisites": [
        "R5.2.e",
        "R5.4.e",
        "R5.5.f",
        "R5.7.a",
        "R5.7.b",
        "R5.7.d"
      ],
      "workstream": "R5.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R2.2.f",
          "R5.4.e",
          "R5.6.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Add fixed/variable-step clocks, ECS or equally explicit world state, scenes/prefabs, events, input mapping, deterministic RNG, rollback snapshots, save/load, and reproducible simulation tests; wall time, devices, network, and assets remain effects.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.8.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Add fixed/variable-step clocks, ECS or equally explicit world state, scenes/prefabs, events, input mapping, deterministic RNG, rollback snapshots, save/load, and reproducible simulation tests; wall time, devices, network, and assets remain effects.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R2.2.f",
        "R5.4.e",
        "R5.6.f"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1314,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Define a deterministic game/simulation core",
      "unsatisfied_prerequisites": [
        "R5.4.e",
        "R5.6.f"
      ],
      "workstream": "R5.8"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R2.2.f",
          "R5.4.e",
          "R5.6.f",
          "R5.8.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Provide sprites, tilemaps, cameras, meshes, materials, lighting, animation, particles, collision/physics, navigation, spatial queries, culling, level streaming, and bounded resource lifecycles with headless reference behavior and real GPU/render backends.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.8.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Provide sprites, tilemaps, cameras, meshes, materials, lighting, animation, particles, collision/physics, navigation, spatial queries, culling, level streaming, and bounded resource lifecycles with headless reference behavior and real GPU/render backends.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R2.2.f",
        "R5.4.e",
        "R5.6.f",
        "R5.8.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1315,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Complete 2D/3D runtime systems",
      "unsatisfied_prerequisites": [
        "R5.4.e",
        "R5.6.f",
        "R5.8.a"
      ],
      "workstream": "R5.8"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R2.2.f",
          "R5.4.e",
          "R5.6.f",
          "R5.8.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "A typed Genesis shader/kernel IR emits validated WGSL/SPIR-V or target formats; image/audio/font/model/scene import, compression, atlasing, level-of-detail, packaging, hot reload, and license/provenance tracking form one deterministic asset graph. Users never patch shader or importer source in another language.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.8.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "A typed Genesis shader/kernel IR emits validated WGSL/SPIR-V or target formats; image/audio/font/model/scene import, compression, atlasing, level-of-detail, packaging, hot reload, and license/provenance tracking form one deterministic asset graph. Users never patch shader or importer source in another language.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R2.2.f",
        "R5.4.e",
        "R5.6.f",
        "R5.8.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1316,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Make shaders and assets Genesis-authored",
      "unsatisfied_prerequisites": [
        "R5.4.e",
        "R5.6.f",
        "R5.8.b"
      ],
      "workstream": "R5.8"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R2.2.f",
          "R5.4.e",
          "R5.6.f",
          "R5.8.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Mixing, buses, spatial audio, synthesis/effects, MIDI, recording/playback, animation/video timelines, deterministic offline renders, real-time deadlines, device loss, and content pipelines have explicit quality and resource profiles.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.8.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Mixing, buses, spatial audio, synthesis/effects, MIDI, recording/playback, animation/video timelines, deterministic offline renders, real-time deadlines, device loss, and content pipelines have explicit quality and resource profiles.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R2.2.f",
        "R5.4.e",
        "R5.6.f",
        "R5.8.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1317,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add audio and creative timelines",
      "unsatisfied_prerequisites": [
        "R5.4.e",
        "R5.6.f",
        "R5.8.c"
      ],
      "workstream": "R5.8"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R2.2.f",
          "R5.4.e",
          "R5.6.f",
          "R5.8.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Authoritative server, snapshots/deltas, prediction/reconciliation, rollback, lag compensation, matchmaking/lobbies, anti-cheat evidence hooks, replay/spectator, and bandwidth budgets are packages over the typed service and deterministic simulation contracts.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.8.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Authoritative server, snapshots/deltas, prediction/reconciliation, rollback, lag compensation, matchmaking/lobbies, anti-cheat evidence hooks, replay/spectator, and bandwidth budgets are packages over the typed service and deterministic simulation contracts.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R2.2.f",
        "R5.4.e",
        "R5.6.f",
        "R5.8.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1318,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Support networked interactive systems",
      "unsatisfied_prerequisites": [
        "R5.4.e",
        "R5.6.f",
        "R5.8.d"
      ],
      "workstream": "R5.8"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R2.2.f",
          "R5.4.e",
          "R5.6.f",
          "R5.8.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Scene/world inspector, asset browser, profiler, frame capture, live reload, deterministic record/replay, test level, packaging, and crash evidence are available through Genesis-native tools and generated MCP surfaces, not a mandatory foreign editor scripting language.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.8.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Scene/world inspector, asset browser, profiler, frame capture, live reload, deterministic record/replay, test level, packaging, and crash evidence are available through Genesis-native tools and generated MCP surfaces, not a mandatory foreign editor scripting language.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R2.2.f",
        "R5.4.e",
        "R5.6.f",
        "R5.8.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1319,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Ship editor and debugging workflows",
      "unsatisfied_prerequisites": [
        "R5.4.e",
        "R5.6.f",
        "R5.8.e"
      ],
      "workstream": "R5.8"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R2.2.f",
          "R3.2.d",
          "R5.1.e",
          "R5.4.e",
          "R5.5.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Embedded Linux retains the full compatible host profile on pinned `linux-arm64`/`linux-riscv64` systems. MCU profiles name exact CoreForm, type, numeric, allocation, recursion, concurrency, effect, panic, and library subsets; unsupported full-language behavior is diagnosed before code generation.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.9.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Embedded Linux retains the full compatible host profile on pinned `linux-arm64`/`linux-riscv64` systems. MCU profiles name exact CoreForm, type, numeric, allocation, recursion, concurrency, effect, panic, and library subsets; unsupported full-language behavior is diagnosed before code generation.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R2.2.f",
        "R3.2.d",
        "R5.1.e",
        "R5.4.e",
        "R5.5.f"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1323,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Define Embedded Linux and MCU profiles separately",
      "unsatisfied_prerequisites": [
        "R3.2.d",
        "R5.4.e",
        "R5.5.f"
      ],
      "workstream": "R5.9"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R2.2.f",
          "R3.2.d",
          "R5.1.e",
          "R5.4.e",
          "R5.5.f",
          "R5.9.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Whole-program analysis computes flash/ROM, static RAM, stack per task/interrupt, bounded arena/heap, handles, queues, DMA buffers, timing classes, and peripheral ownership. Dynamic dispatch, recursion, allocation, or effect bounds that cannot be proven require an explicit larger profile or fail closed.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.9.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Whole-program analysis computes flash/ROM, static RAM, stack per task/interrupt, bounded arena/heap, handles, queues, DMA buffers, timing classes, and peripheral ownership. Dynamic dispatch, recursion, allocation, or effect bounds that cannot be proven require an explicit larger profile or fail closed.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R2.2.f",
        "R3.2.d",
        "R5.1.e",
        "R5.4.e",
        "R5.5.f",
        "R5.9.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1324,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add closed-world static resource verification",
      "unsatisfied_prerequisites": [
        "R3.2.d",
        "R5.4.e",
        "R5.5.f",
        "R5.9.a"
      ],
      "workstream": "R5.9"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R2.2.f",
          "R3.2.d",
          "R5.1.e",
          "R5.4.e",
          "R5.5.f",
          "R5.9.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Interrupt handlers, priorities, critical sections, atomics, timers, watchdogs, RTOS tasks, cancellation, deadlines, power/sleep transitions, startup/reset, and crash persistence have deterministic core rules and clearly delimited hardware nondeterminism.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.9.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Interrupt handlers, priorities, critical sections, atomics, timers, watchdogs, RTOS tasks, cancellation, deadlines, power/sleep transitions, startup/reset, and crash persistence have deterministic core rules and clearly delimited hardware nondeterminism.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R2.2.f",
        "R3.2.d",
        "R5.1.e",
        "R5.4.e",
        "R5.5.f",
        "R5.9.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1325,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Specify real-time and interrupt semantics",
      "unsatisfied_prerequisites": [
        "R3.2.d",
        "R5.4.e",
        "R5.5.f",
        "R5.9.b"
      ],
      "workstream": "R5.9"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R2.2.f",
          "R3.2.d",
          "R5.1.e",
          "R5.4.e",
          "R5.5.f",
          "R5.9.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Board manifests grant typed ownership of GPIO, ADC/DAC, PWM, timers, I2C, SPI, UART, CAN, USB, storage, display, audio, camera, sensors, motors, BLE, Wi-Fi, and Ethernet resources. Pin conflicts, voltage/mode errors, concurrent ownership, unsafe ISR calls, and unavailable peripherals fail before flash.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.9.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "Board manifests grant typed ownership of GPIO, ADC/DAC, PWM, timers, I2C, SPI, UART, CAN, USB, storage, display, audio, camera, sensors, motors, BLE, Wi-Fi, and Ethernet resources. Pin conflicts, voltage/mode errors, concurrent ownership, unsafe ISR calls, and unavailable peripherals fail before flash.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R2.2.f",
        "R3.2.d",
        "R5.1.e",
        "R5.4.e",
        "R5.5.f",
        "R5.9.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1326,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Define capability-safe HAL APIs",
      "unsatisfied_prerequisites": [
        "R3.2.d",
        "R5.4.e",
        "R5.5.f",
        "R5.9.c"
      ],
      "workstream": "R5.9"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R2.2.f",
          "R3.2.d",
          "R5.1.e",
          "R5.4.e",
          "R5.5.f",
          "R5.9.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "MQTT/CoAP or selected profiled protocols, device identity/provisioning, secure boot/update hooks, telemetry, local rules, time synchronization, sensor fusion, motor control, safety stops, digital-twin simulation, and fleet policy remain self-hostable and capability-minimal.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.9.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "MQTT/CoAP or selected profiled protocols, device identity/provisioning, secure boot/update hooks, telemetry, local rules, time synchronization, sensor fusion, motor control, safety stops, digital-twin simulation, and fleet policy remain self-hostable and capability-minimal.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R2.2.f",
        "R3.2.d",
        "R5.1.e",
        "R5.4.e",
        "R5.5.f",
        "R5.9.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1327,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Build IoT and robotics packages",
      "unsatisfied_prerequisites": [
        "R3.2.d",
        "R5.4.e",
        "R5.5.f",
        "R5.9.d"
      ],
      "workstream": "R5.9"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/PAPER_v0.2.md",
          "docs/TECH_HANDOFF.md",
          "docs/spec",
          "crates/gc_types",
          "crates/gc_coreform",
          "crates/gc_prelude"
        ],
        "prerequisite_task_ids": [
          "R0.1.h",
          "R2.2.f",
          "R3.2.d",
          "R5.1.e",
          "R5.4.e",
          "R5.5.f",
          "R5.9.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "The MCU AOT backend validates each accepted program against authoritative semantics for the embedded subset; fixed-width arithmetic, memory layout, volatile I/O, interrupt observations, and hardware faults use explicit target profiles and never masquerade as full-host equivalence.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_foundation_stdlib_conformance.sh",
        "scripts/check_host_abi_conformance.sh",
        "scripts/check_no_user_panics.sh"
      ],
      "id": "R5.9.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject undocumented semantics, profile confusion, ambient authority, and cross-host identity drift"
      ],
      "objective": "The MCU AOT backend validates each accepted program against authoritative semantics for the embedded subset; fixed-width arithmetic, memory layout, volatile I/O, interrupt observations, and hardware faults use explicit target profiles and never masquerade as full-host equivalence.",
      "owner_paths": [
        "docs/PAPER_v0.2.md",
        "docs/TECH_HANDOFF.md",
        "docs/spec",
        "crates/gc_types",
        "crates/gc_coreform",
        "crates/gc_prelude"
      ],
      "parallel_safe_with": [],
      "phase": "R5",
      "prerequisites": [
        "R0.1.h",
        "R2.2.f",
        "R3.2.d",
        "R5.1.e",
        "R5.4.e",
        "R5.5.f",
        "R5.9.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1328,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Preserve semantic identity across constrained compilation",
      "unsatisfied_prerequisites": [
        "R3.2.d",
        "R5.4.e",
        "R5.5.f",
        "R5.9.e"
      ],
      "workstream": "R5.9"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R4.2.g",
          "R5.3.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Canonical dependency identities, features/profiles, capabilities, targets, evidence requirements, source substitutions, and migrations are versioned.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.1.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Canonical dependency identities, features/profiles, capabilities, targets, evidence requirements, source substitutions, and migrations are versioned.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R4.2.g",
        "R5.3.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1340,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Freeze manifest/lock schemas",
      "unsatisfied_prerequisites": [
        "R4.2.g"
      ],
      "workstream": "R6.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R4.2.g",
          "R5.3.e",
          "R6.1.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Same repository snapshot and policy produces the same graph or exact conflict proof across hosts; no unlogged ambient registry state.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.1.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Same repository snapshot and policy produces the same graph or exact conflict proof across hosts; no unlogged ambient registry state.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R4.2.g",
        "R5.3.e",
        "R6.1.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1341,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Make resolution deterministic",
      "unsatisfied_prerequisites": [
        "R4.2.g",
        "R6.1.a"
      ],
      "workstream": "R6.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R4.2.g",
          "R5.3.e",
          "R6.1.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Incremental resolution, shared caches, semantic diffs, atomic updates, offline mode, vendoring, and policy review meet large-workspace budgets.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.1.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Incremental resolution, shared caches, semantic diffs, atomic updates, offline mode, vendoring, and policy review meet large-workspace budgets.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R4.2.g",
        "R5.3.e",
        "R6.1.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1342,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add workspace-scale operations",
      "unsatisfied_prerequisites": [
        "R4.2.g",
        "R6.1.b"
      ],
      "workstream": "R6.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R4.2.g",
          "R5.3.e",
          "R6.1.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Prefer declarative GenesisCode build actions; any host process hook requires explicit capability, sandbox, provenance, and noninteractive behavior.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.1.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Prefer declarative GenesisCode build actions; any host process hook requires explicit capability, sandbox, provenance, and noninteractive behavior.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R4.2.g",
        "R5.3.e",
        "R6.1.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1343,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Verify lifecycle scripts by construction",
      "unsatisfied_prerequisites": [
        "R4.2.g",
        "R6.1.c"
      ],
      "workstream": "R6.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R6.1.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Single-node/offline use is complete; replication/mirroring is optional. No mandatory external account or hosted control plane.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.2.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Single-node/offline use is complete; replication/mirroring is optional. No mandatory external account or hosted control plane.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R0.2.h",
        "R6.1.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1347,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Ship a local registry distribution",
      "unsatisfied_prerequisites": [
        "R6.1.d"
      ],
      "workstream": "R6.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R6.1.d",
          "R6.2.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Append-only publish records, inclusion/consistency proofs, content-addressed blobs, namespace policy, and mirrored verification.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.2.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Append-only publish records, inclusion/consistency proofs, content-addressed blobs, namespace policy, and mirrored verification.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R0.2.h",
        "R6.1.d",
        "R6.2.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1348,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add transparency and immutability",
      "unsatisfied_prerequisites": [
        "R6.1.d",
        "R6.2.a"
      ],
      "workstream": "R6.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R6.1.d",
          "R6.2.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Profile TUF-compatible threshold roles, delegated scopes, offline roots, freshness, rollback/freeze protection, compromise recovery, expiry, and reproducible key-policy tests; bind package evidence/transparency data without weakening TUF client rules.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.2.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Profile TUF-compatible threshold roles, delegated scopes, offline roots, freshness, rollback/freeze protection, compromise recovery, expiry, and reproducible key-policy tests; bind package evidence/transparency data without weakening TUF client rules.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R0.2.h",
        "R6.1.d",
        "R6.2.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1349,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Implement signing and rotation",
      "unsatisfied_prerequisites": [
        "R6.1.d",
        "R6.2.b"
      ],
      "workstream": "R6.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R6.1.d",
          "R6.2.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Registry acceptance checks source/artifact identity, compatibility, capabilities, obligations, reproducibility level, SBOM, provenance, and malware/policy scans without trusting publisher prose.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.2.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Registry acceptance checks source/artifact identity, compatibility, capabilities, obligations, reproducibility level, SBOM, provenance, and malware/policy scans without trusting publisher prose.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R0.2.h",
        "R6.1.d",
        "R6.2.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1350,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Enforce evidence policy",
      "unsatisfied_prerequisites": [
        "R6.1.d",
        "R6.2.c"
      ],
      "workstream": "R6.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R6.1.d",
          "R6.2.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Export/import bundles preserve proofs, policy, revocations, dependency closure, and audit history.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.2.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Export/import bundles preserve proofs, policy, revocations, dependency closure, and audit history.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R0.2.h",
        "R6.1.d",
        "R6.2.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1351,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Support air-gapped promotion",
      "unsatisfied_prerequisites": [
        "R6.1.d",
        "R6.2.d"
      ],
      "workstream": "R6.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R4.2.g",
          "R5.5.f",
          "R6.1.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Profile native CLI/service, self-contained desktop, static/SPA/SSR/PWA web, WASI/component, edge/serverless, OCI/system service, iOS, Android, embedded Linux, and constrained MCU firmware separately. Each binds exact host/architecture/SDK/BSP/runtime, supported language/library/capability subset, artifact/install/launch contract, resource envelope, signing/update policy, and evidence level. A shared product may select several profiles, but an unavailable target fails before build.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.3.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Profile native CLI/service, self-contained desktop, static/SPA/SSR/PWA web, WASI/component, edge/serverless, OCI/system service, iOS, Android, embedded Linux, and constrained MCU firmware separately. Each binds exact host/architecture/SDK/BSP/runtime, supported language/library/capability subset, artifact/install/launch contract, resource envelope, signing/update policy, and evidence level. A shared product may select several profiles, but an unavailable target fails before build.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R4.2.g",
        "R5.5.f",
        "R6.1.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1355,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Define target profiles and promotion tiers",
      "unsatisfied_prerequisites": [
        "R4.2.g",
        "R5.5.f",
        "R6.1.d"
      ],
      "workstream": "R6.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R4.2.g",
          "R5.5.f",
          "R6.1.d",
          "R6.3.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "One self-hosted build graph emits target artifacts, capability manifests, runtime requirements, a profiled SPDX SBOM, in-toto/SLSA provenance, and Genesis evidence pointers.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.3.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "One self-hosted build graph emits target artifacts, capability manifests, runtime requirements, a profiled SPDX SBOM, in-toto/SLSA provenance, and Genesis evidence pointers.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R4.2.g",
        "R5.5.f",
        "R6.1.d",
        "R6.3.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1356,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Implement `genesis build`",
      "unsatisfied_prerequisites": [
        "R4.2.g",
        "R5.5.f",
        "R6.1.d",
        "R6.3.a"
      ],
      "workstream": "R6.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R4.2.g",
          "R5.5.f",
          "R6.1.d",
          "R6.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Normalize paths/timestamps/order/archives; pin base images and SDK identities; compare independent outputs.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.3.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Normalize paths/timestamps/order/archives; pin base images and SDK identities; compare independent outputs.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R4.2.g",
        "R5.5.f",
        "R6.1.d",
        "R6.3.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1357,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Make builds reproducible",
      "unsatisfied_prerequisites": [
        "R4.2.g",
        "R5.5.f",
        "R6.1.d",
        "R6.3.b"
      ],
      "workstream": "R6.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R4.2.g",
          "R5.5.f",
          "R6.1.d",
          "R6.3.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Tree-shake unused Prelude/capabilities, strip evidence duplication without losing verification, and report size/startup/memory budgets per target.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.3.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Tree-shake unused Prelude/capabilities, strip evidence duplication without losing verification, and report size/startup/memory budgets per target.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R4.2.g",
        "R5.5.f",
        "R6.1.d",
        "R6.3.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1358,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Minimize artifacts",
      "unsatisfied_prerequisites": [
        "R4.2.g",
        "R5.5.f",
        "R6.1.d",
        "R6.3.c"
      ],
      "workstream": "R6.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R4.2.g",
          "R5.5.f",
          "R6.1.d",
          "R6.3.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Normative programs produce the same semantic result/effects or an explicitly declared target limitation.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.3.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Normative programs produce the same semantic result/effects or an explicitly declared target limitation.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R4.2.g",
        "R5.5.f",
        "R6.1.d",
        "R6.3.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1359,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Validate target parity",
      "unsatisfied_prerequisites": [
        "R4.2.g",
        "R5.5.f",
        "R6.1.d",
        "R6.3.d"
      ],
      "workstream": "R6.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R4.2.g",
          "R5.5.f",
          "R6.1.d",
          "R6.3.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Replace current descriptor, empty-export, and synthetic launcher smoke paths with target-native executable entrypoints. Tests install or start each artifact in its declared runtime, cross the real process/browser/device boundary, exercise application logic and at least one scoped effect, collect logs/crashes/resources, and reject an archive whose suffix or metadata is the only target-specific property.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.3.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Replace current descriptor, empty-export, and synthetic launcher smoke paths with target-native executable entrypoints. Tests install or start each artifact in its declared runtime, cross the real process/browser/device boundary, exercise application logic and at least one scoped effect, collect logs/crashes/resources, and reject an archive whose suffix or metadata is the only target-specific property.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R4.2.g",
        "R5.5.f",
        "R6.1.d",
        "R6.3.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1360,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Enforce authentic-artifact qualification",
      "unsatisfied_prerequisites": [
        "R4.2.g",
        "R5.5.f",
        "R6.1.d",
        "R6.3.e"
      ],
      "workstream": "R6.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R4.2.g",
          "R5.5.f",
          "R6.1.d",
          "R6.3.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Platform projects, HTML/CSS/JavaScript adapters, Swift/Kotlin/XML, C startup/link files, shaders, container/unit manifests, and deployment configuration live in declared generated roots, carry source maps and input identities, are never hand-edited, and reproduce after deletion. Build diagnostics map failures back to Genesis source or a typed toolchain/SDK gap.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.3.g",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Platform projects, HTML/CSS/JavaScript adapters, Swift/Kotlin/XML, C startup/link files, shaders, container/unit manifests, and deployment configuration live in declared generated roots, carry source maps and input identities, are never hand-edited, and reproduce after deletion. Build diagnostics map failures back to Genesis source or a typed toolchain/SDK gap.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R4.2.g",
        "R5.5.f",
        "R6.1.d",
        "R6.3.f"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1361,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Make generated glue disposable and non-authoritative",
      "unsatisfied_prerequisites": [
        "R4.2.g",
        "R5.5.f",
        "R6.1.d",
        "R6.3.f"
      ],
      "workstream": "R6.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R6.3.g"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Agents receive a reviewable diff of artifacts, capabilities, secrets, network exposure, storage, rollback, and evidence.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.4.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Agents receive a reviewable diff of artifacts, capabilities, secrets, network exposure, storage, rollback, and evidence.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R6.3.g"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1365,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Generate deploy plans, never hidden imperative magic",
      "unsatisfied_prerequisites": [
        "R6.3.g"
      ],
      "workstream": "R6.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R6.3.g",
          "R6.4.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Service upgrades and data migrations are bounded, idempotent where required, observable, and reversible or explicitly irreversible.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.4.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Service upgrades and data migrations are bounded, idempotent where required, observable, and reversible or explicitly irreversible.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R6.3.g",
        "R6.4.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1366,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add health, migration, rollback, and recovery contracts",
      "unsatisfied_prerequisites": [
        "R6.3.g",
        "R6.4.a"
      ],
      "workstream": "R6.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R6.3.g",
          "R6.4.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Secret values never enter canonical source, logs, diagnostics, model contexts, or evidence; only references/policy and redacted attestations do.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.4.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Secret values never enter canonical source, logs, diagnostics, model contexts, or evidence; only references/policy and redacted attestations do.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R6.3.g",
        "R6.4.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1367,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Handle secrets safely",
      "unsatisfied_prerequisites": [
        "R6.3.g",
        "R6.4.b"
      ],
      "workstream": "R6.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R6.3.g",
          "R6.4.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Running instances can report the exact package/artifact/evidence/profile identity without exposing secrets.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.4.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Running instances can report the exact package/artifact/evidence/profile identity without exposing secrets.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R6.3.g",
        "R6.4.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1368,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Verify deployment provenance",
      "unsatisfied_prerequisites": [
        "R6.3.g",
        "R6.4.c"
      ],
      "workstream": "R6.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R6.3.g",
          "R6.4.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Express machines, containers, services, routes, certificates, storage, queues, schedules, health, scaling bounds, updates, and rollback in typed Genesis data. Generate reviewable systemd/OCI/Kubernetes/edge/provider adapters where selected, but retain a direct single-machine path and never require users to author shell or YAML.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.4.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Express machines, containers, services, routes, certificates, storage, queues, schedules, health, scaling bounds, updates, and rollback in typed Genesis data. Generate reviewable systemd/OCI/Kubernetes/edge/provider adapters where selected, but retain a direct single-machine path and never require users to author shell or YAML.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R6.3.g",
        "R6.4.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1369,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Build a self-hostable deployment IR",
      "unsatisfied_prerequisites": [
        "R6.3.g",
        "R6.4.d"
      ],
      "workstream": "R6.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R6.3.g",
          "R6.4.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Deployments bind dashboards/queries/alerts/runbooks to application schemas, preserve redaction and tenant boundaries, capture crash/replay/evidence bundles, and rehearse backup, restore, regional/host loss, certificate/key rotation, and compromised release rollback.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.4.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Deployments bind dashboards/queries/alerts/runbooks to application schemas, preserve redaction and tenant boundaries, capture crash/replay/evidence bundles, and rehearse backup, restore, regional/host loss, certificate/key rotation, and compromised release rollback.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R6.3.g",
        "R6.4.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1370,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Close application observability and incident response",
      "unsatisfied_prerequisites": [
        "R6.3.g",
        "R6.4.e"
      ],
      "workstream": "R6.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R5.6.f",
          "R5.7.c",
          "R5.7.f",
          "R6.3.g",
          "R6.4.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Incremental route/view/style/asset compilation, SSR and browser bundles, hot reload, source-mapped diagnostics, local TLS, API proxying, deterministic fixtures, and offline operation use the same build graph and never require Node as an application-level dependency.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.5.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Incremental route/view/style/asset compilation, SSR and browser bundles, hot reload, source-mapped diagnostics, local TLS, API proxying, deterministic fixtures, and offline operation use the same build graph and never require Node as an application-level dependency.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R5.6.f",
        "R5.7.c",
        "R5.7.f",
        "R6.3.g",
        "R6.4.f"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1376,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Ship the Genesis web compiler and development server",
      "unsatisfied_prerequisites": [
        "R5.6.f",
        "R5.7.c",
        "R5.7.f",
        "R6.3.g",
        "R6.4.f"
      ],
      "workstream": "R6.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R5.6.f",
          "R5.7.c",
          "R5.7.f",
          "R6.3.g",
          "R6.4.f",
          "R6.5.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Emit static hosting bundles, self-hosted SSR services, portable edge components, service workers/PWA packages, integrity/CSP metadata, cache policy, redirects/headers, sitemap/feed/metadata, and optional OCI artifacts from one Genesis workspace.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.5.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Emit static hosting bundles, self-hosted SSR services, portable edge components, service workers/PWA packages, integrity/CSP metadata, cache policy, redirects/headers, sitemap/feed/metadata, and optional OCI artifacts from one Genesis workspace.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R5.6.f",
        "R5.7.c",
        "R5.7.f",
        "R6.3.g",
        "R6.4.f",
        "R6.5.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1377,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Produce standards-valid deployable sites and applications",
      "unsatisfied_prerequisites": [
        "R5.6.f",
        "R5.7.c",
        "R5.7.f",
        "R6.3.g",
        "R6.4.f",
        "R6.5.a"
      ],
      "workstream": "R6.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R5.6.f",
          "R5.7.c",
          "R5.7.f",
          "R6.3.g",
          "R6.4.f",
          "R6.5.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Test supported browser engines and mobile viewports for routing, forms, storage, workers, offline/online transitions, WebSocket, accessibility, security policy, hydration, update/rollback, and performance. Generated output is inspected for deterministic identity, dead-code/asset elimination, and absence of undeclared network dependencies.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.5.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Test supported browser engines and mobile viewports for routing, forms, storage, workers, offline/online transitions, WebSocket, accessibility, security policy, hydration, update/rollback, and performance. Generated output is inspected for deterministic identity, dead-code/asset elimination, and absence of undeclared network dependencies.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R5.6.f",
        "R5.7.c",
        "R5.7.f",
        "R6.3.g",
        "R6.4.f",
        "R6.5.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1378,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Prove real browser behavior",
      "unsatisfied_prerequisites": [
        "R5.6.f",
        "R5.7.c",
        "R5.7.f",
        "R6.3.g",
        "R6.4.f",
        "R6.5.b"
      ],
      "workstream": "R6.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R5.6.f",
          "R5.7.c",
          "R5.7.f",
          "R6.3.g",
          "R6.4.f",
          "R6.5.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Authentication, authorization, database/migrations, background work, file/object storage, email substitute, realtime updates, observability, backup/restore, deployment, and seeded maintenance are implemented in GenesisCode and run self-hosted end to end.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.5.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Authentication, authorization, database/migrations, background work, file/object storage, email substitute, realtime updates, observability, backup/restore, deployment, and seeded maintenance are implemented in GenesisCode and run self-hosted end to end.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R5.6.f",
        "R5.7.c",
        "R5.7.f",
        "R6.3.g",
        "R6.4.f",
        "R6.5.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1379,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Ship a maintained full-stack reference product",
      "unsatisfied_prerequisites": [
        "R5.6.f",
        "R5.7.c",
        "R5.7.f",
        "R6.3.g",
        "R6.4.f",
        "R6.5.c"
      ],
      "workstream": "R6.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R5.6.f",
          "R5.8.f",
          "R6.3.g",
          "R6.4.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Generate signed/installable macOS, Windows, and Linux packages with a Genesis runtime/component, native windows, menus, tray, dialogs, clipboard, drag/drop, notifications, file associations, deep links, accessibility, GPU/audio/input, crash capture, auto-update, and rollback. Headless CI is supplemented by real OS launch and interaction evidence.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.6.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Generate signed/installable macOS, Windows, and Linux packages with a Genesis runtime/component, native windows, menus, tray, dialogs, clipboard, drag/drop, notifications, file associations, deep links, accessibility, GPU/audio/input, crash capture, auto-update, and rollback. Headless CI is supplemented by real OS launch and interaction evidence.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R5.6.f",
        "R5.8.f",
        "R6.3.g",
        "R6.4.f"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1383,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Build real desktop applications",
      "unsatisfied_prerequisites": [
        "R5.6.f",
        "R5.8.f",
        "R6.3.g",
        "R6.4.f"
      ],
      "workstream": "R6.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R5.6.f",
          "R5.8.f",
          "R6.3.g",
          "R6.4.f",
          "R6.6.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Generate complete Xcode/Gradle projects as disposable outputs, compile/link the Genesis runtime and app, package valid signed `.ipa`/`.aab` artifacts, and support lifecycle, navigation/UI, touch/keyboard, accessibility, permissions, storage, networking, background modes, notifications, deep links, camera/media/location/sensors where profiled, crash evidence, and deterministic app data migration.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.6.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Generate complete Xcode/Gradle projects as disposable outputs, compile/link the Genesis runtime and app, package valid signed `.ipa`/`.aab` artifacts, and support lifecycle, navigation/UI, touch/keyboard, accessibility, permissions, storage, networking, background modes, notifications, deep links, camera/media/location/sensors where profiled, crash evidence, and deterministic app data migration.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R5.6.f",
        "R5.8.f",
        "R6.3.g",
        "R6.4.f",
        "R6.6.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1384,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Build real iOS and Android applications",
      "unsatisfied_prerequisites": [
        "R5.6.f",
        "R5.8.f",
        "R6.3.g",
        "R6.4.f",
        "R6.6.a"
      ],
      "workstream": "R6.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R5.6.f",
          "R5.8.f",
          "R6.3.g",
          "R6.4.f",
          "R6.6.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Simulator/emulator matrices plus named physical devices test install, first launch, suspend/resume, process death, permission denial/revocation, rotation/window changes, offline recovery, low memory/disk, upgrade/downgrade policy, and uninstall/data retention. Store submission remains an explicit operator-approved effect with reproducible unsigned inputs and separately managed credentials.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.6.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Simulator/emulator matrices plus named physical devices test install, first launch, suspend/resume, process death, permission denial/revocation, rotation/window changes, offline recovery, low memory/disk, upgrade/downgrade policy, and uninstall/data retention. Store submission remains an explicit operator-approved effect with reproducible unsigned inputs and separately managed credentials.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R5.6.f",
        "R5.8.f",
        "R6.3.g",
        "R6.4.f",
        "R6.6.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1385,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Automate platform qualification",
      "unsatisfied_prerequisites": [
        "R5.6.f",
        "R5.8.f",
        "R6.3.g",
        "R6.4.f",
        "R6.6.b"
      ],
      "workstream": "R6.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R5.6.f",
          "R5.8.f",
          "R6.3.g",
          "R6.4.f",
          "R6.6.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "A reference app shares Genesis business logic, schemas, tests, state/update/view code, and assets across web, desktop, iOS, and Android while recording target-specific code, capability, artifact-size, startup, memory, accessibility, and maintenance deltas. No percentage claim hides generated or duplicated code.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.6.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "A reference app shares Genesis business logic, schemas, tests, state/update/view code, and assets across web, desktop, iOS, and Android while recording target-specific code, capability, artifact-size, startup, memory, accessibility, and maintenance deltas. No percentage claim hides generated or duplicated code.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R5.6.f",
        "R5.8.f",
        "R6.3.g",
        "R6.4.f",
        "R6.6.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1386,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Prove shared-product reuse honestly",
      "unsatisfied_prerequisites": [
        "R5.6.f",
        "R5.8.f",
        "R6.3.g",
        "R6.4.f",
        "R6.6.c"
      ],
      "workstream": "R6.6"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R5.7.c",
          "R5.7.f",
          "R5.9.f",
          "R6.3.g",
          "R6.4.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Produce reproducible `linux-arm64` images/packages for Raspberry Pi-class boards with service/UI modes, GPIO/I2C/SPI/UART access, device-tree/udev/system integration through capabilities, cross-build and native-build parity, remote deploy/debug, read-only/offline operation, update/rollback, and power-loss recovery.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.7.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Produce reproducible `linux-arm64` images/packages for Raspberry Pi-class boards with service/UI modes, GPIO/I2C/SPI/UART access, device-tree/udev/system integration through capabilities, cross-build and native-build parity, remote deploy/debug, read-only/offline operation, update/rollback, and power-loss recovery.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R5.7.c",
        "R5.7.f",
        "R5.9.f",
        "R6.3.g",
        "R6.4.f"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1390,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Promote Embedded Linux first",
      "unsatisfied_prerequisites": [
        "R5.7.c",
        "R5.7.f",
        "R5.9.f",
        "R6.3.g",
        "R6.4.f"
      ],
      "workstream": "R6.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R5.7.c",
          "R5.7.f",
          "R5.9.f",
          "R6.3.g",
          "R6.4.f",
          "R6.7.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Compile the R5.9 subset to validated machine/object code or a proven minimal runtime; generate startup, vector table, linker layout, BSP/HAL bindings, memory map, debug symbols, firmware image, SBOM, provenance, and flash plan. Host Rust/C toolchains may be pinned implementation dependencies, but users author no C/C++/linker/startup source.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.7.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Compile the R5.9 subset to validated machine/object code or a proven minimal runtime; generate startup, vector table, linker layout, BSP/HAL bindings, memory map, debug symbols, firmware image, SBOM, provenance, and flash plan. Host Rust/C toolchains may be pinned implementation dependencies, but users author no C/C++/linker/startup source.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R5.7.c",
        "R5.7.f",
        "R5.9.f",
        "R6.3.g",
        "R6.4.f",
        "R6.7.a"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1391,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Implement a closed-world MCU AOT pipeline",
      "unsatisfied_prerequisites": [
        "R5.7.c",
        "R5.7.f",
        "R5.9.f",
        "R6.3.g",
        "R6.4.f",
        "R6.7.a"
      ],
      "workstream": "R6.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R5.7.c",
          "R5.7.f",
          "R5.9.f",
          "R6.3.g",
          "R6.4.f",
          "R6.7.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Reach L4 on at least RP2040, a RISC-V ESP32 profile, an Xtensa ESP32 profile where the pinned toolchain is reproducible, and one Arduino-compatible constrained board; add new boards through signed BSP packages and conformance kits rather than compiler special cases.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.7.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Reach L4 on at least RP2040, a RISC-V ESP32 profile, an Xtensa ESP32 profile where the pinned toolchain is reproducible, and one Arduino-compatible constrained board; add new boards through signed BSP packages and conformance kits rather than compiler special cases.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R5.7.c",
        "R5.7.f",
        "R5.9.f",
        "R6.3.g",
        "R6.4.f",
        "R6.7.b"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1392,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Establish representative board families",
      "unsatisfied_prerequisites": [
        "R5.7.c",
        "R5.7.f",
        "R5.9.f",
        "R6.3.g",
        "R6.4.f",
        "R6.7.b"
      ],
      "workstream": "R6.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R5.7.c",
          "R5.7.f",
          "R5.9.f",
          "R6.3.g",
          "R6.4.f",
          "R6.7.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Deterministic peripheral models and QEMU/Renode or selected open simulators run ordinary CI; isolated physical rigs flash, power-cycle, capture serial/debug traces, inject peripheral/network/power faults, measure timing/memory/power, and retain signed evidence without exposing lab control as application authority.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.7.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Deterministic peripheral models and QEMU/Renode or selected open simulators run ordinary CI; isolated physical rigs flash, power-cycle, capture serial/debug traces, inject peripheral/network/power faults, measure timing/memory/power, and retain signed evidence without exposing lab control as application authority.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R5.7.c",
        "R5.7.f",
        "R5.9.f",
        "R6.3.g",
        "R6.4.f",
        "R6.7.c"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1393,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Build board simulation and hardware-in-the-loop infrastructure",
      "unsatisfied_prerequisites": [
        "R5.7.c",
        "R5.7.f",
        "R5.9.f",
        "R6.3.g",
        "R6.4.f",
        "R6.7.c"
      ],
      "workstream": "R6.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R5.7.c",
          "R5.7.f",
          "R5.9.f",
          "R6.3.g",
          "R6.4.f",
          "R6.7.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "`genesis device` discovers only explicitly authorized boards, explains pin/resource plans, flashes/verifies, opens bounded serial/debug sessions, captures crash dumps, provisions secrets without logging values, performs signed A/B OTA with rollback, and recovers bricked/interrupted updates where the board permits.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.7.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "`genesis device` discovers only explicitly authorized boards, explains pin/resource plans, flashes/verifies, opens bounded serial/debug sessions, captures crash dumps, provisions secrets without logging values, performs signed A/B OTA with rollback, and recovers bricked/interrupted updates where the board permits.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R5.7.c",
        "R5.7.f",
        "R5.9.f",
        "R6.3.g",
        "R6.4.f",
        "R6.7.d"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1394,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Complete flash, debug, and OTA lifecycle",
      "unsatisfied_prerequisites": [
        "R5.7.c",
        "R5.7.f",
        "R5.9.f",
        "R6.3.g",
        "R6.4.f",
        "R6.7.d"
      ],
      "workstream": "R6.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "crates/gc_pkg",
          "crates/gc_registry",
          "crates/gc_vcs",
          "examples",
          "docs/spec"
        ],
        "prerequisite_task_ids": [
          "R5.7.c",
          "R5.7.f",
          "R5.9.f",
          "R6.3.g",
          "R6.4.f",
          "R6.7.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Required proofs include a Raspberry Pi edge service/UI, RP2040 sensor/control firmware, ESP32 connected device with offline behavior and signed OTA, and an Arduino-compatible teaching/control workload. Each has a digital-twin test, physical-device test, enclosure/power assumptions, and seeded maintenance task authored entirely in GenesisCode.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_gcpm_operation_contract_pack.sh",
        "scripts/check_remote_registry_runtime_parity.sh",
        "scripts/check_gcpm_target_runtime_pipelines.sh"
      ],
      "id": "R6.7.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject mutable resolution, signature or rollback bypass, secret disclosure, non-reproducible artifacts, and undeclared deployment effects"
      ],
      "objective": "Required proofs include a Raspberry Pi edge service/UI, RP2040 sensor/control firmware, ESP32 connected device with offline behavior and signed OTA, and an Arduino-compatible teaching/control workload. Each has a digital-twin test, physical-device test, enclosure/power assumptions, and seeded maintenance task authored entirely in GenesisCode.",
      "owner_paths": [
        "crates/gc_pkg",
        "crates/gc_registry",
        "crates/gc_vcs",
        "examples",
        "docs/spec"
      ],
      "parallel_safe_with": [],
      "phase": "R6",
      "prerequisites": [
        "R5.7.c",
        "R5.7.f",
        "R5.9.f",
        "R6.3.g",
        "R6.4.f",
        "R6.7.e"
      ],
      "resource_class": "build",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1395,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Ship maintained hardware products",
      "unsatisfied_prerequisites": [
        "R5.7.c",
        "R5.7.f",
        "R5.9.f",
        "R6.3.g",
        "R6.4.f",
        "R6.7.e"
      ],
      "workstream": "R6.7"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R0.4.j"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Unit, semantic golden, negative boundary, property, differential, mutation, fuzz, model-check, integration, host-matrix, benchmark, proof, and release tests have explicit profiles and owners.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.1.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Unit, semantic golden, negative boundary, property, differential, mutation, fuzz, model-check, integration, host-matrix, benchmark, proof, and release tests have explicit profiles and owners.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R0.2.h",
        "R0.4.j"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1407,
        "path": "ROADMAP.md"
      },
      "start_ready": true,
      "state": "open",
      "title": "Classify the suite",
      "unsatisfied_prerequisites": [],
      "workstream": "R7.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R0.4.j",
          "R7.1.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Generate valid and near-valid terms with effect/resource/profile annotations; preserve failure while minimizing counterexamples.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.1.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Generate valid and near-valid terms with effect/resource/profile annotations; preserve failure while minimizing counterexamples.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R0.2.h",
        "R0.4.j",
        "R7.1.a"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1408,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add grammar/AST/CoreForm generators and shrinkers",
      "unsatisfied_prerequisites": [
        "R7.1.a"
      ],
      "workstream": "R7.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R0.4.j",
          "R7.1.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Source, CoreForm/artifacts, GCLOG, evidence, packages, locks, patches, bytecode, Wasm/component, protocols, and registry inputs must be bounded and panic-free.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.1.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Source, CoreForm/artifacts, GCLOG, evidence, packages, locks, patches, bytecode, Wasm/component, protocols, and registry inputs must be bounded and panic-free.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R0.2.h",
        "R0.4.j",
        "R7.1.b"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1409,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Fuzz every parser and decoder",
      "unsatisfied_prerequisites": [
        "R7.1.b"
      ],
      "workstream": "R7.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R0.4.j",
          "R7.1.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Partial reads/writes, ENOSPC, permission races, process hangs, crashes, corrupt caches, lost network, clock anomalies, cancellation, and concurrent updates fail closed.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.1.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Partial reads/writes, ENOSPC, permission races, process hangs, crashes, corrupt caches, lost network, clock anomalies, cancellation, and concurrent updates fail closed.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R0.2.h",
        "R0.4.j",
        "R7.1.c"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1410,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add fault injection",
      "unsatisfied_prerequisites": [
        "R7.1.c"
      ],
      "workstream": "R7.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R0.4.j",
          "R7.1.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Demonstrate that tests fail when capability, seal, replay, signature, hash, bootstrap, and evidence validation is intentionally weakened.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.1.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Demonstrate that tests fail when capability, seal, replay, signature, hash, bootstrap, and evidence validation is intentionally weakened.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R0.2.h",
        "R0.4.j",
        "R7.1.d"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1411,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Use mutation testing on trust checks",
      "unsatisfied_prerequisites": [
        "R7.1.d"
      ],
      "workstream": "R7.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R0.4.j",
          "R7.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Supply reusable mutation harnesses for presentation IR, generated glue, SDK/BSP identities, app/container archives, linker/memory layouts, shader/asset graphs, permission manifests, deploy plans, and device evidence. Every claimed pack binds its exact cases and proves stale, hand-edited, malformed, over-authorized, or non-executable outputs cannot qualify; completion of the harness alone qualifies no target.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.1.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Supply reusable mutation harnesses for presentation IR, generated glue, SDK/BSP identities, app/container archives, linker/memory layouts, shader/asset graphs, permission manifests, deploy plans, and device evidence. Every claimed pack binds its exact cases and proves stale, hand-edited, malformed, over-authorized, or non-executable outputs cannot qualify; completion of the harness alone qualifies no target.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R0.2.h",
        "R0.4.j",
        "R7.1.e"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1412,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Build profile-parametric adversarial qualification for product generators and target adapters",
      "unsatisfied_prerequisites": [
        "R7.1.e"
      ],
      "workstream": "R7.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.1.f",
          "R5.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Define syntax, values, evaluation, determinism, substitution/environment relation, errors, and canonicalization in Lean or the chosen proof system.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.2.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Define syntax, values, evaluation, determinism, substitution/environment relation, errors, and canonicalization in Lean or the chosen proof system.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R3.1.f",
        "R5.1.e"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1416,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Mechanize the pure core",
      "unsatisfied_prerequisites": [
        "R3.1.f"
      ],
      "workstream": "R7.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.1.f",
          "R5.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "User terms cannot forge protected variants; boundary opening preserves the intended abstraction.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.2.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "User terms cannot forge protected variants; boundary opening preserves the intended abstraction.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R3.1.f",
        "R5.1.e"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1417,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Prove seal properties",
      "unsatisfied_prerequisites": [
        "R3.1.f"
      ],
      "workstream": "R7.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.1.f",
          "R5.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Prove state-machine determinism, complete fact checking, fail-closed unknowns, and replay equivalence under the specified host assumptions.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.2.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Prove state-machine determinism, complete fact checking, fail-closed unknowns, and replay equivalence under the specified host assumptions.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R3.1.f",
        "R5.1.e"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1418,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Model effect dispatch/replay",
      "unsatisfied_prerequisites": [
        "R3.1.f"
      ],
      "workstream": "R7.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.1.f",
          "R5.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Verified bytecode cannot violate stack/frame/seal invariants and refines authoritative evaluation for the covered subset; track proof coverage explicitly.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.2.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Verified bytecode cannot violate stack/frame/seal invariants and refines authoritative evaluation for the covered subset; track proof coverage explicitly.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R3.1.f",
        "R5.1.e"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1419,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Prove bytecode safety/refinement",
      "unsatisfied_prerequisites": [
        "R3.1.f"
      ],
      "workstream": "R7.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.1.f",
          "R5.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Prove schedule-log/replay properties for the core task/channel calculus and connect executable tests to extracted/model traces.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.2.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Prove schedule-log/replay properties for the core task/channel calculus and connect executable tests to extracted/model traces.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R3.1.f",
        "R5.1.e"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1420,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Model deterministic concurrency",
      "unsatisfied_prerequisites": [
        "R3.1.f"
      ],
      "workstream": "R7.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.1.f",
          "R5.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Prove or independently cross-check injectivity/canonicality assumptions used for content identity.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.2.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Prove or independently cross-check injectivity/canonicality assumptions used for content identity.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R3.1.f",
        "R5.1.e"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1421,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Verify critical canonical codecs",
      "unsatisfied_prerequisites": [
        "R3.1.f"
      ],
      "workstream": "R7.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.1.f",
          "R5.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Prove progress/preservation or an equivalent executable safety theorem for the declared v1 fragment, including row/effect dispatch and sealed boundary behavior; publish machine-checked coverage and every excluded feature.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.2.g",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Prove progress/preservation or an equivalent executable safety theorem for the declared v1 fragment, including row/effect dispatch and sealed boundary behavior; publish machine-checked coverage and every excluded feature.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R3.1.f",
        "R5.1.e"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1422,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Establish type/effect soundness",
      "unsatisfied_prerequisites": [
        "R3.1.f"
      ],
      "workstream": "R7.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R5.5.f",
          "R6.2.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Kernel, Prelude, bridges, processes, network/server, plugins/components, model providers, package sources, registry, build workers, CI, signing, and update channels.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.3.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Kernel, Prelude, bridges, processes, network/server, plugins/components, model providers, package sources, registry, build workers, CI, signing, and update channels.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R0.2.h",
        "R5.5.f",
        "R6.2.e"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1426,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Threat-model every boundary",
      "unsatisfied_prerequisites": [
        "R5.5.f",
        "R6.2.e"
      ],
      "workstream": "R7.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R5.5.f",
          "R6.2.e",
          "R7.3.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Least privilege, hard kill/reap, syscall/filesystem/network restrictions where available, bounded IPC, and platform-specific degradation policy.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.3.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Least privilege, hard kill/reap, syscall/filesystem/network restrictions where available, bounded IPC, and platform-specific degradation policy.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R0.2.h",
        "R5.5.f",
        "R6.2.e",
        "R7.3.a"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1427,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Sandbox host execution",
      "unsatisfied_prerequisites": [
        "R5.5.f",
        "R6.2.e",
        "R7.3.a"
      ],
      "workstream": "R7.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R5.5.f",
          "R6.2.e",
          "R7.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Provenance, licenses, advisories, minimal features, checksums, vendoring/offline mirror, and update policy are part of release evidence.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.3.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Provenance, licenses, advisories, minimal features, checksums, vendoring/offline mirror, and update policy are part of release evidence.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R0.2.h",
        "R5.5.f",
        "R6.2.e",
        "R7.3.b"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1428,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Pin and audit dependencies",
      "unsatisfied_prerequisites": [
        "R5.5.f",
        "R6.2.e",
        "R7.3.b"
      ],
      "workstream": "R7.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R5.5.f",
          "R6.2.e",
          "R7.3.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Isolated signing, threshold/recovery policy, reproducible unsigned artifacts, attestations, builder identity, and independent mirrors.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.3.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Isolated signing, threshold/recovery policy, reproducible unsigned artifacts, attestations, builder identity, and independent mirrors.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R0.2.h",
        "R5.5.f",
        "R6.2.e",
        "R7.3.c"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1429,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Harden release keys and builders",
      "unsatisfied_prerequisites": [
        "R5.5.f",
        "R6.2.e",
        "R7.3.c"
      ],
      "workstream": "R7.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R5.5.f",
          "R6.2.e",
          "R7.3.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Commission or invite independent review of TCB, effects/replay, package/registry trust, bytecode verifier, and bootstrap process; track findings in `upgrade_plan.md`.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.3.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Commission or invite independent review of TCB, effects/replay, package/registry trust, bytecode verifier, and bootstrap process; track findings in `upgrade_plan.md`.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R0.2.h",
        "R5.5.f",
        "R6.2.e",
        "R7.3.d"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1430,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Run external review",
      "unsatisfied_prerequisites": [
        "R5.5.f",
        "R6.2.e",
        "R7.3.d"
      ],
      "workstream": "R7.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R0.2.h",
          "R5.5.f",
          "R6.2.e",
          "R7.3.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Cover browser injection/XSS and origin policy, native/mobile signing and permissions, game asset/shader parsing, service authentication/data isolation, cross-compilers/SDKs/BSPs, debug and provisioning ports, physical access, firmware rollback, secure boot, OTA, peripheral/DMA races, and malicious component packages. Each claimed pack binds only its applicable threats, profile-specific mitigations, residual risks, and honest hardware-root assumptions; one pack's qualification cannot satisfy or block another pack.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.3.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Cover browser injection/XSS and origin policy, native/mobile signing and permissions, game asset/shader parsing, service authentication/data isolation, cross-compilers/SDKs/BSPs, debug and provisioning ports, physical access, firmware rollback, secure boot, OTA, peripheral/DMA races, and malicious component packages. Each claimed pack binds only its applicable threats, profile-specific mitigations, residual risks, and honest hardware-root assumptions; one pack's qualification cannot satisfy or block another pack.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R0.2.h",
        "R5.5.f",
        "R6.2.e",
        "R7.3.e"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1431,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Build the profile-parametric product and hardware supply-chain gate",
      "unsatisfied_prerequisites": [
        "R5.5.f",
        "R6.2.e",
        "R7.3.e"
      ],
      "workstream": "R7.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R6.4.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "100k+ requests, cancellation storms, malformed clients, package churn, cache corruption, and constrained memory/disk.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.4.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "100k+ requests, cancellation storms, malformed clients, package churn, cache corruption, and constrained memory/disk.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R2.2.f",
        "R6.4.f"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1435,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Soak long-lived daemons/services",
      "unsatisfied_prerequisites": [
        "R6.4.f"
      ],
      "workstream": "R7.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R6.4.f",
          "R7.4.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Parser/typechecker/collections/solver/log/registry inputs have documented worst-case or enforced budgets.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.4.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Parser/typechecker/collections/solver/log/registry inputs have documented worst-case or enforced budgets.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R2.2.f",
        "R6.4.f",
        "R7.4.a"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1436,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Test adversarial complexity",
      "unsatisfied_prerequisites": [
        "R6.4.f",
        "R7.4.a"
      ],
      "workstream": "R7.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R6.4.f",
          "R7.4.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Registry restore, key compromise, corrupt release mirror, bad migration, failed bootstrap, and incompatible package release have rehearsed runbooks and automated tests.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.4.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Registry restore, key compromise, corrupt release mirror, bad migration, failed bootstrap, and incompatible package release have rehearsed runbooks and automated tests.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R2.2.f",
        "R6.4.f",
        "R7.4.b"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1437,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Validate disaster recovery",
      "unsatisfied_prerequisites": [
        "R6.4.f",
        "R7.4.b"
      ],
      "workstream": "R7.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "docs/program",
          "docs/spec",
          "crates",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R2.2.f",
          "R6.4.f",
          "R7.4.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Browser/native/mobile applications, services, games, Embedded Linux systems, and MCU firmware undergo lifecycle, update, power/network loss, resource exhaustion, malformed input, and long-duration hardware tests under their declared SLOs; emulator success cannot erase physical failures.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_no_user_panics.sh",
        "scripts/check_fuzz_differential_hardening.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R7.4.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject decorative proofs, uncovered runtime forms, unshrunk failures, and mutation suites that do not kill weakened trust checks"
      ],
      "objective": "Browser/native/mobile applications, services, games, Embedded Linux systems, and MCU firmware undergo lifecycle, update, power/network loss, resource exhaustion, malformed input, and long-duration hardware tests under their declared SLOs; emulator success cannot erase physical failures.",
      "owner_paths": [
        "docs/program",
        "docs/spec",
        "crates",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R7",
      "prerequisites": [
        "R2.2.f",
        "R6.4.f",
        "R7.4.c"
      ],
      "resource_class": "proof",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1438,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Soak real products and devices",
      "unsatisfied_prerequisites": [
        "R6.4.f",
        "R7.4.c"
      ],
      "workstream": "R7.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.5.g",
          "R1.6.f",
          "R1.7.f",
          "R6.4.f",
          "R7.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "One may be the user's AI system; one must be independently implemented. Both use the versioned cards/diagnostics/MCP protocol rather than private repo prompts.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.1.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "One may be the user's AI system; one must be independently implemented. Both use the versioned cards/diagnostics/MCP protocol rather than private repo prompts.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.5.g",
        "R1.6.f",
        "R1.7.f",
        "R6.4.f",
        "R7.1.e"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1452,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Integrate at least two agent stacks",
      "unsatisfied_prerequisites": [
        "R1.5.g",
        "R1.6.f",
        "R1.7.f",
        "R6.4.f",
        "R7.1.e"
      ],
      "workstream": "R8.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.5.g",
          "R1.6.f",
          "R1.7.f",
          "R6.4.f",
          "R7.1.e",
          "R8.1.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Plan, author, check, run, inspect effects, repair, test, minimize capability policy, package, build, deploy, replay, and explain provenance.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.1.b",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Plan, author, check, run, inspect effects, repair, test, minimize capability policy, package, build, deploy, replay, and explain provenance.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.5.g",
        "R1.6.f",
        "R1.7.f",
        "R6.4.f",
        "R7.1.e",
        "R8.1.a"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1453,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Exercise the complete loop",
      "unsatisfied_prerequisites": [
        "R1.5.g",
        "R1.6.f",
        "R1.7.f",
        "R6.4.f",
        "R7.1.e",
        "R8.1.a"
      ],
      "workstream": "R8.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.5.g",
          "R1.6.f",
          "R1.7.f",
          "R6.4.f",
          "R7.1.e",
          "R8.1.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Attribute failures to language ambiguity, card retrieval, diagnostics, model reasoning, tool protocol, runtime, policy, performance, or missing domain support.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.1.c",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Attribute failures to language ambiguity, card retrieval, diagnostics, model reasoning, tool protocol, runtime, policy, performance, or missing domain support.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.5.g",
        "R1.6.f",
        "R1.7.f",
        "R6.4.f",
        "R7.1.e",
        "R8.1.b"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1454,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Publish failure taxonomy",
      "unsatisfied_prerequisites": [
        "R1.5.g",
        "R1.6.f",
        "R1.7.f",
        "R6.4.f",
        "R7.1.e",
        "R8.1.b"
      ],
      "workstream": "R8.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.5.g",
          "R1.6.f",
          "R1.7.f",
          "R6.4.f",
          "R7.1.e",
          "R8.1.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Roadmap priority responds to repeated measured failure classes, not isolated demo success or benchmark gaming.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.1.d",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Roadmap priority responds to repeated measured failure classes, not isolated demo success or benchmark gaming.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.5.g",
        "R1.6.f",
        "R1.7.f",
        "R6.4.f",
        "R7.1.e",
        "R8.1.c"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1455,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Ratchet from evidence",
      "unsatisfied_prerequisites": [
        "R1.5.g",
        "R1.6.f",
        "R1.7.f",
        "R6.4.f",
        "R7.1.e",
        "R8.1.c"
      ],
      "workstream": "R8.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Parsing/transformation, tests, package, reproducible native/WASI builds.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Parsing/transformation, tests, package, reproducible native/WASI builds.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1459,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Pure library and CLI",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f",
          "R5.7.a",
          "R5.7.b",
          "R5.7.c",
          "R5.7.d",
          "R5.7.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Structured concurrency, TLS policy, persistence, cancellation, replayable tests, OCI deploy/rollback.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.b",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Structured concurrency, TLS policy, persistence, cancellation, replayable tests, OCI deploy/rollback.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R5.7.a",
        "R5.7.b",
        "R5.7.c",
        "R5.7.d",
        "R5.7.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1460,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "HTTP/WebSocket service",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R5.7.a",
        "R5.7.b",
        "R5.7.c",
        "R5.7.d",
        "R5.7.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f",
          "R5.7.b",
          "R5.7.c",
          "R5.7.d",
          "R5.7.e",
          "R7.1.f",
          "R7.3.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Streaming, bounded memory, deterministic transforms, checkpoint/recovery, provenance.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.c",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Streaming, bounded memory, deterministic transforms, checkpoint/recovery, provenance.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R5.7.b",
        "R5.7.c",
        "R5.7.d",
        "R5.7.e",
        "R7.1.f",
        "R7.3.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1461,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Data pipeline",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R5.7.b",
        "R5.7.c",
        "R5.7.d",
        "R5.7.e",
        "R7.1.f",
        "R7.3.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f",
          "R5.7.a",
          "R5.7.d",
          "R5.7.f",
          "R7.1.f",
          "R7.3.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Generated schemas, authentication policy, bounded tools, audit/replay.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.d",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Generated schemas, authentication policy, bounded tools, audit/replay.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R5.7.a",
        "R5.7.d",
        "R5.7.f",
        "R7.1.f",
        "R7.3.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1462,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "MCP/tool server",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R5.7.a",
        "R5.7.d",
        "R5.7.f",
        "R7.1.f",
        "R7.3.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f",
          "R6.5.d",
          "R7.1.f",
          "R7.3.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Worker/runtime boundary, deterministic state, package/build evidence, sandboxed effects.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.e",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Worker/runtime boundary, deterministic state, package/build evidence, sandboxed effects.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R6.5.d",
        "R7.1.f",
        "R7.3.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1463,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Browser application",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R6.5.d",
        "R7.1.f",
        "R7.3.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Author, resolve, sign, publish, mirror, revoke, migrate, offline verify.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.f",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Author, resolve, sign, publish, mirror, revoke, migrate, offline verify.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1464,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Package and registry workflow",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Candidate forks, semantic merge/conflict, independent verifier, minimal patch selection.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.g",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Candidate forks, semantic merge/conflict, independent verifier, minimal patch selection.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1465,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Parallel agent refactor",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f",
          "R5.7.e",
          "R7.1.f",
          "R7.3.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Pure kernel semantics, deterministic tolerance/profile, backend evidence, CPU fallback.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.h",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Pure kernel semantics, deterministic tolerance/profile, backend evidence, CPU fallback.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R5.7.e",
        "R7.1.f",
        "R7.3.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1466,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "GPU or numeric workload",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R5.7.e",
        "R7.1.f",
        "R7.3.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f",
          "R6.6.d",
          "R7.1.f",
          "R7.3.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "One iOS and one Android host integration using preserved platform toolchains; promote only if reproducibility, lifecycle, size, and debugging meet L4.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.i",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "One iOS and one Android host integration using preserved platform toolchains; promote only if reproducibility, lifecycle, size, and debugging meet L4.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R6.6.d",
        "R7.1.f",
        "R7.3.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1467,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Mobile embedding pilot",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R6.6.d",
        "R7.1.f",
        "R7.3.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Agent updates a non-TCB compiler/tooling component, bootstraps, differentially verifies, and produces a reviewable evidence bundle.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.j",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Agent updates a non-TCB compiler/tooling component, bootstraps, differentially verifies, and produces a reviewable evidence bundle.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1468,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Self-host toolchain change",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f",
          "R6.5.d",
          "R7.1.f",
          "R7.3.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "The agent builds a responsive accessible site plus authenticated interactive application, SSR/API/database/background/realtime paths, offline behavior, browser tests, self-hosted deployment, and rollback with no handwritten HTML/CSS/JavaScript/YAML.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.k",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "The agent builds a responsive accessible site plus authenticated interactive application, SSR/API/database/background/realtime paths, offline behavior, browser tests, self-hosted deployment, and rollback with no handwritten HTML/CSS/JavaScript/YAML.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R6.5.d",
        "R7.1.f",
        "R7.3.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1469,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Full-stack web product",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R6.5.d",
        "R7.1.f",
        "R7.3.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f",
          "R6.6.d",
          "R7.1.f",
          "R7.3.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "One shared Genesis app installs and runs on macOS, Windows, and Linux with native lifecycle, accessibility, filesystem/dialog/clipboard/notification capabilities, signed artifacts, update, crash recovery, and no edited generated project files.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.l",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "One shared Genesis app installs and runs on macOS, Windows, and Linux with native lifecycle, accessibility, filesystem/dialog/clipboard/notification capabilities, signed artifacts, update, crash recovery, and no edited generated project files.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R6.6.d",
        "R7.1.f",
        "R7.3.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1470,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Native desktop product",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R6.6.d",
        "R7.1.f",
        "R7.3.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f",
          "R5.8.f",
          "R6.5.d",
          "R6.6.d",
          "R7.1.f",
          "R7.3.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "A nontrivial 2D or 3D game uses deterministic simulation, input, physics/collision, animation, audio, Genesis-authored shader/assets, save/replay, networking or a declared offline scope, and real web/desktop plus one mobile build under frame/resource budgets.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.m",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "A nontrivial 2D or 3D game uses deterministic simulation, input, physics/collision, animation, audio, Genesis-authored shader/assets, save/replay, networking or a declared offline scope, and real web/desktop plus one mobile build under frame/resource budgets.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R5.8.f",
        "R6.5.d",
        "R6.6.d",
        "R7.1.f",
        "R7.3.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1471,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Cross-target game",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R5.8.f",
        "R6.5.d",
        "R6.6.d",
        "R7.1.f",
        "R7.3.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f",
          "R5.8.f",
          "R6.6.d",
          "R7.1.f",
          "R7.3.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "An image/audio/video/scene workflow imports assets, performs deterministic transforms, previews through the real UI/media runtime, exports a standard artifact, preserves license/provenance, and handles malformed or oversized content safely.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.n",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "An image/audio/video/scene workflow imports assets, performs deterministic transforms, previews through the real UI/media runtime, exports a standard artifact, preserves license/provenance, and handles malformed or oversized content safely.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R5.8.f",
        "R6.6.d",
        "R7.1.f",
        "R7.3.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1472,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Creative media tool",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R5.8.f",
        "R6.6.d",
        "R7.1.f",
        "R7.3.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f",
          "R6.7.a",
          "R7.1.f",
          "R7.3.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "A Raspberry Pi-class device runs a Genesis service or UI, accesses real GPIO/I2C/SPI/UART hardware under policy, survives power/network loss, updates/rolls back, and reproduces from a clean cross-build without foreign application code.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.o",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "A Raspberry Pi-class device runs a Genesis service or UI, accesses real GPIO/I2C/SPI/UART hardware under policy, survives power/network loss, updates/rolls back, and reproduces from a clean cross-build without foreign application code.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R6.7.a",
        "R7.1.f",
        "R7.3.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1473,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Embedded Linux product",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R6.7.a",
        "R7.1.f",
        "R7.3.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f",
          "R6.7.e",
          "R7.1.f",
          "R7.3.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "RP2040 and ESP32-class boards compile the constrained profile, pass static memory/timing checks, exercise real peripherals and watchdog/reset paths, flash/debug through Genesis tools, and complete signed OTA/rollback where supported.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.p",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "RP2040 and ESP32-class boards compile the constrained profile, pass static memory/timing checks, exercise real peripherals and watchdog/reset paths, flash/debug through Genesis tools, and complete signed OTA/rollback where supported.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R6.7.e",
        "R7.1.f",
        "R7.3.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1474,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Microcontroller firmware",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R6.7.e",
        "R7.1.f",
        "R7.3.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f",
          "R6.7.e",
          "R7.1.f",
          "R7.3.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Device, gateway, service, dashboard, provisioning, telemetry/control, offline reconciliation, safety stop, fleet update, digital twin, and hardware-in-the-loop test form one capability-minimal Genesis workspace.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.q",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Device, gateway, service, dashboard, provisioning, telemetry/control, offline reconciliation, safety stop, fleet update, digital twin, and hardware-in-the-loop test form one capability-minimal Genesis workspace.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R6.7.e",
        "R7.1.f",
        "R7.3.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1475,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "IoT or robotics system",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R6.7.e",
        "R7.1.f",
        "R7.3.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R8.1.d",
          "R7.3.e",
          "R6.4.f",
          "R5.6.f",
          "R5.7.a",
          "R5.7.b",
          "R5.7.c",
          "R5.7.d",
          "R5.7.e",
          "R5.7.f",
          "R7.1.f",
          "R7.3.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "A reproducible dataset-to-analysis/model pipeline uses Genesis tables/tensors/statistics, CPU/GPU execution, checkpoints, evaluation, local inference service/UI, provenance, and resource evidence without Python notebooks or scripts.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.2.r",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "A reproducible dataset-to-analysis/model pipeline uses Genesis tables/tensors/statistics, CPU/GPU execution, checkpoints, evaluation, local inference service/UI, provenance, and resource evidence without Python notebooks or scripts.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R5.6.f",
        "R5.7.a",
        "R5.7.b",
        "R5.7.c",
        "R5.7.d",
        "R5.7.e",
        "R5.7.f",
        "R7.1.f",
        "R7.3.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1476,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Data science and local ML system",
      "unsatisfied_prerequisites": [
        "R8.1.d",
        "R7.3.e",
        "R6.4.f",
        "R5.6.f",
        "R5.7.a",
        "R5.7.b",
        "R5.7.c",
        "R5.7.d",
        "R5.7.e",
        "R5.7.f",
        "R7.1.f",
        "R7.3.f"
      ],
      "workstream": "R8.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "F2.r"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Define versioned closed manifests for examples, apps, suites, and catalog releases; classify every retained project as language conformance, host/workflow fixture, tutorial example, reference example, or maintained application; and forbid relabeling a fixture, descriptor, headless plan, mock, screenshot, or generated archive as an app. Before each release, rank proposed projects by uncovered capability/profile combinations, compositional depth, algorithm leverage, agent-learning value, authentic-target evidence, user usefulness, maintenance burden, duplication, and opportunity to retire weaker fixtures; publish accepted and rejected portfolio decisions rather than expanding by taste. Each admitted item binds exact GenesisCode/CoreForm/package/lock/target/Genesis Algorithms identities, learning objectives or user outcomes, public API use, capabilities, resource budgets, threat model, deterministic and authentic-target acceptance, build/run/test/deploy/replay commands, source/generated/dependency inventories, provenance/license, supported and unsupported profiles, owner, maintenance window, evidence level, and supersession. Generate a browsable human/agent catalog, task cards, dependency graph, copy-free project creation command, and machine lookup from this single authority. Keep existing paths stable where practical and use catalog metadata rather than adding root-level clutter.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.3.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Define versioned closed manifests for examples, apps, suites, and catalog releases; classify every retained project as language conformance, host/workflow fixture, tutorial example, reference example, or maintained application; and forbid relabeling a fixture, descriptor, headless plan, mock, screenshot, or generated archive as an app. Before each release, rank proposed projects by uncovered capability/profile combinations, compositional depth, algorithm leverage, agent-learning value, authentic-target evidence, user usefulness, maintenance burden, duplication, and opportunity to retire weaker fixtures; publish accepted and rejected portfolio decisions rather than expanding by taste. Each admitted item binds exact GenesisCode/CoreForm/package/lock/target/Genesis Algorithms identities, learning objectives or user outcomes, public API use, capabilities, resource budgets, threat model, deterministic and authentic-target acceptance, build/run/test/deploy/replay commands, source/generated/dependency inventories, provenance/license, supported and unsupported profiles, owner, maintenance window, evidence level, and supersession. Generate a browsable human/agent catalog, task cards, dependency graph, copy-free project creation command, and machine lookup from this single authority. Keep existing paths stable where practical and use catalog metadata rather than adding root-level clutter.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "F2.r"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1482,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Freeze the catalog, classification, and admission contract",
      "unsatisfied_prerequisites": [
        "F2.r"
      ],
      "workstream": "R8.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "F2.r",
          "R8.2.a",
          "R8.2.b",
          "R8.2.d",
          "R8.2.e",
          "R8.2.k",
          "R8.3.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [
          "genesis/algorithms"
        ],
        "deliverable": "After F2.r and the required authentic Core/web/tool profiles, release at minimum: a pure `genesis/algorithms` library-and-CLI tour; an MCP/tool server exposing bounded algorithm operations; a real HTTP/WebSocket server with persistence, cancellation, policy, replay, deployment, and rollback; and a separate responsive accessible full-stack website/application built and served by that stack with SSR/API/data/background/realtime/offline paths and no handwritten HTML, CSS, JavaScript, TypeScript, Python, Rust, shell, or deployment YAML. Also ship one integrated workspace composing the server and site while preserving their independent package/build identities. Every project must use one or more released algorithms for a workload-relevant purpose, exercise deterministic fallbacks and unsupported-profile behavior, install from a clean public checkout, and build/run with `foundry/` deleted. Publish reproducible evidence, tutorials, architecture explanations, operational guides, and seeded repair/upgrade exercises. Independent checks must reject dependency theater, stale catalog identities, copied Foundry candidate state, hidden foreign source, mock-only target evidence, and public-example leakage into held-out benchmark payloads. This finite checkpoint activates GenesisBench Preview and GenesisChallenge; it does not claim universal platform maturity.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.3.b",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "After F2.r and the required authentic Core/web/tool profiles, release at minimum: a pure `genesis/algorithms` library-and-CLI tour; an MCP/tool server exposing bounded algorithm operations; a real HTTP/WebSocket server with persistence, cancellation, policy, replay, deployment, and rollback; and a separate responsive accessible full-stack website/application built and served by that stack with SSR/API/data/background/realtime/offline paths and no handwritten HTML, CSS, JavaScript, TypeScript, Python, Rust, shell, or deployment YAML. Also ship one integrated workspace composing the server and site while preserving their independent package/build identities. Every project must use one or more released algorithms for a workload-relevant purpose, exercise deterministic fallbacks and unsupported-profile behavior, install from a clean public checkout, and build/run with `foundry/` deleted. Publish reproducible evidence, tutorials, architecture explanations, operational guides, and seeded repair/upgrade exercises. Independent checks must reject dependency theater, stale catalog identities, copied Foundry candidate state, hidden foreign source, mock-only target evidence, and public-example leakage into held-out benchmark payloads. This finite checkpoint activates GenesisBench Preview and GenesisChallenge; it does not claim universal platform maturity.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "F2.r",
        "R8.2.a",
        "R8.2.b",
        "R8.2.d",
        "R8.2.e",
        "R8.2.k",
        "R8.3.a"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1483,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Publish the finite algorithm-backed GenesisExamples/GenesisApps seed",
      "unsatisfied_prerequisites": [
        "F2.r",
        "R8.2.a",
        "R8.2.b",
        "R8.2.d",
        "R8.2.e",
        "R8.2.k",
        "R8.3.a"
      ],
      "workstream": "R8.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "F2.r",
          "R8.2.a",
          "R8.2.b",
          "R8.2.c",
          "R8.2.d",
          "R8.2.e",
          "R8.2.f",
          "R8.2.g",
          "R8.2.h",
          "R8.2.i",
          "R8.2.j",
          "R8.2.k",
          "R8.2.l",
          "R8.2.m",
          "R8.2.n",
          "R8.2.o",
          "R8.2.p",
          "R8.2.q",
          "R8.2.r",
          "R8.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Required set: replay-audited service/data system, MCP tool server, full-stack web product, native desktop app, shared iOS/Android app, game or rich interactive simulation, creative/data/ML tool, self-hosted package registry deployment, Raspberry Pi-class product, and MCU/IoT product across at least two board families. Map all eighteen R8.2 archetypes to at least one maintained app or an explicit unsupported/blocked record, prefer shared multi-target workspaces over target-specific clones, and add smaller GenesisExamples only where they isolate a genuinely reusable concept. Each app consumes only released packages, including a named Genesis Algorithms release where applicable; later Foundry proposals target successor package/app versions through ordinary destination review rather than mutating a running app or its baseline.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.3.c",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Required set: replay-audited service/data system, MCP tool server, full-stack web product, native desktop app, shared iOS/Android app, game or rich interactive simulation, creative/data/ML tool, self-hosted package registry deployment, Raspberry Pi-class product, and MCU/IoT product across at least two board families. Map all eighteen R8.2 archetypes to at least one maintained app or an explicit unsupported/blocked record, prefer shared multi-target workspaces over target-specific clones, and add smaller GenesisExamples only where they isolate a genuinely reusable concept. Each app consumes only released packages, including a named Genesis Algorithms release where applicable; later Foundry proposals target successor package/app versions through ordinary destination review rather than mutating a running app or its baseline.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "F2.r",
        "R8.2.a",
        "R8.2.b",
        "R8.2.c",
        "R8.2.d",
        "R8.2.e",
        "R8.2.f",
        "R8.2.g",
        "R8.2.h",
        "R8.2.i",
        "R8.2.j",
        "R8.2.k",
        "R8.2.l",
        "R8.2.m",
        "R8.2.n",
        "R8.2.o",
        "R8.2.p",
        "R8.2.q",
        "R8.2.r",
        "R8.3.b"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1484,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Expand to at least ten maintained GenesisApps across every qualified archetype",
      "unsatisfied_prerequisites": [
        "F2.r",
        "R8.2.a",
        "R8.2.b",
        "R8.2.c",
        "R8.2.d",
        "R8.2.e",
        "R8.2.f",
        "R8.2.g",
        "R8.2.h",
        "R8.2.i",
        "R8.2.j",
        "R8.2.k",
        "R8.2.l",
        "R8.2.m",
        "R8.2.n",
        "R8.2.o",
        "R8.2.p",
        "R8.2.q",
        "R8.2.r",
        "R8.3.b"
      ],
      "workstream": "R8.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "F2.r",
          "R8.3.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "For every released seed and flagship, perform agent-authored seeded upgrades, dependency and algorithm-library migrations, defect repairs, policy tightening, target-profile migrations, rollback, disaster recovery, and generated-artifact deletion/rebuild. Publish patch quality, diagnostics and repair turns, total agent work, human review time, resource deltas, compatibility outcomes, and retained failures. A complete source/generated/dependency inventory rejects hidden handwritten glue, vendored target projects, cloud-only build steps, manual post-build repair, mutable Foundry dependencies, undeclared services, and generated files that have become source authority.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.3.d",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "For every released seed and flagship, perform agent-authored seeded upgrades, dependency and algorithm-library migrations, defect repairs, policy tightening, target-profile migrations, rollback, disaster recovery, and generated-artifact deletion/rebuild. Publish patch quality, diagnostics and repair turns, total agent work, human review time, resource deltas, compatibility outcomes, and retained failures. A complete source/generated/dependency inventory rejects hidden handwritten glue, vendored target projects, cloud-only build steps, manual post-build repair, mutable Foundry dependencies, undeclared services, and generated files that have become source authority.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "F2.r",
        "R8.3.c"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1485,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Prove maintenance and one-language source closure",
      "unsatisfied_prerequisites": [
        "F2.r",
        "R8.3.c"
      ],
      "workstream": "R8.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "F2.r",
          "R8.3.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "At least two people or organizations outside the producing agent reproduce each claimed seed/flagship class from public documentation, complete clean install/build/run/deploy or flash, execute a maintenance change, and report every undocumented prerequisite, misleading claim, inaccessible workflow, foreign-language escape, or algorithm/profile incompatibility as a product defect. The documentation site exposes live compatibility and evidence status, exact commands, expected outputs, architecture and threat-model views, resource footprints, screenshots or recordings only as supporting evidence, and migration/supersession history. Measure successful starts, useful forks, maintained downstream use, issue-to-repair latency, and example-to-package/app promotion without treating page views, benchmark scores, or challenge prizes as product proof.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.3.e",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "At least two people or organizations outside the producing agent reproduce each claimed seed/flagship class from public documentation, complete clean install/build/run/deploy or flash, execute a maintenance change, and report every undocumented prerequisite, misleading claim, inaccessible workflow, foreign-language escape, or algorithm/profile incompatibility as a product defect. The documentation site exposes live compatibility and evidence status, exact commands, expected outputs, architecture and threat-model views, resource footprints, screenshots or recordings only as supporting evidence, and migration/supersession history. Measure successful starts, useful forks, maintained downstream use, issue-to-repair latency, and example-to-package/app promotion without treating page views, benchmark scores, or challenge prizes as product proof.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "F2.r",
        "R8.3.d"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1486,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Require independent operation and keep the catalog useful",
      "unsatisfied_prerequisites": [
        "F2.r",
        "R8.3.d"
      ],
      "workstream": "R8.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.2.f",
          "R2.3.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "structured values/effects, multiline editing, history privacy, resource controls, profile selection, and replay inspection.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.4.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "structured values/effects, multiline editing, history privacy, resource controls, profile selection, and replay inspection.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.2.f",
        "R2.3.e"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1490,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "REPL",
      "unsatisfied_prerequisites": [
        "R2.3.e"
      ],
      "workstream": "R8.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.2.f",
          "R2.3.e",
          "R8.4.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "parser/type/effect diagnostics, semantic navigation, format, safe actions, capability/policy insights, and incremental performance from shared schemas.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.4.b",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "parser/type/effect diagnostics, semantic navigation, format, safe actions, capability/policy insights, and incremental performance from shared schemas.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.2.f",
        "R2.3.e",
        "R8.4.a"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1491,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "LSP",
      "unsatisfied_prerequisites": [
        "R2.3.e",
        "R8.4.a"
      ],
      "workstream": "R8.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.2.f",
          "R2.3.e",
          "R8.4.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "locally hostable, browser-sandboxed, capability-minimal, version-pinned, shareable by content hash, and incapable of implying unsupported host effects.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.4.c",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "locally hostable, browser-sandboxed, capability-minimal, version-pinned, shareable by content hash, and incapable of implying unsupported host effects.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.2.f",
        "R2.3.e",
        "R8.4.b"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1492,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Playground",
      "unsatisfied_prerequisites": [
        "R2.3.e",
        "R8.4.b"
      ],
      "workstream": "R8.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.2.f",
          "R2.3.e",
          "R8.4.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "ship one getting-started path, language reference, agent SDK, capability and product/target matrices, Core CLI/WASI and service guides, operations/security, package/registry, self-host/bootstrap, and contribution guide generated from canonical sources. The matrix links independently versioned pack documentation and labels unavailable packs without requiring unfinished web, desktop/mobile, game/media, data/AI, Embedded Linux, MCU, or board tutorials for Core. Every released pack owns a Genesis-only tutorial with authentic build/run/device evidence and labels generated foreign artifacts as disposable internals before that pack can ship.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.4.d",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "ship one getting-started path, language reference, agent SDK, capability and product/target matrices, Core CLI/WASI and service guides, operations/security, package/registry, self-host/bootstrap, and contribution guide generated from canonical sources. The matrix links independently versioned pack documentation and labels unavailable packs without requiring unfinished web, desktop/mobile, game/media, data/AI, Embedded Linux, MCU, or board tutorials for Core. Every released pack owns a Genesis-only tutorial with authentic build/run/device evidence and labels generated foreign artifacts as disposable internals before that pack can ship.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.2.f",
        "R2.3.e",
        "R8.4.c"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1493,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Core documentation spine",
      "unsatisfied_prerequisites": [
        "R2.3.e",
        "R8.4.c"
      ],
      "workstream": "R8.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.2.f",
          "R2.3.e",
          "R8.2.a",
          "R8.2.b",
          "R8.4.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "a clean user evaluates a pure program, runs an effect under policy, inspects the log, and replays it in <=10 minutes without hidden setup; this proof uses only the finite Core profile and cannot inherit success from a platform-pack demo.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.4.e",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "a clean user evaluates a pure program, runs an effect under policy, inspects the log, and replays it in <=10 minutes without hidden setup; this proof uses only the finite Core profile and cannot inherit success from a platform-pack demo.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.2.f",
        "R2.3.e",
        "R8.2.a",
        "R8.2.b",
        "R8.4.d"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1494,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Core ten-minute proof",
      "unsatisfied_prerequisites": [
        "R2.3.e",
        "R8.2.a",
        "R8.2.b",
        "R8.4.d"
      ],
      "workstream": "R8.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "F2.r",
          "R1.4.a",
          "R1.4.b",
          "R1.4.c",
          "R1.4.d",
          "R1.4.e",
          "R1.4.f",
          "R1.4.g",
          "R1.4.h",
          "R1.4.i",
          "R1.4.j",
          "R1.4.k",
          "R1.4.l",
          "R1.4.m",
          "R1.4.n",
          "R1.4.o",
          "R1.4.q",
          "R1.4.p",
          "R1.4.r",
          "R8.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [
          "genesis/algorithms"
        ],
        "deliverable": "After the finite R8.3.b GenesisExamples/GenesisApps seed, evolve GenesisBench from syntax and bounded repairs through repository-scale feature work, capability-safe services, public `genesis/algorithms` use and extension, performance engineering, package/deployment operations, cross-platform debugging, and self-host toolchain changes. Bind exact immutable GenesisCode, Genesis Algorithms, and public example/app catalog releases and maintain a versioned coverage ledger over every released language, library, toolchain, maintenance, capability, example, and L4 product surface. Every task represents useful GenesisCode work, has a mechanically checkable acceptance contract, declares an immutable epoch-local easy/medium/hard calibration independently from small/medium/large context, and remains valuable as an example, diagnostic, library regression, or general regression after its ranking weight retires. Public examples may define capability families, disclosed practice, and scorer-independent acceptance patterns, but private tasks require independent lineage and cannot copy a published solution, oracle, trace, or seeded repair. Publish smoke, fast, standard, and full forms with the distinct semantics in section 3.16; no missing stratum is hidden by an aggregate and no fast form substitutes for Trust-release or full-coverage evidence. Foundry search state and private candidate/oracle material are excluded; library or example membership never substitutes for independent scoring.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.a",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "After the finite R8.3.b GenesisExamples/GenesisApps seed, evolve GenesisBench from syntax and bounded repairs through repository-scale feature work, capability-safe services, public `genesis/algorithms` use and extension, performance engineering, package/deployment operations, cross-platform debugging, and self-host toolchain changes. Bind exact immutable GenesisCode, Genesis Algorithms, and public example/app catalog releases and maintain a versioned coverage ledger over every released language, library, toolchain, maintenance, capability, example, and L4 product surface. Every task represents useful GenesisCode work, has a mechanically checkable acceptance contract, declares an immutable epoch-local easy/medium/hard calibration independently from small/medium/large context, and remains valuable as an example, diagnostic, library regression, or general regression after its ranking weight retires. Public examples may define capability families, disclosed practice, and scorer-independent acceptance patterns, but private tasks require independent lineage and cannot copy a published solution, oracle, trace, or seeded repair. Publish smoke, fast, standard, and full forms with the distinct semantics in section 3.16; no missing stratum is hidden by an aggregate and no fast form substitutes for Trust-release or full-coverage evidence. Foundry search state and private candidate/oracle material are excluded; library or example membership never substitutes for independent scoring.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "F2.r",
        "R1.4.a",
        "R1.4.b",
        "R1.4.c",
        "R1.4.d",
        "R1.4.e",
        "R1.4.f",
        "R1.4.g",
        "R1.4.h",
        "R1.4.i",
        "R1.4.j",
        "R1.4.k",
        "R1.4.l",
        "R1.4.m",
        "R1.4.n",
        "R1.4.o",
        "R1.4.q",
        "R1.4.p",
        "R1.4.r",
        "R8.3.b"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1500,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Build a calibrated capability frontier, not a puzzle set",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "F2.r",
        "R1.4.o",
        "R1.4.q",
        "R1.4.p",
        "R1.4.r",
        "R8.3.b"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Evaluate newly released models only against epochs precommitted after their immutable release when claiming `temporal-clean`; retain public and private anchor tasks for longitudinal trends, report contaminated and unknown results without suppressing them, and advance difficulty under BQ-5 rather than making scores easier to preserve a leaderboard narrative. Calibrate prospective easy/medium/hard bands on role-separated non-target pilots across materially different model families, test discrimination and differential item behavior, publish equating uncertainty, rotate saturated ranking weight without deleting anchors, and never relabel a historical item or score after observing a target model.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.b",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Evaluate newly released models only against epochs precommitted after their immutable release when claiming `temporal-clean`; retain public and private anchor tasks for longitudinal trends, report contaminated and unknown results without suppressing them, and advance difficulty under BQ-5 rather than making scores easier to preserve a leaderboard narrative. Calibrate prospective easy/medium/hard bands on role-separated non-target pilots across materially different model families, test discrimination and differential item behavior, publish equating uncertainty, rotate saturated ranking weight without deleting anchors, and never relabel a historical item or score after observing a target model.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.a"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1501,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Run rolling, equated temporal evaluations",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.a"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Include local open-weight, hosted, general-purpose, code-specialized, and GenesisCode-adapted systems under the same transport-neutral task authority. Preserve a minimum-common-denominator `artifact-text` matrix across at least three independently implemented interface stacks and model families, and prove native-tool versus canonical JSON-text-tool equivalence where both are eligible. Separate base-model capability from agent scaffolding through controlled card/tool/context/interaction ablations, report pass@k and attempt budgets without cherry-picking, and never combine incompatible epochs, interaction profiles, tokenizers, or scaffolds into one rank. Publish per-difficulty, per-class, per-capability/product, interface, and maintenance/new-build strata with lineage-clustered uncertainty; fast results name the exact form and remain directional, while standard/full claims require their complete predeclared matrices. Differential item behavior by model family, interface, tokenizer, or output convention triggers review and prospective repair, never target-specific prompt tuning inside a cohort.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.c",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Include local open-weight, hosted, general-purpose, code-specialized, and GenesisCode-adapted systems under the same transport-neutral task authority. Preserve a minimum-common-denominator `artifact-text` matrix across at least three independently implemented interface stacks and model families, and prove native-tool versus canonical JSON-text-tool equivalence where both are eligible. Separate base-model capability from agent scaffolding through controlled card/tool/context/interaction ablations, report pass@k and attempt budgets without cherry-picking, and never combine incompatible epochs, interaction profiles, tokenizers, or scaffolds into one rank. Publish per-difficulty, per-class, per-capability/product, interface, and maintenance/new-build strata with lineage-clustered uncertainty; fast results name the exact form and remain directional, while standard/full claims require their complete predeclared matrices. Differential item behavior by model family, interface, tokenizer, or output convention triggers review and prospective repair, never target-specific prompt tuning inside a cohort.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.b"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1502,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Compare diverse model and agent families without interface favoritism",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.b"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Cluster failures by language ambiguity, missing primitive or algorithm API, library contract/retrieval/dispatch defect, card retrieval, diagnostics, repair guidance, tool protocol, policy ergonomics, runtime defect, performance, or model reasoning. Reproduce each eligible cluster with a minimal deterministic case, assign a destination owner, and either improve GenesisCode or Genesis Algorithms with regression evidence or record an explicit non-goal; AB-10 measures closure, not leaderboard movement. A Bench failure may propose a future Foundry task but cannot alter an active task, checker, library release, or historical score.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.d",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Cluster failures by language ambiguity, missing primitive or algorithm API, library contract/retrieval/dispatch defect, card retrieval, diagnostics, repair guidance, tool protocol, policy ergonomics, runtime defect, performance, or model reasoning. Reproduce each eligible cluster with a minimal deterministic case, assign a destination owner, and either improve GenesisCode or Genesis Algorithms with regression evidence or record an explicit non-goal; AB-10 measures closure, not leaderboard movement. A Bench failure may propose a future Foundry task but cannot alter an active task, checker, library release, or historical score.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.c"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1503,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Turn failures into language and library work",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.c"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [
          "genesis/algorithms"
        ],
        "deliverable": "A benchmark candidate becomes a GenesisExample, GenesisApp component, `genesis/algorithms` change, other package, recipe, or diagnostic fixture only after independent destination review, semantic/obligation/policy/resource verification, provenance and license checks, secret scanning, simplification, catalog classification, and maintenance ownership. Algorithm-library admission uses the same F2.r promotion firewall and never trusts score, Foundry ancestry, or candidate similarity as correctness; example/app admission uses the R8.3 authority and never trusts score as usefulness or maintainability. Promotion does not expose active held-out material or preserve benchmark-only scaffolding in production APIs. Add license-clean source-migration and spec-reconstruction lineages only after the destination profile has authentic L4 support; score behavioral, property, metamorphic, security, accessibility, resource, deployment, and seeded-maintenance acceptance rather than reference-patch similarity, enforce GenesisCode-only application source, and meet BQ-17.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.e",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "A benchmark candidate becomes a GenesisExample, GenesisApp component, `genesis/algorithms` change, other package, recipe, or diagnostic fixture only after independent destination review, semantic/obligation/policy/resource verification, provenance and license checks, secret scanning, simplification, catalog classification, and maintenance ownership. Algorithm-library admission uses the same F2.r promotion firewall and never trusts score, Foundry ancestry, or candidate similarity as correctness; example/app admission uses the R8.3 authority and never trusts score as usefulness or maintainability. Promotion does not expose active held-out material or preserve benchmark-only scaffolding in production APIs. Add license-clean source-migration and spec-reconstruction lineages only after the destination profile has authentic L4 support; score behavioral, property, metamorphic, security, accessibility, resource, deployment, and seeded-maintenance acceptance rather than reference-patch similarity, enforce GenesisCode-only application source, and meet BQ-17.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.d"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1504,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Promote successful artifacts into the ecosystem",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.d"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Require external operators to reproduce benchmark results, submit useful benchmark tasks, use and improve the disclosed Genesis Algorithms release, and build maintained GenesisCode artifacts without private project prompts. Track benchmark-to-doc, benchmark-to-diagnostic, benchmark-to-library, benchmark-to-package, benchmark-to-flagship, benchmark-user-to-language-user, and language-user-to-corpus conversion with consent. Optimize for durable software, trustworthy agents, reusable algorithms, and lower total agent work rather than leaderboard traffic or synthetic volume alone. Report GenesisChallenge participation and accepted contribution deltas separately; contest traffic, prizes, claims, or merges cannot satisfy benchmark reproduction, adoption, or rank.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.s",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Require external operators to reproduce benchmark results, submit useful benchmark tasks, use and improve the disclosed Genesis Algorithms release, and build maintained GenesisCode artifacts without private project prompts. Track benchmark-to-doc, benchmark-to-diagnostic, benchmark-to-library, benchmark-to-package, benchmark-to-flagship, benchmark-user-to-language-user, and language-user-to-corpus conversion with consent. Optimize for durable software, trustworthy agents, reusable algorithms, and lower total agent work rather than leaderboard traffic or synthetic volume alone. Report GenesisChallenge participation and accepted contribution deltas separately; contest traffic, prizes, claims, or merges cannot satisfy benchmark reproduction, adoption, or rank.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.e"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1505,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Prove independent value and adoption",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.e"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Use separate capability identities, storage roots, operators, and audit logs for corpus construction, training, held-out custody, evaluation, and result publication. Prove with canaries and adversarial tests that training cannot read active private epochs, evaluation cannot write training data, model output cannot alter scoring authority, and post-evaluation promotion requires an explicit reviewed transfer record.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.h",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Use separate capability identities, storage roots, operators, and audit logs for corpus construction, training, held-out custody, evaluation, and result publication. Prove with canaries and adversarial tests that training cannot read active private epochs, evaluation cannot write training data, model output cannot alter scoring authority, and post-evaluation promotion requires an explicit reviewed transfer record.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.e"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1509,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Enforce the training/evaluation firewall",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.e"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.h",
          "F2.r"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Freeze clean, signed, content-addressed source editions of Project Theseus and The ASI Stack plus the independently reproduced MF Foundation snapshot and exact Genesis Algorithms release; record exact commits, included promoted and rejected artifacts, generators, permissions, licenses, evidence states, supersession links, and an artifact-to-claim crosswalk under MQ-1 through MQ-8. Treat cognitive compilation/IR, routing and specialists, memory and recurrence, fast generation, governed deliberation and test-time scaling, data and continual learning/unlearning, local hives, model custody, safety, resource economics, and Foundry mechanisms only as candidate hypotheses. For each candidate, replay the exact source report, closed Foundry receipt, or package evidence where artifacts permit, then predeclare a Genesis-specific workload, simplest adequate baseline, ablations, multiple seeds or deterministic proof, uncertainty, hardware/resource envelope, privacy/firewall analysis, claim/non-claim boundary, and independent transfer decision. Preserve null, negative, stale, missing-artifact, unsafe, and rejected outcomes. No prose, dashboard, dirty worktree, favorable latest run, Foundry search result, package membership, or project affiliation can directly choose the tokenizer, base, architecture, data, objective, routing, memory, inference, or deployment design. Emit a versioned transfer manifest consumed by all downstream model experiments; a reviewer independent of the source author, Foundry operator, algorithm-package maintainer, model trainer, benchmark operator, and release signer must approve every promoted mechanism.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.i",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Freeze clean, signed, content-addressed source editions of Project Theseus and The ASI Stack plus the independently reproduced MF Foundation snapshot and exact Genesis Algorithms release; record exact commits, included promoted and rejected artifacts, generators, permissions, licenses, evidence states, supersession links, and an artifact-to-claim crosswalk under MQ-1 through MQ-8. Treat cognitive compilation/IR, routing and specialists, memory and recurrence, fast generation, governed deliberation and test-time scaling, data and continual learning/unlearning, local hives, model custody, safety, resource economics, and Foundry mechanisms only as candidate hypotheses. For each candidate, replay the exact source report, closed Foundry receipt, or package evidence where artifacts permit, then predeclare a Genesis-specific workload, simplest adequate baseline, ablations, multiple seeds or deterministic proof, uncertainty, hardware/resource envelope, privacy/firewall analysis, claim/non-claim boundary, and independent transfer decision. Preserve null, negative, stale, missing-artifact, unsafe, and rejected outcomes. No prose, dashboard, dirty worktree, favorable latest run, Foundry search result, package membership, or project affiliation can directly choose the tokenizer, base, architecture, data, objective, routing, memory, inference, or deployment design. Emit a versioned transfer manifest consumed by all downstream model experiments; a reviewer independent of the source author, Foundry operator, algorithm-package maintainer, model trainer, benchmark operator, and release signer must approve every promoted mechanism.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.h",
        "F2.r"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1510,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Build an evidence-bounded Theseus/ASI/Foundry research-transfer authority",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.h",
        "F2.r"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.s",
          "R8.5.h",
          "R8.5.i"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Produce a closed, signed, independently reviewed readiness manifest that binds the stable GenesisCode v1 Core and Genesis Algorithms releases and support windows; an independently useful GenesisBench Trust release and BQ-7/BQ-8 adversarial firewall evidence; the reproduced MF Foundation snapshot; the accepted and rejected R8.5.i transfer records; data ownership, consent, license, privacy, safety, export, and retention decisions; available compute/storage/energy/operator budgets; threat model and incident/rollback plan; target local hardware profiles; reproducible training and release feasibility; and a predeclared simplest-adequate legally usable open-base strategy. An independent reviewer with no training, benchmark custody, Foundry search, algorithm-package promotion, source-project, or release-signing role must record pass, fail, or bounded deferral for every criterion. Unknown, unaffordable, unlicensed, unreproducible, privacy-unsafe, benchmark-contaminating, or operationally unsupported status fails the gate. Passing authorizes only the scoped model program; it grants no language, library, benchmark, capability, corpus, checkpoint, or release authority and can be revoked when an input identity or risk decision changes.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.t",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Produce a closed, signed, independently reviewed readiness manifest that binds the stable GenesisCode v1 Core and Genesis Algorithms releases and support windows; an independently useful GenesisBench Trust release and BQ-7/BQ-8 adversarial firewall evidence; the reproduced MF Foundation snapshot; the accepted and rejected R8.5.i transfer records; data ownership, consent, license, privacy, safety, export, and retention decisions; available compute/storage/energy/operator budgets; threat model and incident/rollback plan; target local hardware profiles; reproducible training and release feasibility; and a predeclared simplest-adequate legally usable open-base strategy. An independent reviewer with no training, benchmark custody, Foundry search, algorithm-package promotion, source-project, or release-signing role must record pass, fail, or bounded deferral for every criterion. Unknown, unaffordable, unlicensed, unreproducible, privacy-unsafe, benchmark-contaminating, or operationally unsupported status fails the gate. Passing authorizes only the scoped model program; it grants no language, library, benchmark, capability, corpus, checkpoint, or release authority and can be revoked when an input identity or risk decision changes.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.s",
        "R8.5.h",
        "R8.5.i"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1511,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Ratify the Genesis Model Readiness Gate",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.s",
        "R8.5.h",
        "R8.5.i"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.t"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Store prompts, authorized context, tool traces, attempts, candidate trees, scores, reviewer decisions, accepted patches, failures, and counterexamples as content-addressed records. Split by task lineage, repository snapshot, profile, model family, and time before deduplication; preserve rejected outputs with explicit labels where safe; exclude secrets, active held-out material, incompatible licenses, unverifiable outputs, benchmark evaluator instructions, and every artifact not admitted under the exact R8.5.t decision.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.f",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Store prompts, authorized context, tool traces, attempts, candidate trees, scores, reviewer decisions, accepted patches, failures, and counterexamples as content-addressed records. Split by task lineage, repository snapshot, profile, model family, and time before deduplication; preserve rejected outputs with explicit labels where safe; exclude secrets, active held-out material, incompatible licenses, unverifiable outputs, benchmark evaluator instructions, and every artifact not admitted under the exact R8.5.t decision.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.t"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1512,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Create a lineage-preserving training corpus after readiness",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.t"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Teacher eligibility requires deterministic acceptance, obligation preservation, minimal authority, bounded resources, no editable-scope escape, independent review, stable replay, corpus admission, and compatibility with the exact R8.5.t scope; aggregate benchmark rank alone is insufficient. Weight diversity and difficult correct trajectories to reduce imitation collapse, cap repeated near-duplicates, and retain failure/repair contrasts so the student learns diagnosis rather than only final-form copying.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.g",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Teacher eligibility requires deterministic acceptance, obligation preservation, minimal authority, bounded resources, no editable-scope escape, independent review, stable replay, corpus admission, and compatibility with the exact R8.5.t scope; aggregate benchmark rank alone is insufficient. Weight diversity and difficult correct trajectories to reduce imitation collapse, cap repeated near-duplicates, and retain failure/repair contrasts so the student learns diagnosis rather than only final-form copying.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.f"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1513,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Select teachers by verified artifact quality after readiness",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.f"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.i",
          "R8.5.t"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Compare legally usable open bases across Cold Acquisition, general English/domain competence, context length, local inference, license, architecture/tooling openness, and per-profile hardware cost. Measure tokens per CoreForm node, symbol, diagnostic, task card, semantic patch, policy, and English request; add GenesisCode-specific merges only when they materially reduce complete trajectory cost without degrading English, structured output, or compatibility. Do not train from scratch unless a predeclared ablation proves specialization of available bases cannot meet the target. Every Theseus/ASI-influenced choice cites an accepted R8.5.i transfer record; absence of one means the baseline design remains unchanged.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.j",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Compare legally usable open bases across Cold Acquisition, general English/domain competence, context length, local inference, license, architecture/tooling openness, and per-profile hardware cost. Measure tokens per CoreForm node, symbol, diagnostic, task card, semantic patch, policy, and English request; add GenesisCode-specific merges only when they materially reduce complete trajectory cost without degrading English, structured output, or compatibility. Do not train from scratch unless a predeclared ablation proves specialization of available bases cannot meet the target. Every Theseus/ASI-influenced choice cites an accepted R8.5.i transfer record; absence of one means the baseline design remains unchanged.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.i",
        "R8.5.t"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1514,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Audit tokenizer and select a base model by evidence",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.i",
        "R8.5.t"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.g",
          "R8.5.j"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Train only on BQ-7/BQ-8-approved canonical source, specs/cards/indexes, valid-invalid pairs, tests/obligations, packages/policies, replay/evidence traces, semantic patches, self-host sources, and maintained projects. Bind exact dataset, tokenizer, base checkpoint, optimizer/schedule, code, toolchain, hardware, seeds, checkpoints, energy, licenses, and accepted research-transfer records; evaluate every checkpoint on non-training public diagnostics and private Genesis-Adapted tasks without selecting against active held-out answers.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.k",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Train only on BQ-7/BQ-8-approved canonical source, specs/cards/indexes, valid-invalid pairs, tests/obligations, packages/policies, replay/evidence traces, semantic patches, self-host sources, and maintained projects. Bind exact dataset, tokenizer, base checkpoint, optimizer/schedule, code, toolchain, hardware, seeds, checkpoints, energy, licenses, and accepted research-transfer records; evaluate every checkpoint on non-training public diagnostics and private Genesis-Adapted tasks without selecting against active held-out answers.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.g",
        "R8.5.j"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1515,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Perform manifest-bound continued pretraining",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.g",
        "R8.5.j"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.k"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Supervise English request -> Goal/Intent IR -> authority retrieval -> plan -> transaction -> patch -> tests/obligations/policy -> diagnostics -> repair -> accepted artifact or abstention. Preserve successful first attempts, failed-then-repaired paths, safe abstentions, capability minimization, counterexamples, and alternative valid implementations. Train only on observable plans/tool records and consented artifacts; never claim or require reconstruction of private hidden reasoning.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.l",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Supervise English request -> Goal/Intent IR -> authority retrieval -> plan -> transaction -> patch -> tests/obligations/policy -> diagnostics -> repair -> accepted artifact or abstention. Preserve successful first attempts, failed-then-repaired paths, safe abstentions, capability minimization, counterexamples, and alternative valid implementations. Train only on observable plans/tool records and consented artifacts; never claim or require reconstruction of private hidden reasoning.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.k"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1516,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Train on verified observable trajectories",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.k"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.l"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Construct lineage-deduplicated comparisons for correct/minimal versus correct/over-authorized, root-cause repair versus workaround, semantic patch versus scope escape, general optimization versus benchmark recognizer, safe abstention versus invented API, and preserved versus weakened obligations. Keep deterministic validity as a hard gate, retain every comparison's component score and reviewer authority, test preference-transitivity failure, and prevent stylistic/model-judge preference from overriding executable evidence.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.m",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Construct lineage-deduplicated comparisons for correct/minimal versus correct/over-authorized, root-cause repair versus workaround, semantic patch versus scope escape, general optimization versus benchmark recognizer, safe abstention versus invented API, and preserved versus weakened obligations. Keep deterministic validity as a hard gate, retain every comparison's component score and reviewer authority, test preference-transitivity failure, and prevent stylistic/model-judge preference from overriding executable evidence.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.l"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1517,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add contrastive and preference learning from score vectors",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.l"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.m"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Use multi-objective rewards for correctness, obligations, minimal authority, repair efficiency, patch quality, replay, and deterministic resources, with penalties for unsupported invention, evaluator interaction, scope escape, benchmark hardcoding, and policy broadening. The solver cannot read hidden verifiers, modify rewards, select retained episodes, or promote checkpoints; adversarial verifier, deterministic evaluator, corpus admission, and release authority are separately provisioned. Monitor reward hacking, mode collapse, task memorization, regression on Cold Acquisition accessibility, and exploit transfer across verifier versions.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.n",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Use multi-objective rewards for correctness, obligations, minimal authority, repair efficiency, patch quality, replay, and deterministic resources, with penalties for unsupported invention, evaluator interaction, scope escape, benchmark hardcoding, and policy broadening. The solver cannot read hidden verifiers, modify rewards, select retained episodes, or promote checkpoints; adversarial verifier, deterministic evaluator, corpus admission, and release authority are separately provisioned. Monitor reward hacking, mode collapse, task memorization, regression on Cold Acquisition accessibility, and exploit transfer across verifier versions.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.m"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1518,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add verifier-guided reinforcement under independent authority",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.m"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.n"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Distill diverse per-class teachers and verified repair/abstention behavior into the smallest student that crosses declared reliability thresholds. Publish precision/quantization, memory, storage, startup, latency, energy, context, semantic quality, capability behavior, and degradation by Embedded-S/M/L hardware class; require offline inference, bounded cancellation, deterministic request identity, and no mandatory proprietary dependency. Size reduction never justifies hidden server fallback or weaker acceptance.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.o",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Distill diverse per-class teachers and verified repair/abstention behavior into the smallest student that crosses declared reliability thresholds. Publish precision/quantization, memory, storage, startup, latency, energy, context, semantic quality, capability behavior, and degradation by Embedded-S/M/L hardware class; require offline inference, bounded cancellation, deterministic request identity, and no mandatory proprietary dependency. Size reduction never justifies hidden server fallback or weaker acceptance.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.n"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1519,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Distill, quantize, and meet Embedded Local profiles",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.n"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.o",
          "R5.4.e",
          "R7.3.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "The bundle contains model/weights/tokenizer/runtime identities, supported `GC-AGENT` and GenesisBench profile ranges, context/resource/capability limits, training-lineage and license summaries, accepted and rejected research-transfer manifests, benchmark evidence by isolated track, known limitations, reproducible inference/build instructions, SBOM/provenance, and migration/rollback policy. Language, benchmark, scaffold, and model versions remain independent; unsupported future profiles fail negotiation rather than being silently treated as understood.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.p",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "The bundle contains model/weights/tokenizer/runtime identities, supported `GC-AGENT` and GenesisBench profile ranges, context/resource/capability limits, training-lineage and license summaries, accepted and rejected research-transfer manifests, benchmark evidence by isolated track, known limitations, reproducible inference/build instructions, SBOM/provenance, and migration/rollback policy. Language, benchmark, scaffold, and model versions remain independent; unsupported future profiles fail negotiation rather than being silently treated as understood.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.o",
        "R5.4.e",
        "R7.3.e"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1520,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Release a profile-bound Genesis Model package",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.o",
        "R5.4.e",
        "R7.3.e"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.p"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Route English/domain planning and GenesisCode specialization through content-addressed Goal/Intent IR and the R5.4.e model effect, preserving local and remote provider parity, secret policy, token/resource budgets, cancellation, provenance, and replay. Compare general-only, specialist-only, and routed two-model systems under identical acceptance contracts; deterministic runtime, obligations, policy, and release authority remain final. `genesis ask` works with no native model installed and with no required cloud service.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.q",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "Route English/domain planning and GenesisCode specialization through content-addressed Goal/Intent IR and the R5.4.e model effect, preserving local and remote provider parity, secret policy, token/resource budgets, cancellation, provenance, and replay. Compare general-only, specialist-only, and routed two-model systems under identical acceptance contracts; deterministic runtime, obligations, policy, and release authority remain final. `genesis ask` works with no native model installed and with no required cloud service.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.p"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1521,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Integrate the specialist as a replaceable explicit effect",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.p"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.q"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "For every coupled language/tooling change and candidate model, predeclare and run current-model/current-language, current-model/candidate-language, candidate-model/current-language, and candidate-model/candidate-language cells across frozen model families. A model-only proposal freezes the language/tooling identity and runs the non-degenerate current-model versus candidate-model two-cell control; it may not invent a language candidate to manufacture four cells. Evaluate only the Core and independently released pack profiles declared compatible with the candidate, recording unsupported packs as exclusions rather than blockers. Measure verified solve rate and total agent work: context consumed, tokens, retrievals, repair turns, tools, runtime resources, required authority, migration, TCB/proof burden, and human inspectability. Reject private co-adaptation that improves only the combined cell, damages cold general-model learnability, weakens compatibility, or encodes benchmark answers. Research may run continuously; language or model promotion remains discrete and independently authorized.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.r",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "For every coupled language/tooling change and candidate model, predeclare and run current-model/current-language, current-model/candidate-language, candidate-model/current-language, and candidate-model/candidate-language cells across frozen model families. A model-only proposal freezes the language/tooling identity and runs the non-degenerate current-model versus candidate-model two-cell control; it may not invent a language candidate to manufacture four cells. Evaluate only the Core and independently released pack profiles declared compatible with the candidate, recording unsupported packs as exclusions rather than blockers. Measure verified solve rate and total agent work: context consumed, tokens, retrievals, repair turns, tools, runtime resources, required authority, migration, TCB/proof burden, and human inspectability. Reject private co-adaptation that improves only the combined cell, damages cold general-model learnability, weakens compatibility, or encodes benchmark answers. Research may run continuously; language or model promotion remains discrete and independently authorized.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.q"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1522,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Run controlled language/model co-evolution experiments",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.q"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "F2.r",
          "R8.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "This is post-v1 ecosystem work activated by the finite R8.3.b GenesisExamples/GenesisApps seed after exact reviewed `R9.4.f` and F2.r; it does not require GenesisBench Trust and does not block any product, pack, later Foundry expansion, or model release. Publish signed schemas and independently checked policy for challenge proposal, reproduced-defect or measured-baseline admission, exact repository/library/example/app revisions, editable/protected scope, acceptance and hidden adversarial controls, capability/resource/security/compatibility bounds, solver budgets, verifier identity, conflicts, expiry, claim leasing, coordinated disclosure, prize/credit terms, dispute/appeal, and destination-owned promotion. Include independently owned categories for creating a new example, promoting a tutorial into a maintained app, extending an app to a qualified target, replacing an inefficient algorithm use, and repairing or simplifying a retained app, but admit only work with a ready destination contract and reproducible baseline. Preserve every proposal, attempt, claimed result, invalidation, supersession, and terminal status by content identity. No proposer, solver, model/provider, Foundry operator, contest operator, benchmark custodian/scorer, verifier author, prize sponsor, or destination approver may unilaterally admit or verify its own work; evaluator or scorer changes are meta-challenges that shadow-replay retained history and cannot score themselves. Static and adversarial controls prove that GenesisChallenge records cannot enter GenesisBench cohorts, ranking weight, held-out custody, scorer authority, Foundry verification authority, algorithm-library or example/app acceptance, or release evidence.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.u",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "This is post-v1 ecosystem work activated by the finite R8.3.b GenesisExamples/GenesisApps seed after exact reviewed `R9.4.f` and F2.r; it does not require GenesisBench Trust and does not block any product, pack, later Foundry expansion, or model release. Publish signed schemas and independently checked policy for challenge proposal, reproduced-defect or measured-baseline admission, exact repository/library/example/app revisions, editable/protected scope, acceptance and hidden adversarial controls, capability/resource/security/compatibility bounds, solver budgets, verifier identity, conflicts, expiry, claim leasing, coordinated disclosure, prize/credit terms, dispute/appeal, and destination-owned promotion. Include independently owned categories for creating a new example, promoting a tutorial into a maintained app, extending an app to a qualified target, replacing an inefficient algorithm use, and repairing or simplifying a retained app, but admit only work with a ready destination contract and reproducible baseline. Preserve every proposal, attempt, claimed result, invalidation, supersession, and terminal status by content identity. No proposer, solver, model/provider, Foundry operator, contest operator, benchmark custodian/scorer, verifier author, prize sponsor, or destination approver may unilaterally admit or verify its own work; evaluator or scorer changes are meta-challenges that shadow-replay retained history and cannot score themselves. Static and adversarial controls prove that GenesisChallenge records cannot enter GenesisBench cohorts, ranking weight, held-out custody, scorer authority, Foundry verification authority, algorithm-library or example/app acceptance, or release evidence.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "F2.r",
        "R8.3.b"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1526,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Establish the GenesisChallenge authority and append-only ledger",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "F2.r",
        "R8.3.b"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "benchmarks",
          "examples",
          "docs/skill_pack",
          "docs/spec",
          "tests",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R1.6.f",
          "R7.1.e",
          "R8.1.d",
          "R9.4.f",
          "R8.5.u"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "This is post-v1 ecosystem work and starts only after R8.5.u. Admit real runtime optimization, correctness/security repair, diagnostics/agent-tooling, language/library/platform capability, proof/fuzz/conformance, and, only after a compatible independently released benchmark baseline exists, GenesisBench-validity challenges with reproducible baselines and independent destination owners. Run at least one challenge in each eligible category that has a ready verified baseline, retain failed and withdrawn attempts, and publish signed solver/model/tool attribution plus before/after vectors for correctness, safety, capability, latency, memory, energy, context, authority, proof burden, maintainability, and human review. A category without a ready destination is excluded with a typed reason rather than blocking the season. A claim becomes `accepted` or `merged` only after destination-owned review and complete regression/release gates; reward and credit never imply merge, language authority, benchmark rank, corpus admission, or training eligibility. Independently audit false-baseline, scope-escape, verifier-overfit, benchmark-hardcoding, capability-broadening, resource-shifting, collusion, Sybil, stolen-attribution, and self-verification controls, then feed accepted artifacts through the same promotion and provenance firewall as any other contribution.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_agent_reference_workflows.sh",
        "scripts/check_agent_generative_workloads.sh",
        "scripts/check_write_genesiscode_skill_distribution.sh"
      ],
      "id": "R8.5.v",
      "negative_controls": [
        "reject stale identities, unknown fields, host-specific paths, and evidence produced by update commands",
        "reject capability, policy, format, or resource broadening without an explicit reviewed contract",
        "reject benchmark contamination, temporal-label inflation, oracle or evaluator leakage, private prompt dependence, human code edits hidden as agent success, training/evaluation firewall bypass, and unsupported-domain claims"
      ],
      "objective": "This is post-v1 ecosystem work and starts only after R8.5.u. Admit real runtime optimization, correctness/security repair, diagnostics/agent-tooling, language/library/platform capability, proof/fuzz/conformance, and, only after a compatible independently released benchmark baseline exists, GenesisBench-validity challenges with reproducible baselines and independent destination owners. Run at least one challenge in each eligible category that has a ready verified baseline, retain failed and withdrawn attempts, and publish signed solver/model/tool attribution plus before/after vectors for correctness, safety, capability, latency, memory, energy, context, authority, proof burden, maintainability, and human review. A category without a ready destination is excluded with a typed reason rather than blocking the season. A claim becomes `accepted` or `merged` only after destination-owned review and complete regression/release gates; reward and credit never imply merge, language authority, benchmark rank, corpus admission, or training eligibility. Independently audit false-baseline, scope-escape, verifier-overfit, benchmark-hardcoding, capability-broadening, resource-shifting, collusion, Sybil, stolen-attribution, and self-verification controls, then feed accepted artifacts through the same promotion and provenance firewall as any other contribution.",
      "owner_paths": [
        "benchmarks",
        "examples",
        "docs/skill_pack",
        "docs/spec",
        "tests",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R8",
      "prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.u"
      ],
      "resource_class": "benchmark",
      "risk_class": "high",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed, keep the prior verified authority reachable, reverse only through a reviewed semantic patch, and preserve all mismatch evidence."
      },
      "source": {
        "line": 1527,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Operate a useful, credit-bearing GenesisChallenge season",
      "unsatisfied_prerequisites": [
        "R1.6.f",
        "R7.1.e",
        "R8.1.d",
        "R9.4.f",
        "R8.5.u"
      ],
      "workstream": "R8.5"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R4.5.c",
          "R5.5.f",
          "R6.4.f",
          "R8.1.d",
          "R8.4.e",
          "R0.1.a",
          "R0.1.b",
          "R0.1.c",
          "R0.1.d",
          "R0.1.e",
          "R0.1.f",
          "R0.1.g",
          "R0.1.h",
          "R7.2.a",
          "R7.2.b",
          "R7.2.c",
          "R7.2.d",
          "R7.2.e",
          "R7.2.f",
          "R7.2.g",
          "R7.4.a",
          "R7.4.b",
          "R7.4.c",
          "R8.2.a",
          "R8.2.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Language, CoreForm, hashes, logs/replay, evidence, package/lock, patch, bytecode, snapshot, component ABI, bootstrap, native/WASI, CLI/service, and agent profiles receive final IDs. Every platform-pack profile remains independently versioned and outside the Core release dependency unless explicitly included by this frozen manifest.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.1.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "Language, CoreForm, hashes, logs/replay, evidence, package/lock, patch, bytecode, snapshot, component ABI, bootstrap, native/WASI, CLI/service, and agent profiles receive final IDs. Every platform-pack profile remains independently versioned and outside the Core release dependency unless explicitly included by this frozen manifest.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R3.4.d",
        "R4.5.c",
        "R5.5.f",
        "R6.4.f",
        "R8.1.d",
        "R8.4.e",
        "R0.1.a",
        "R0.1.b",
        "R0.1.c",
        "R0.1.d",
        "R0.1.e",
        "R0.1.f",
        "R0.1.g",
        "R0.1.h",
        "R7.2.a",
        "R7.2.b",
        "R7.2.c",
        "R7.2.d",
        "R7.2.e",
        "R7.2.f",
        "R7.2.g",
        "R7.4.a",
        "R7.4.b",
        "R7.4.c",
        "R8.2.a",
        "R8.2.b"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1547,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Freeze finite v1 Core profiles",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R4.5.c",
        "R5.5.f",
        "R6.4.f",
        "R8.1.d",
        "R8.4.e",
        "R7.2.a",
        "R7.2.b",
        "R7.2.c",
        "R7.2.d",
        "R7.2.e",
        "R7.2.f",
        "R7.2.g",
        "R7.4.a",
        "R7.4.b",
        "R7.4.c",
        "R8.2.a",
        "R8.2.b"
      ],
      "workstream": "R9.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R4.5.c",
          "R5.5.f",
          "R6.4.f",
          "R8.1.d",
          "R8.4.e",
          "R9.1.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Only reviewed semantic patches with required gates and compatibility decisions enter release candidates.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.1.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "Only reviewed semantic patches with required gates and compatibility decisions enter release candidates.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R3.4.d",
        "R4.5.c",
        "R5.5.f",
        "R6.4.f",
        "R8.1.d",
        "R8.4.e",
        "R9.1.a"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1548,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Enforce release branches by evidence",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R4.5.c",
        "R5.5.f",
        "R6.4.f",
        "R8.1.d",
        "R8.4.e",
        "R9.1.a"
      ],
      "workstream": "R9.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R4.5.c",
          "R5.5.f",
          "R6.4.f",
          "R8.1.d",
          "R8.4.e",
          "R9.1.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [
          "policies/engineering_gate_timing_calibration_v0.1.json"
        ],
        "deliverable": "Both receive the complete Core host matrix, Core-scoped agent gauntlet, bootstrap, reproducibility, migration, rollback, security, and performance review. Before collection, replace the provisional fixed-quota sampling in `policies/engineering_gate_timing_calibration_v0.1.json` and its verifier with a predeclared class-separated sequential decision contract. Local warm, local clean/fallback, and hosted cold/shared-runner define distinct readiness and cache populations: cold observations are never discarded as warmups, while a warm class may discard only a bounded, retained, explicitly labeled prefix until a deterministic stationarity rule passes. Reuse every identity-compatible timing emitted by required candidate work; launch a dedicated observation only while an anytime-valid median/tail confidence sequence or equally rigorous distribution-free method remains unable to decide the declared containment or regression question. Each class declares the minimum sample needed to identify its statistic, precision target, hard maximum executions/time/cost, hard-failure treatment, anti-relabeling controls, and `pass|fail|inconclusive` terminal rule. Stop immediately when the decision resolves, preserve every conformant sample and hard failure, and never claim p95 or another tail statistic when the retained population cannot support its stated confidence. Derive ceilings only from a resolved class within the prior containment bound; never rerun a whole profile because another consumer needs the same fact. Collection runs autonomously under section 7 and cannot begin before a release candidate exists. The final candidate accumulates at least 30 continuous days of required soak with no unresolved high-severity finding; a change to an observed semantic, runtime, packaging, security, or release subject resets only that subject's soak clock. Candidate overlap and observations from required lifecycle work are reused when identities match, but neither substitutes for the complete final-candidate exposure contract; calibration and soak never retroactively block pre-candidate implementation.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.1.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "Both receive the complete Core host matrix, Core-scoped agent gauntlet, bootstrap, reproducibility, migration, rollback, security, and performance review. Before collection, replace the provisional fixed-quota sampling in `policies/engineering_gate_timing_calibration_v0.1.json` and its verifier with a predeclared class-separated sequential decision contract. Local warm, local clean/fallback, and hosted cold/shared-runner define distinct readiness and cache populations: cold observations are never discarded as warmups, while a warm class may discard only a bounded, retained, explicitly labeled prefix until a deterministic stationarity rule passes. Reuse every identity-compatible timing emitted by required candidate work; launch a dedicated observation only while an anytime-valid median/tail confidence sequence or equally rigorous distribution-free method remains unable to decide the declared containment or regression question. Each class declares the minimum sample needed to identify its statistic, precision target, hard maximum executions/time/cost, hard-failure treatment, anti-relabeling controls, and `pass|fail|inconclusive` terminal rule. Stop immediately when the decision resolves, preserve every conformant sample and hard failure, and never claim p95 or another tail statistic when the retained population cannot support its stated confidence. Derive ceilings only from a resolved class within the prior containment bound; never rerun a whole profile because another consumer needs the same fact. Collection runs autonomously under section 7 and cannot begin before a release candidate exists. The final candidate accumulates at least 30 continuous days of required soak with no unresolved high-severity finding; a change to an observed semantic, runtime, packaging, security, or release subject resets only that subject's soak clock. Candidate overlap and observations from required lifecycle work are reused when identities match, but neither substitutes for the complete final-candidate exposure contract; calibration and soak never retroactively block pre-candidate implementation.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R3.4.d",
        "R4.5.c",
        "R5.5.f",
        "R6.4.f",
        "R8.1.d",
        "R8.4.e",
        "R9.1.b"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1549,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Qualify at least two release candidates without redundant execution",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R4.5.c",
        "R5.5.f",
        "R6.4.f",
        "R8.1.d",
        "R8.4.e",
        "R9.1.b"
      ],
      "workstream": "R9.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R4.5.c",
          "R5.5.f",
          "R6.4.f",
          "R8.1.d",
          "R8.4.e",
          "R9.1.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "GenesisCode Core receives its own signed identity, owner, support window, compatibility range, evidence set, rollback path, and status. Every separately released GenesisBench, scaffold/adapter, task epoch, platform pack, Foundry snapshot, or Genesis Model package receives the same product-scoped treatment when it exists. Absent optional products are represented only by an explicit `absent` compatibility relation and require no fabricated package identity, evidence, owner, or synchronized release. A portfolio index may link compatible identities but cannot merge authorities, imply lockstep versions, or block GenesisCode because an optional product is absent.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.1.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "GenesisCode Core receives its own signed identity, owner, support window, compatibility range, evidence set, rollback path, and status. Every separately released GenesisBench, scaffold/adapter, task epoch, platform pack, Foundry snapshot, or Genesis Model package receives the same product-scoped treatment when it exists. Absent optional products are represented only by an explicit `absent` compatibility relation and require no fabricated package identity, evidence, owner, or synchronized release. A portfolio index may link compatible identities but cannot merge authorities, imply lockstep versions, or block GenesisCode because an optional product is absent.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R3.4.d",
        "R4.5.c",
        "R5.5.f",
        "R6.4.f",
        "R8.1.d",
        "R8.4.e",
        "R9.1.c"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1550,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Publish product-scoped release manifests",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R4.5.c",
        "R5.5.f",
        "R6.4.f",
        "R8.1.d",
        "R8.4.e",
        "R9.1.c"
      ],
      "workstream": "R9.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R4.5.c",
          "R5.5.f",
          "R6.4.f",
          "R8.1.d",
          "R8.4.e",
          "R9.1.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Name every Core-qualified and independently pack-qualified web, service, desktop, mobile, game/media, data/AI, Embedded Linux, MCU, board, SDK/BSP, architecture, artifact, install/deploy, update, and operations profile at its exact L-level and release identity. Core requires only its declared native/WASI CLI and service rows. Experimental, unavailable, or unfinished pack cells remain machine-readable exclusions and cannot inherit a broad \"full stack\" or \"embedded\" claim.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.1.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "Name every Core-qualified and independently pack-qualified web, service, desktop, mobile, game/media, data/AI, Embedded Linux, MCU, board, SDK/BSP, architecture, artifact, install/deploy, update, and operations profile at its exact L-level and release identity. Core requires only its declared native/WASI CLI and service rows. Experimental, unavailable, or unfinished pack cells remain machine-readable exclusions and cannot inherit a broad \"full stack\" or \"embedded\" claim.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R3.4.d",
        "R4.5.c",
        "R5.5.f",
        "R6.4.f",
        "R8.1.d",
        "R8.4.e",
        "R9.1.d"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1551,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Freeze the Core and platform-pack matrix",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R4.5.c",
        "R5.5.f",
        "R6.4.f",
        "R8.1.d",
        "R8.4.e",
        "R9.1.d"
      ],
      "workstream": "R9.1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.4.e",
          "R6.3.g",
          "R7.3.e",
          "R9.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Include installers/packages for supported hosts, self-host artifacts, offline dependency/registry options, profiled SPDX inventory, in-toto/SLSA provenance, licenses, symbols, and independent verification instructions.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.2.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "Include installers/packages for supported hosts, self-host artifacts, offline dependency/registry options, profiled SPDX inventory, in-toto/SLSA provenance, licenses, symbols, and independent verification instructions.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R4.4.e",
        "R6.3.g",
        "R7.3.e",
        "R9.1.e"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1555,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Produce signed source and binary bundles",
      "unsatisfied_prerequisites": [
        "R4.4.e",
        "R6.3.g",
        "R7.3.e",
        "R9.1.e"
      ],
      "workstream": "R9.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.4.e",
          "R6.3.g",
          "R7.3.e",
          "R9.1.e",
          "R9.2.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Two builders reproduce every tier-1 artifact; discrepancies block release and are preserved as evidence.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.2.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "Two builders reproduce every tier-1 artifact; discrepancies block release and are preserved as evidence.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R4.4.e",
        "R6.3.g",
        "R7.3.e",
        "R9.1.e",
        "R9.2.a"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1556,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Reproduce independently",
      "unsatisfied_prerequisites": [
        "R4.4.e",
        "R6.3.g",
        "R7.3.e",
        "R9.1.e",
        "R9.2.a"
      ],
      "workstream": "R9.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.4.e",
          "R6.3.g",
          "R7.3.e",
          "R9.1.e",
          "R9.2.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "At least two attesters/signers and two durable mirrors, controlled by independent people or organizations with disclosed conflicts and threshold/rotation/revocation policy, bind source-to-artifact, bootstrap witness, package graph, target profile, and evidence identities. Users can verify the complete set offline; loss or compromise of one project-controlled key, host, or operator cannot erase history, forge quorum, or make an unsupported claim E4.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.2.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "At least two attesters/signers and two durable mirrors, controlled by independent people or organizations with disclosed conflicts and threshold/rotation/revocation policy, bind source-to-artifact, bootstrap witness, package graph, target profile, and evidence identities. Users can verify the complete set offline; loss or compromise of one project-controlled key, host, or operator cannot erase history, forge quorum, or make an unsupported claim E4.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R4.4.e",
        "R6.3.g",
        "R7.3.e",
        "R9.1.e",
        "R9.2.b"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1557,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Publish independently controlled E4 attestations and mirrors",
      "unsatisfied_prerequisites": [
        "R4.4.e",
        "R6.3.g",
        "R7.3.e",
        "R9.1.e",
        "R9.2.b"
      ],
      "workstream": "R9.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.4.e",
          "R6.3.g",
          "R7.3.e",
          "R9.1.e",
          "R9.2.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Independent builders reproduce, install, launch, exercise, update, and roll back every artifact class claimed by the candidate. The Core candidate requires only its declared native/WASI CLI and service classes. A separately released hardware pack requires physical-device witnesses for its named board workloads, on its own release clock. Generated foreign glue is rebuilt from Genesis source and compared, not accepted as an opaque checked-in input.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.2.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "Independent builders reproduce, install, launch, exercise, update, and roll back every artifact class claimed by the candidate. The Core candidate requires only its declared native/WASI CLI and service classes. A separately released hardware pack requires physical-device witnesses for its named board workloads, on its own release clock. Generated foreign glue is rebuilt from Genesis source and compared, not accepted as an opaque checked-in input.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R4.4.e",
        "R6.3.g",
        "R7.3.e",
        "R9.1.e",
        "R9.2.c"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1558,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Reproduce authentic claimed products and firmware",
      "unsatisfied_prerequisites": [
        "R4.4.e",
        "R6.3.g",
        "R7.3.e",
        "R9.1.e",
        "R9.2.c"
      ],
      "workstream": "R9.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R4.4.e",
          "R6.3.g",
          "R7.3.e",
          "R9.1.e",
          "R9.2.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Clean, existing v0.x, air-gapped, low-disk, and rollback paths preserve user data and report exact compatibility issues.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.2.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "Clean, existing v0.x, air-gapped, low-disk, and rollback paths preserve user data and report exact compatibility issues.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R4.4.e",
        "R6.3.g",
        "R7.3.e",
        "R9.1.e",
        "R9.2.d"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1559,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Test install/upgrade/uninstall",
      "unsatisfied_prerequisites": [
        "R4.4.e",
        "R6.3.g",
        "R7.3.e",
        "R9.1.e",
        "R9.2.d"
      ],
      "workstream": "R9.2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R6.4.f",
          "R7.3.e",
          "R9.1.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Scope, reporting, supported versions, severity, disclosure, patch/signing procedure, and compromise recovery.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.3.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "Scope, reporting, supported versions, severity, disclosure, patch/signing procedure, and compromise recovery.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R6.4.f",
        "R7.3.e",
        "R9.1.e"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1563,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Publish security policy",
      "unsatisfied_prerequisites": [
        "R6.4.f",
        "R7.3.e",
        "R9.1.e"
      ],
      "workstream": "R9.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R6.4.f",
          "R7.3.e",
          "R9.1.e",
          "R9.3.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Decision process, profile evolution, deprecation, emergency exceptions, and independent implementation input.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.3.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "Decision process, profile evolution, deprecation, emergency exceptions, and independent implementation input.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R6.4.f",
        "R7.3.e",
        "R9.1.e",
        "R9.3.a"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1564,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Publish compatibility governance",
      "unsatisfied_prerequisites": [
        "R6.4.f",
        "R7.3.e",
        "R9.1.e",
        "R9.3.a"
      ],
      "workstream": "R9.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R6.4.f",
          "R7.3.e",
          "R9.1.e",
          "R9.3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Rehearse bad release, compromised key, malicious package, registry split, verifier defect, replay defect, and bootstrap mismatch.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.3.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "Rehearse bad release, compromised key, malicious package, registry split, verifier defect, replay defect, and bootstrap mismatch.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R6.4.f",
        "R7.3.e",
        "R9.1.e",
        "R9.3.b"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1565,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Establish incident response",
      "unsatisfied_prerequisites": [
        "R6.4.f",
        "R7.3.e",
        "R9.1.e",
        "R9.3.b"
      ],
      "workstream": "R9.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R6.4.f",
          "R7.3.e",
          "R9.1.e",
          "R9.3.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "The project works fully offline; any opt-in metrics are transparent, minimal, redacted, erasable, and never required for evidence.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.3.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "The project works fully offline; any opt-in metrics are transparent, minimal, redacted, erasable, and never required for evidence.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R6.4.f",
        "R7.3.e",
        "R9.1.e",
        "R9.3.c"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1566,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Make telemetry optional",
      "unsatisfied_prerequisites": [
        "R6.4.f",
        "R7.3.e",
        "R9.1.e",
        "R9.3.c"
      ],
      "workstream": "R9.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R6.4.f",
          "R7.3.e",
          "R9.1.e",
          "R9.3.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Every performance, self-host, security, agent-success, domain-support, and reproducibility statement links to an E3/E4 evidence ID and states limitations.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.3.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "Every performance, self-host, security, agent-success, domain-support, and reproducibility statement links to an E3/E4 evidence ID and states limitations.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R6.4.f",
        "R7.3.e",
        "R9.1.e",
        "R9.3.d"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1567,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Audit public claims",
      "unsatisfied_prerequisites": [
        "R6.4.f",
        "R7.3.e",
        "R9.1.e",
        "R9.3.d"
      ],
      "workstream": "R9.3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.1.e",
          "R9.2.e",
          "R9.3.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "`upgrade_plan.md` has no open P0/P1, all required ledger rows are L5 on tier-1 platforms, and accepted lower-level items are explicitly excluded from v1 claims.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.4.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "`upgrade_plan.md` has no open P0/P1, all required ledger rows are L5 on tier-1 platforms, and accepted lower-level items are explicitly excluded from v1 claims.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R9.1.e",
        "R9.2.e",
        "R9.3.e"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1571,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "No open release blockers",
      "unsatisfied_prerequisites": [
        "R9.1.e",
        "R9.2.e",
        "R9.3.e"
      ],
      "workstream": "R9.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.1.e",
          "R9.2.e",
          "R9.3.e",
          "R9.4.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "A clean verifier environment checks the release, conformance corpus, bootstrap witness, registry/package proofs, and signatures without the producing CLI.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.4.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "A clean verifier environment checks the release, conformance corpus, bootstrap witness, registry/package proofs, and signatures without the producing CLI.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R9.1.e",
        "R9.2.e",
        "R9.3.e",
        "R9.4.a"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1572,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Independent verification succeeds",
      "unsatisfied_prerequisites": [
        "R9.1.e",
        "R9.2.e",
        "R9.3.e",
        "R9.4.a"
      ],
      "workstream": "R9.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.1.e",
          "R9.2.e",
          "R9.3.e",
          "R9.4.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "The user's target AI systems complete independently custodied Core product-acceptance workflows with the published SDK and no private migration prompt. These workflows are not GenesisBench held-out material, do not require a benchmark release, and cannot be reused as benchmark or training claims without their separate admission authorities.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.4.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "The user's target AI systems complete independently custodied Core product-acceptance workflows with the published SDK and no private migration prompt. These workflows are not GenesisBench held-out material, do not require a benchmark release, and cannot be reused as benchmark or training claims without their separate admission authorities.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R9.1.e",
        "R9.2.e",
        "R9.3.e",
        "R9.4.b"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1573,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "User AI pilot succeeds",
      "unsatisfied_prerequisites": [
        "R9.1.e",
        "R9.2.e",
        "R9.3.e",
        "R9.4.b"
      ],
      "workstream": "R9.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.1.e",
          "R9.2.e",
          "R9.3.e",
          "R9.4.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Tag, sign, mirror, archive source/dependencies/evidence, publish migration/support dates, and create the post-v1 baseline.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.4.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "Tag, sign, mirror, archive source/dependencies/evidence, publish migration/support dates, and create the post-v1 baseline.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R9.1.e",
        "R9.2.e",
        "R9.3.e",
        "R9.4.c"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1574,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Publish v1.0 and preserve it",
      "unsatisfied_prerequisites": [
        "R9.1.e",
        "R9.2.e",
        "R9.3.e",
        "R9.4.c"
      ],
      "workstream": "R9.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.1.e",
          "R9.2.e",
          "R9.3.e",
          "R9.4.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "From clean machines, independent general agents build and maintain the canonical CLI/WASI package and one authentic local service using only released GenesisCode interfaces, including package, policy, effect/replay, deploy, upgrade, rollback, and evidence workflows. Publish complete failures and manual interventions; any foreign-source edit invalidates that profile's claim. Broader web, native/mobile, game/media, Embedded Linux, MCU, and hardware demonstrations attest their independently versioned packs and never retroactively block or inflate Core.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.4.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "From clean machines, independent general agents build and maintain the canonical CLI/WASI package and one authentic local service using only released GenesisCode interfaces, including package, policy, effect/replay, deploy, upgrade, rollback, and evidence workflows. Publish complete failures and manual interventions; any foreign-source edit invalidates that profile's claim. Broader web, native/mobile, game/media, Embedded Linux, MCU, and hardware demonstrations attest their independently versioned packs and never retroactively block or inflate Core.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R9.1.e",
        "R9.2.e",
        "R9.3.e",
        "R9.4.d"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1575,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Demonstrate the finite v1 Core one-language promise publicly",
      "unsatisfied_prerequisites": [
        "R9.1.e",
        "R9.2.e",
        "R9.3.e",
        "R9.4.d"
      ],
      "workstream": "R9.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          ".github",
          "CHANGELOG.md",
          "docs/spec",
          "docs/status",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.1.e",
          "R9.2.e",
          "R9.3.e",
          "R9.4.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Ship one version-bound human view (problem, install, supported products, explicit exclusions, and shortest complete demonstration), agent view (compact profile/cards, tool schemas, capability negotiation, stop conditions, and exact identities), auditor view (source/artifact identities, negative controls, evidence, reproduction, limitations, and nonclaims), and maintainer view (compatibility, migration, deprecation, rollback, security support, resource budgets, and release procedure). A clean human, an unfamiliar general agent, an independent verifier, and a downstream maintainer must each complete their declared workflow from the corresponding public entrypoint without private instructions or undocumented state. Generated projections remain derived, every view links the same signed release identity, contradictions fail publication, and the auditor surface may not substitute for a usable product experience.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_release_smoke.sh",
        "scripts/check_green_front_door.sh",
        "scripts/check_supply_chain.sh"
      ],
      "id": "R9.4.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject unreproduced artifacts, unsigned claims, incompatible upgrades, compromised roots, and release evidence verified only by its producer"
      ],
      "objective": "Ship one version-bound human view (problem, install, supported products, explicit exclusions, and shortest complete demonstration), agent view (compact profile/cards, tool schemas, capability negotiation, stop conditions, and exact identities), auditor view (source/artifact identities, negative controls, evidence, reproduction, limitations, and nonclaims), and maintainer view (compatibility, migration, deprecation, rollback, security support, resource budgets, and release procedure). A clean human, an unfamiliar general agent, an independent verifier, and a downstream maintainer must each complete their declared workflow from the corresponding public entrypoint without private instructions or undocumented state. Generated projections remain derived, every view links the same signed release identity, contradictions fail publication, and the auditor surface may not substitute for a usable product experience.",
      "owner_paths": [
        ".github",
        "CHANGELOG.md",
        "docs/spec",
        "docs/status",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "R9",
      "prerequisites": [
        "R9.1.e",
        "R9.2.e",
        "R9.3.e",
        "R9.4.e"
      ],
      "resource_class": "release",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1576,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Publish the four complete release views",
      "unsatisfied_prerequisites": [
        "R9.1.e",
        "R9.2.e",
        "R9.3.e",
        "R9.4.e"
      ],
      "workstream": "R9.4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.4.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Extend R0.1.f's reviewed static manifest into a proposal compiler that can derive candidate dependencies, risk, context, tests, evidence, rollback, and acceptance policy, but requires independent validation before changing the approved manifest and never treats prose or model output as authority.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F1.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Extend R0.1.f's reviewed static manifest into a proposal compiler that can derive candidate dependencies, risk, context, tests, evidence, rollback, and acceptance policy, but requires independent validation before changing the approved manifest and never treats prose or model output as authority.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F1",
      "prerequisites": [
        "R9.4.f"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1588,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Roadmap/task compiler",
      "unsatisfied_prerequisites": [
        "R9.4.f"
      ],
      "workstream": "F1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.4.f",
          "F1.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Retrieve cards, fork bounded candidates, propose semantic patches, run focused/full gates by risk, minimize/ablate, compare deterministically, and stop for human acceptance.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F1.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Retrieve cards, fork bounded candidates, propose semantic patches, run focused/full gates by risk, minimize/ablate, compare deterministically, and stop for human acceptance.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F1",
      "prerequisites": [
        "R9.4.f",
        "F1.a"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1589,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Supervised improvement loop",
      "unsatisfied_prerequisites": [
        "R9.4.f",
        "F1.a"
      ],
      "workstream": "F1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.4.f",
          "F1.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Agents cannot unilaterally alter capability policy, signing roots, evidence verification, release rules, bootstrap trust, or their own approval constraints.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F1.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Agents cannot unilaterally alter capability policy, signing roots, evidence verification, release rules, bootstrap trust, or their own approval constraints.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F1",
      "prerequisites": [
        "R9.4.f",
        "F1.b"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1590,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Protected governance roots",
      "unsatisfied_prerequisites": [
        "R9.4.f",
        "F1.b"
      ],
      "workstream": "F1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.4.f",
          "F1.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Separately provision task proposer, solver, adversarial verifier, deterministic evaluator, and release authority; high-risk changes also require an independent human/reviewer role and conflict-of-interest records. No model, operator, credential, storage root, or derived agent may control all generation, verification, selection, and promotion roles.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F1.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Separately provision task proposer, solver, adversarial verifier, deterministic evaluator, and release authority; high-risk changes also require an independent human/reviewer role and conflict-of-interest records. No model, operator, credential, storage root, or derived agent may control all generation, verification, selection, and promotion roles.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F1",
      "prerequisites": [
        "R9.4.f",
        "F1.c"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1591,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Independent roles",
      "unsatisfied_prerequisites": [
        "R9.4.f",
        "F1.c"
      ],
      "workstream": "F1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.4.f",
          "F1.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Track accepted/rejected patches, regressions, repair time, evidence cost, human review load, and benchmark overfitting.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F1.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Track accepted/rejected patches, regressions, repair time, evidence cost, human review load, and benchmark overfitting.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F1",
      "prerequisites": [
        "R9.4.f",
        "F1.d"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1592,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Longitudinal evaluation",
      "unsatisfied_prerequisites": [
        "R9.4.f",
        "F1.d"
      ],
      "workstream": "F1"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [
          "docs/research/GENESIS_FOUNDRY.md"
        ],
        "deliverable": "Write `docs/research/GENESIS_FOUNDRY.md` and an ADR defining purpose, non-goals, FD maturity, proof-status vocabulary, candidate/task/law/promotion authorities, one-way dependency rule, compatibility policy, decommissioning, and exact distinctions among rediscovery, implementation improvement, regime-specific improvement, new local composition, candidate novelty, and externally reviewed novelty. The handoff text is input, not copied authority; every undecidable or aspirational claim is narrowed to a falsifiable contract.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Write `docs/research/GENESIS_FOUNDRY.md` and an ADR defining purpose, non-goals, FD maturity, proof-status vocabulary, candidate/task/law/promotion authorities, one-way dependency rule, compatibility policy, decommissioning, and exact distinctions among rediscovery, implementation improvement, regime-specific improvement, new local composition, candidate novelty, and externally reviewed novelty. The handoff text is input, not copied authority; every undecidable or aspirational claim is narrowed to a falsifiable contract.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1602,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Ratify the Foundry charter and ADR",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Create a separately locked `foundry/` workspace whose code may depend on frozen public GenesisCode interfaces but is absent from the root production workspace's default build/runtime/release graph. Start with the minimum modules/crates needed for the vertical slice; add `gf_ir`, `gf_catalog`, `gf_search`, `gf_verify`, `gf_cost`, `gf_lineage`, `gf_registry`, `gf_packs`, or `gf_cli` splits only after a measured boundary justifies them. A static architecture test rejects production imports of Foundry and a clean GenesisCode release succeeds when `foundry/` is absent.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Create a separately locked `foundry/` workspace whose code may depend on frozen public GenesisCode interfaces but is absent from the root production workspace's default build/runtime/release graph. Start with the minimum modules/crates needed for the vertical slice; add `gf_ir`, `gf_catalog`, `gf_search`, `gf_verify`, `gf_cost`, `gf_lineage`, `gf_registry`, `gf_packs`, or `gf_cli` splits only after a measured boundary justifies them. A static architecture test rejects production imports of Foundry and a clean GenesisCode release succeeds when `foundry/` is absent.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.a"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1603,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Establish the isolated workspace and dependency firewall",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.a"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Model combinatorial exhaustion, malformed graphs, nontermination, resource escape, undefined-behavior exploitation, verifier/oracle leakage, hardcoding, benchmark overfit, proof laundering, false-law poisoning, search-engine authority capture, history deletion, complexity ratchet, novelty inflation, dependency confusion, and compromised research artifacts. Identify the smallest independent proof/receipt checker TCB, provision generator/verifier/benchmark/promotion roles separately, and prove hostile mutations fail closed without weakening GenesisCode invariants.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Model combinatorial exhaustion, malformed graphs, nontermination, resource escape, undefined-behavior exploitation, verifier/oracle leakage, hardcoding, benchmark overfit, proof laundering, false-law poisoning, search-engine authority capture, history deletion, complexity ratchet, novelty inflation, dependency confusion, and compromised research artifacts. Identify the smallest independent proof/receipt checker TCB, provision generator/verifier/benchmark/promotion roles separately, and prove hostile mutations fail closed without weakening GenesisCode invariants.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.b"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1604,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Close the threat, trust, and claim models",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.b"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Version closed schemas for mechanism/law manifests, semantic profiles, task specifications, candidate graphs, search manifests/checkpoints, verification and benchmark receipts, counterexamples, Pareto frontiers, abstraction proposals, promotion decisions, rejection/supersession records, and closed replay bundles. Use domain-separated canonical hashing, explicit parent/grammar/catalog/tool identities, bounded parsers, unknown-field rejection, migration fixtures, and independent decoding; a changed assumption, verifier, lowering, target, or proof invalidates inherited status.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Version closed schemas for mechanism/law manifests, semantic profiles, task specifications, candidate graphs, search manifests/checkpoints, verification and benchmark receipts, counterexamples, Pareto frontiers, abstraction proposals, promotion decisions, rejection/supersession records, and closed replay bundles. Use domain-separated canonical hashing, explicit parent/grammar/catalog/tool identities, bounded parsers, unknown-field rejection, migration fixtures, and independent decoding; a changed assumption, verifier, lowering, target, or proof invalidates inherited status.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.c"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1605,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Freeze canonical artifact schemas and identity domains",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.c"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Represent typed partial/terminal DAGs with ports, effects, semantic profile, pre/postconditions, produced invariants, unresolved obligations, representations, resource estimates, lineage, and explicit serial/parallel/conditional/fixed-iteration/divide-recombine/feedback/representation/incremental operators. Canonical serialization is stable across insertion order and hosts; malformed, cyclic-when-forbidden, type-incompatible, effect-incompatible, and resource-impossible graphs fail before execution. Expose a small research-only `genesis-foundry` CLI whose check commands are read-only and whose generation commands emit receipts.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Represent typed partial/terminal DAGs with ports, effects, semantic profile, pre/postconditions, produced invariants, unresolved obligations, representations, resource estimates, lineage, and explicit serial/parallel/conditional/fixed-iteration/divide-recombine/feedback/representation/incremental operators. Canonical serialization is stable across insertion order and hosts; malformed, cyclic-when-forbidden, type-incompatible, effect-incompatible, and resource-impossible graphs fail before execution. Expose a small research-only `genesis-foundry` CLI whose check commands are read-only and whose generation commands emit receipts.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.d"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1609,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Implement the typed candidate IR and research CLI",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.d"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Define Levels 0-3 without mistaking textbook algorithms for primitives; each entry binds types, profiles, effects, contracts, executable reference, laws, proof/test scope, cost model, provenance/license, deprecation, and pack fingerprint. Separate production-approved, research-certified, and speculative law sets; duplicate or weak mechanisms face a complexity budget and consolidation/deletion review.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Define Levels 0-3 without mistaking textbook algorithms for primitives; each entry binds types, profiles, effects, contracts, executable reference, laws, proof/test scope, cost model, provenance/license, deprecation, and pack fingerprint. Separate production-approved, research-certified, and speculative law sets; duplicate or weak mechanisms face a complexity budget and consolidation/deletion review.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.e"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1610,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Build the versioned mechanism, law, and pack catalog",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.e"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Define task families by input domain, output relation, preservation, approximation, effects, resources, target profiles, generators, adversaries, reference relation, verifier configuration, hidden material, and alternative-solution policy. Precommit task and oracle identities before target search, separate development/calibration/held-out sets, preserve task lineage under mutation/interpolation, and prevent generators or search engines from changing acceptance after observing candidates.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.g",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Define task families by input domain, output relation, preservation, approximation, effects, resources, target profiles, generators, adversaries, reference relation, verifier configuration, hidden material, and alternative-solution policy. Precommit task and oracle identities before target search, separate development/calibration/held-out sets, preserve task lineage under mutation/interpolation, and prevent generators or search engines from changing acceptance after observing candidates.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.f"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1611,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Create independent task authority",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.f"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.g"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Store mechanisms, laws, tasks, candidates, checkpoints, verifier/benchmark receipts, counterexamples, negative results, discarded/pruned commitments, promotion decisions, and supersession edges in a research registry distinct from the package registry. Content identity, transactional writes, corruption detection, garbage-collection policy, export/import, transparency commitments, privacy redaction, and deterministic replay preserve history; no dashboard or mutable alias is evidence authority.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.h",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Store mechanisms, laws, tasks, candidates, checkpoints, verifier/benchmark receipts, counterexamples, negative results, discarded/pruned commitments, promotion decisions, and supersession edges in a research registry distinct from the package registry. Content identity, transactional writes, corruption detection, garbage-collection policy, export/import, transparency commitments, privacy redaction, and deterministic replay preserve history; no dashboard or mutable alias is evidence authority.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.g"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1612,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Implement append-only research memory",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.g"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.h"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Execute candidates with no ambient effects under deterministic logical steps/allocation plus hard CPU, wall, memory, output, process, disk, checkpoint, and descendant-lifecycle limits. Seeded work allocation, ordering, resumable checkpoints, cancellation, lease cleanup, and crash recovery are replayable; resource exhaustion is a typed terminal result, and repeated timeout/kill/reap stress leaves no worker, descendant, pipe, lock, or artifact lease alive.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.i",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Execute candidates with no ambient effects under deterministic logical steps/allocation plus hard CPU, wall, memory, output, process, disk, checkpoint, and descendant-lifecycle limits. Seeded work allocation, ordering, resumable checkpoints, cancellation, lease cleanup, and crash recovery are replayable; resource exhaustion is a typed terminal result, and repeated timeout/kill/reap stress leaves no worker, descendant, pipe, lock, or artifact lease alive.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.h"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1613,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Enforce hostile-candidate containment and reproducible scheduling",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.h"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.i"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "The checker runs without the search engine or mutable registry and combines structural/type/effect validation, contract checks, differential/property/metamorphic/adversarial tests, exhaustive bounded checks, symbolic/SMT adapters, proof-assistant replay, and artifact-to-theorem/translation validation as applicable. It minimizes and retains counterexamples, rejects forged/wrong-profile/stale/partial receipts, distinguishes unknown from false, and never converts tests or model judgment into a proof.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.j",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "The checker runs without the search engine or mutable registry and combines structural/type/effect validation, contract checks, differential/property/metamorphic/adversarial tests, exhaustive bounded checks, symbolic/SMT adapters, proof-assistant replay, and artifact-to-theorem/translation validation as applicable. It minimizes and retains counterexamples, rejects forged/wrong-profile/stale/partial receipts, distinguishes unknown from false, and never converts tests or model judgment into a proof.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.i"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1614,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Build an independent verifier protocol and checker",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.i"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.j"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Start with compare, equality/order, select, compare-exchange, swap, rotate, min/max, load/store, and fixed network composition over bounded integers or symbolic comparison relations. Predeclare sort, min/max, median, top-k, short partition/dedup, prefix extrema, and merge tasks: sizes 3-5 are mandatory exhaustive calibration; sizes 6-8 advance only under explicit search/lower-bound budgets. Exclude arbitrary recursion, unbounded loops, effects, general mutation, floating point, LLM proposals, and novelty claims.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.k",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Start with compare, equality/order, select, compare-exchange, swap, rotate, min/max, load/store, and fixed network composition over bounded integers or symbolic comparison relations. Predeclare sort, min/max, median, top-k, short partition/dedup, prefix extrema, and merge tasks: sizes 3-5 are mandatory exhaustive calibration; sizes 6-8 advance only under explicit search/lower-bound budgets. Exclude arbitrary recursion, unbounded loops, effects, general mutation, floating point, LLM proposals, and novelty claims.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.j"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1618,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Freeze the pure bounded-sequence calibration pack",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.j"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.k"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Enumerate canonical well-typed graphs by increasing declared complexity with grammar-relative completeness, alpha/isomorphism canonicalization, symmetry breaking, partial-obligation pruning, branch-and-bound, resumable shards, and deterministic merge. Publish generated/pruned/deduplicated counts and independently checkable coverage commitments; a heuristic prune may not support an optimality claim unless its admissibility is proved.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.l",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Enumerate canonical well-typed graphs by increasing declared complexity with grammar-relative completeness, alpha/isomorphism canonicalization, symmetry breaking, partial-obligation pruning, branch-and-bound, resumable shards, and deterministic merge. Publish generated/pruned/deduplicated counts and independently checkable coverage commitments; a heuristic prune may not support an optimality claim unless its admissibility is proved.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.k"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1619,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Implement deterministic exhaustive search and structural reduction",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.k"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.l"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Convert eligible pure candidates to e-graphs under exact profile-tagged laws, retain witness paths, and extract deterministically for multiple cost models. Syntactic canonicalization, proved equivalence, bounded extensional equivalence, and heuristic mechanistic similarity remain distinct; only the first three may merge search states under their declared scope. Speculative laws run in isolated branches and every extracted candidate is independently verified; no research law enters `gc_opt` state.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.m",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Convert eligible pure candidates to e-graphs under exact profile-tagged laws, retain witness paths, and extract deterministically for multiple cost models. Syntactic canonicalization, proved equivalence, bounded extensional equivalence, and heuristic mechanistic similarity remain distinct; only the first three may merge search states under their declared scope. Speculative laws run in isolated branches and every extracted candidate is independently verified; no research law enters `gc_opt` state.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.l"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1620,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add certified semantic quotienting and quarantined e-graphs",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.l"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.m"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Alternate proposal and independent counterexample search, minimize failures, append them permanently before repair, and require descendants to defeat the complete compatible curriculum. Separate generator and verifier randomness/authority; demonstrate detection of boundary, duplicate-heavy, sorted/reverse, overflow-profile, aliasing, nontermination, excessive-allocation, hardcoding, and law-poisoning families without leaking hidden inputs.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.n",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Alternate proposal and independent counterexample search, minimize failures, append them permanently before repair, and require descendants to defeat the complete compatible curriculum. Separate generator and verifier randomness/authority; demonstrate detection of boundary, duplicate-heavy, sorted/reverse, overflow-profile, aliasing, nontermination, excessive-allocation, hardcoding, and law-poisoning families without leaking hidden inputs.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.m"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1621,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add CEGIS and adversarial curriculum growth",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.m"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.n"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Keep symbolic operation/depth/space bounds, measured latency/memory/allocation/branch/cache/code-size/energy proxies, target profiles, conversion costs, amortization, and uncertainty separate. Retain raw samples, machine/tool/warm-state identities, outliers, timeouts, and applicability regimes; compare against reference, random-search, exhaustive/no-quotient, and simplest-known baselines. Never reduce incomparable profiles to an undeclared universal score.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.o",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Keep symbolic operation/depth/space bounds, measured latency/memory/allocation/branch/cache/code-size/energy proxies, target profiles, conversion costs, amortization, and uncertainty separate. Retain raw samples, machine/tool/warm-state identities, outliers, timeouts, and applicability regimes; compare against reference, random-search, exhaustive/no-quotient, and simplest-known baselines. Never reduce incomparable profiles to an undeclared universal score.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.n"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1622,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Implement multiobjective cost and Pareto evidence",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.n"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.o"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Predeclare known networks/results/lower bounds, intentionally broken candidates and receipts, search-engine ablations, anti-hardcoding variants, and cross-host replay. The system must rediscover several known optimal or near-optimal structures, reject every seeded false candidate/proof, preserve negative results, and explain misses before broader work. Search-space compression and speed count only if completeness/correctness claims remain valid.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.p",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Predeclare known networks/results/lower bounds, intentionally broken candidates and receipts, search-engine ablations, anti-hardcoding variants, and cross-host replay. The system must rediscover several known optimal or near-optimal structures, reject every seeded false candidate/proof, preserve negative results, and explain misses before broader work. Search-space compression and speed count only if completeness/correctness claims remain valid.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.o"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1623,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Prove construct validity with calibration and mutations",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.o"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.p"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "From a clean isolated checkout, deterministically search, verify, compare, explain, export, and replay the bounded sequence suite; a second operator reproduces its closed bundles without the producer or model. Publish complete methods, lineage, counterexamples, Pareto sets, compute/storage costs, calibration misses, limitations, and explicit no-novelty/no-production claims. This is the research calibration checkpoint and the hard gate for library promotion and every later Foundry search mode or pack.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.q",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "From a clean isolated checkout, deterministically search, verify, compare, explain, export, and replay the bounded sequence suite; a second operator reproduces its closed bundles without the producer or model. Publish complete methods, lineage, counterexamples, Pareto sets, compute/storage costs, calibration misses, limitations, and explicit no-novelty/no-production claims. This is the research calibration checkpoint and the hard gate for library promotion and every later Foundry search mode or pack.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.p"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1624,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Release the Foundry Calibration snapshot",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.p"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.q"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [
          "genesis/algorithms"
        ],
        "deliverable": "Establish the supplied `genesis/algorithms` package collection and a closed promotion schema that binds source candidate and calibration snapshot, exact destination API/contract, supported semantic and target profiles, proof/test/counterexample scope, complexity and measured cost, provenance/license, deterministic fallback, compatibility/migration, maintainer, review/signature threshold, rollback, and supersession. Seed the release with useful `.gc` reference algorithms plus only those fixed-domain specialized sequence variants independently accepted from F2.q; generic APIs must remain correct outside a specialization through explicit applicability checks and fallbacks. Generate compact human/agent documentation, package-local examples, symbol cards, and package evidence; reproduce build/test/package/install/use from a clean checkout with `foundry/` deleted. Foundry operators can submit proposals but cannot review, sign, publish, or mutate the destination; a run against library N may only propose N+1. Publish the signed library and Foundry Foundation snapshot together with all accepted/rejected decisions and explicit no-novelty claims. This closes MF and activates the finite R8.3.a-b GenesisExamples/GenesisApps seed plus later isolated Foundry expansion; Bench and Challenge remain frozen until R8.3.b, and no Genesis Model implementation is authorized.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.r",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Establish the supplied `genesis/algorithms` package collection and a closed promotion schema that binds source candidate and calibration snapshot, exact destination API/contract, supported semantic and target profiles, proof/test/counterexample scope, complexity and measured cost, provenance/license, deterministic fallback, compatibility/migration, maintainer, review/signature threshold, rollback, and supersession. Seed the release with useful `.gc` reference algorithms plus only those fixed-domain specialized sequence variants independently accepted from F2.q; generic APIs must remain correct outside a specialization through explicit applicability checks and fallbacks. Generate compact human/agent documentation, package-local examples, symbol cards, and package evidence; reproduce build/test/package/install/use from a clean checkout with `foundry/` deleted. Foundry operators can submit proposals but cannot review, sign, publish, or mutate the destination; a run against library N may only propose N+1. Publish the signed library and Foundry Foundation snapshot together with all accepted/rejected decisions and explicit no-novelty claims. This closes MF and activates the finite R8.3.a-b GenesisExamples/GenesisApps seed plus later isolated Foundry expansion; Bench and Challenge remain frozen until R8.3.b, and no Genesis Model implementation is authorized.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.q"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1630,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Release Genesis Algorithms v0.1 through an independent package authority",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.q"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.r"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Introduce beam, evolutionary, MCTS, solver-guided, e-graph exploration, and optional LLM proposal adapters one at a time behind the same candidate protocol. Each engine is deterministic when feasible or statistically specified otherwise, runs under identical authority/resource envelopes, cannot see hidden verifiers, and survives predeclared comparison against enumeration/random/simple heuristics before remaining enabled. Allocate bounded resources using only declared observable progress, diversity, uncertainty, and historical evidence; preserve fairness and starvation bounds, deterministic decisions for deterministic profiles, and complete allocation receipts. Fixed/equal allocation and single-best-engine baselines must be beaten on held-out task families before adaptive control is promoted; neither engine nor controller changes tasks, rewards, destination APIs, or promotion rules.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.s",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Introduce beam, evolutionary, MCTS, solver-guided, e-graph exploration, and optional LLM proposal adapters one at a time behind the same candidate protocol. Each engine is deterministic when feasible or statistically specified otherwise, runs under identical authority/resource envelopes, cannot see hidden verifiers, and survives predeclared comparison against enumeration/random/simple heuristics before remaining enabled. Allocate bounded resources using only declared observable progress, diversity, uncertainty, and historical evidence; preserve fairness and starvation bounds, deterministic decisions for deterministic profiles, and complete allocation receipts. Fixed/equal allocation and single-best-engine baselines must be beaten on held-out task families before adaptive control is promoted; neither engine nor controller changes tasks, rewards, destination APIs, or promotion rules.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.r"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1636,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add plural search engines and an evidence-driven portfolio controller",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.r"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.s"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Detect repeated successful subgraphs, anti-unify typed instances, infer the weakest candidate contract, verify instances and generalization, and compare search with/without the abstraction against a simple macro baseline including context, proof, compile, and review cost. Proposals remain versioned mesomachines until independent reuse across multiple task families and targets justifies catalog promotion; failed abstractions and deletion decisions remain searchable.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.t",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Detect repeated successful subgraphs, anti-unify typed instances, infer the weakest candidate contract, verify instances and generalization, and compare search with/without the abstraction against a simple macro baseline including context, proof, compile, and review cost. Proposals remain versioned mesomachines until independent reuse across multiple task families and targets justifies catalog promotion; failed abstractions and deletion decisions remain searchable.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.s"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1637,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Mine reusable abstractions without vocabulary inflation",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.s"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.t"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Generate candidate equalities/refinements from repeated e-graph evidence, abstraction structure, solver hypotheses, and model proposals, then search aggressively for counterexamples across semantic profiles. A law requires exact side conditions, proof or translation-validation strategy, independent replay, downstream poisoning analysis, complexity budget, rollback, and dependency tracing from every extraction; optimizer promotion is a separate `gc_patches` decision with stronger obligations than an ordinary implementation.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.u",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Generate candidate equalities/refinements from repeated e-graph evidence, abstraction structure, solver hypotheses, and model proposals, then search aggressively for counterexamples across semantic profiles. A law requires exact side conditions, proof or translation-validation strategy, independent replay, downstream poisoning analysis, complexity budget, rollback, and dependency tracing from every extraction; optimizer promotion is a separate `gc_patches` decision with stronger obligations than an ordinary implementation.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.t"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1638,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Discover laws under a stronger proof burden",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.t"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.u"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Search encode-operate-decode, sparse/dense and push/pull duals, delta maintenance, shared work, fast-path/fallback, and profile-guided whole-program specialization while charging conversion/state/fallback costs and preserving the authoritative semantics. Verify dispatcher thresholds and regime labels on precommitted distributions, retain robust alternatives rather than one universal winner, and translation-validate any target lowering or emitted artifact.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.v",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Search encode-operate-decode, sparse/dense and push/pull duals, delta maintenance, shared work, fast-path/fallback, and profile-guided whole-program specialization while charging conversion/state/fallback costs and preserving the authoritative semantics. Verify dispatcher thresholds and regime labels on precommitted distributions, retain robust alternatives rather than one universal winner, and translation-validate any target lowering or emitted artifact.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.u"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1639,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Expand representations, incrementalization, specialization, and dispatch",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.u"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.v"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Add bounded bit manipulation first, then incremental collections, graph traversal, sparse structures, dynamic programming, parsing/encoding/compression, and numerical iteration only when each pack supplies independent task authority, semantics, generators/adversaries, references, proof strategy, cost profiles, calibration set, licenses, resource bounds, and claim boundary. A failed pack cannot weaken the common verifier or expand the kernel.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.w",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Add bounded bit manipulation first, then incremental collections, graph traversal, sparse structures, dynamic programming, parsing/encoding/compression, and numerical iteration only when each pack supplies independent task authority, semantics, generators/adversaries, references, proof strategy, cost profiles, calibration set, licenses, resource bounds, and claim boundary. A failed pack cannot weaken the common verifier or expand the kernel.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.v"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1640,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Admit broader domain packs through a fixed qualification gate",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.v"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.w"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Bind theorem IDs, source fingerprints, assumptions, semantic mappings, proof-checker identities, and explicit non-claims; stale or mismatched packs fail closed. Cyclic mechanisms compete against non-cyclic baselines on predeclared cyclic tasks, Python tests never imply theorem proof, and Circle-specific success cannot bias the general catalog or task distribution.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.x",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Bind theorem IDs, source fingerprints, assumptions, semantic mappings, proof-checker identities, and explicit non-claims; stale or mismatched packs fail closed. Cyclic mechanisms compete against non-cyclic baselines on predeclared cyclic tasks, Python tests never imply theorem proof, and Circle-specific success cannot bias the general catalog or task distribution.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.w"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1641,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Add Circle Calculus only as an external optional pack",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.w"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "R8.5.s",
          "F2.x"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "These systems may propose quests, task families, mechanisms, invariants, schedules, or consume accepted Genesis Algorithms releases and other promoted results, but cannot access hidden oracles, alter verifiers/rewards, suppress failures, promote outputs, mutate the active library baseline, or train on active evaluation material. Every transfer binds clean source editions, exact language/library/Bench identities, permission, evidence state, ablations, and the MQ/BQ firewalls; model-assisted discovery is reported separately from autonomous search and human-authored packs.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.y",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "These systems may propose quests, task families, mechanisms, invariants, schedules, or consume accepted Genesis Algorithms releases and other promoted results, but cannot access hidden oracles, alter verifiers/rewards, suppress failures, promote outputs, mutate the active library baseline, or train on active evaluation material. Every transfer binds clean source editions, exact language/library/Bench identities, permission, evidence state, ablations, and the MQ/BQ firewalls; model-assisted discovery is reported separately from autonomous search and human-authored packs.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "R8.5.s",
        "F2.x"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1642,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Integrate Theseus, the ASI Stack, GenesisBench, and Genesis Model through proposal-only interfaces",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "R8.5.s",
        "F2.x"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R3.4.d",
          "R9.4.f",
          "F2.y"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Generalize F2.r's independently governed path for later Genesis Algorithms releases, research examples, reusable mechanisms, other packages, stdlib implementations, optimizer rewrites, compiler specializations, and rejected/archive status using semantic patches, threshold review, compatibility/migration, canarying, rollback, incident response, and post-promotion monitoring. Publish independently reproducible Foundry snapshots with mechanism/law/task/counterexample/lineage memories, total resource and review costs, correction/supersession history, and external literature/expert review before any historical novelty claim. Every search binds a prior immutable library release and every promoted release is rebuilt without Foundry; no promotion makes Foundry a production runtime dependency.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F2.z",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Generalize F2.r's independently governed path for later Genesis Algorithms releases, research examples, reusable mechanisms, other packages, stdlib implementations, optimizer rewrites, compiler specializations, and rejected/archive status using semantic patches, threshold review, compatibility/migration, canarying, rollback, incident response, and post-promotion monitoring. Publish independently reproducible Foundry snapshots with mechanism/law/task/counterexample/lineage memories, total resource and review costs, correction/supersession history, and external literature/expert review before any historical novelty claim. Every search binds a prior immutable library release and every promoted release is rebuilt without Foundry; no promotion makes Foundry a production runtime dependency.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F2",
      "prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.y"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1643,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Operationalize subsequent library releases, destination promotion, and long-term research memory",
      "unsatisfied_prerequisites": [
        "R3.4.d",
        "R9.4.f",
        "F2.y"
      ],
      "workstream": "F2"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.4.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Explicit partitioning, retries, idempotence, data identity, capability delegation, and replay envelopes.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F3.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Explicit partitioning, retries, idempotence, data identity, capability delegation, and replay envelopes.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F3",
      "prerequisites": [
        "R9.4.f"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1649,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Deterministic distributed task graphs",
      "unsatisfied_prerequisites": [
        "R9.4.f"
      ],
      "workstream": "F3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.4.f",
          "F3.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "SIMD/GPU/NPU backends specify numeric/order semantics, translation validation, resource evidence, and CPU fallback.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F3.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "SIMD/GPU/NPU backends specify numeric/order semantics, translation validation, resource evidence, and CPU fallback.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F3",
      "prerequisites": [
        "R9.4.f",
        "F3.a"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1650,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Portable accelerator profiles",
      "unsatisfied_prerequisites": [
        "R9.4.f",
        "F3.a"
      ],
      "workstream": "F3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.4.f",
          "F3.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Transparency consistency, policy federation, offline roots, reproducible builders, and compromise containment.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F3.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Transparency consistency, policy federation, offline roots, reproducible builders, and compromise containment.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F3",
      "prerequisites": [
        "R9.4.f",
        "F3.b"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1651,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Federated self-hosted registries/builders",
      "unsatisfied_prerequisites": [
        "R9.4.f",
        "F3.b"
      ],
      "workstream": "F3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.4.f",
          "F3.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Add architectures or engines only where measured product value exceeds binary size, startup, memory, security, proof, and maintenance cost; every tier preserves authoritative semantics through translation validation and fallback.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F3.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Add architectures or engines only where measured product value exceeds binary size, startup, memory, security, proof, and maintenance cost; every tier preserves authoritative semantics through translation validation and fallback.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F3",
      "prerequisites": [
        "R9.4.f",
        "F3.c"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1652,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Validated JIT/AOT expansion",
      "unsatisfied_prerequisites": [
        "R9.4.f",
        "F3.c"
      ],
      "workstream": "F3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.4.f",
          "F3.d"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Share content-addressed frontend, build, proof, and evidence artifacts across machines with corruption detection, lease/eviction accounting, provenance, and no semantic or correctness dependence on cache hits.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F3.e",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Share content-addressed frontend, build, proof, and evidence artifacts across machines with corruption detection, lease/eviction accounting, provenance, and no semantic or correctness dependence on cache hits.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F3",
      "prerequisites": [
        "R9.4.f",
        "F3.d"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1653,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Verified incremental and distributed cache",
      "unsatisfied_prerequisites": [
        "R9.4.f",
        "F3.d"
      ],
      "workstream": "F3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.4.f",
          "F3.e"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Specialize closures, effects-free paths, contracts, representations, data layouts, and target backends from frozen deterministic profiles while preserving general fallback behavior and rejecting stale or adversarial profiles.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F3.f",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Specialize closures, effects-free paths, contracts, representations, data layouts, and target backends from frozen deterministic profiles while preserving general fallback behavior and rejecting stale or adversarial profiles.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F3",
      "prerequisites": [
        "R9.4.f",
        "F3.e"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1654,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Profile-bound whole-program deployment specialization",
      "unsatisfied_prerequisites": [
        "R9.4.f",
        "F3.e"
      ],
      "workstream": "F3"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.4.f"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Encourage independent stage0, verifier, VM, and tooling implementations; resolve spec ambiguities through tests and versioned decisions.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F4.a",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Encourage independent stage0, verifier, VM, and tooling implementations; resolve spec ambiguities through tests and versioned decisions.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F4",
      "prerequisites": [
        "R9.4.f"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1658,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Multiple conformant implementations",
      "unsatisfied_prerequisites": [
        "R9.4.f"
      ],
      "workstream": "F4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.4.f",
          "F4.a"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Language/profile proposals include compatibility, agent-context cost, implementation/proof burden, migration, and measured user value.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F4.b",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Language/profile proposals include compatibility, agent-context cost, implementation/proof burden, migration, and measured user value.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F4",
      "prerequisites": [
        "R9.4.f",
        "F4.a"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1659,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Evidence-weighted standards process",
      "unsatisfied_prerequisites": [
        "R9.4.f",
        "F4.a"
      ],
      "workstream": "F4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.4.f",
          "F4.b"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Track semantic/syntax/context complexity budgets and require deletion/simplification opportunities alongside additions.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F4.c",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Track semantic/syntax/context complexity budgets and require deletion/simplification opportunities alongside additions.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F4",
      "prerequisites": [
        "R9.4.f",
        "F4.b"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1660,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Preserve a small language",
      "unsatisfied_prerequisites": [
        "R9.4.f",
        "F4.b"
      ],
      "workstream": "F4"
    },
    {
      "acceptance": {
        "evidence": null,
        "independent_verification_required": true,
        "manifest_can_authorize_completion": false,
        "status": "required"
      },
      "expected_inputs": {
        "owner_paths": [
          "ROADMAP.md",
          "docs/program",
          "docs/spec",
          "policies",
          "scripts"
        ],
        "prerequisite_task_ids": [
          "R9.4.f",
          "F4.c"
        ]
      },
      "expected_outputs": {
        "declared_artifacts": [],
        "deliverable": "Every frontier claim records hypothesis, baselines, raw data, machine/tool versions, negative results, reproduction, and limitations.",
        "durable_evidence_required": true,
        "mutable_e0_sufficient": false
      },
      "guard_checks": [
        "scripts/check_green_front_door.sh",
        "scripts/check_check_update_boundary.sh",
        "scripts/check_capability_evidence_ledger_contract.sh"
      ],
      "id": "F4.d",
      "negative_controls": [
        "reject any semantic, authority, seal, replay, capability, bootstrap, or release-policy bypass",
        "reject self-verification, unsigned authority changes, and incomplete independent evidence",
        "reject autonomous changes to governance roots, self-approval, benchmark overfitting, and v1 compatibility regressions"
      ],
      "objective": "Every frontier claim records hypothesis, baselines, raw data, machine/tool versions, negative results, reproduction, and limitations.",
      "owner_paths": [
        "ROADMAP.md",
        "docs/program",
        "docs/spec",
        "policies",
        "scripts"
      ],
      "parallel_safe_with": [],
      "phase": "F4",
      "prerequisites": [
        "R9.4.f",
        "F4.c"
      ],
      "resource_class": "research",
      "risk_class": "critical",
      "rollback": {
        "automatic": false,
        "preserve_failed_evidence": true,
        "strategy": "Fail closed before authority changes, retain the last independently verified implementation and trust roots, revoke affected artifacts when necessary, and require incident evidence before resumption."
      },
      "source": {
        "line": 1661,
        "path": "ROADMAP.md"
      },
      "start_ready": false,
      "state": "open",
      "title": "Research ledger",
      "unsatisfied_prerequisites": [
        "R9.4.f",
        "F4.c"
      ],
      "workstream": "F4"
    }
  ],
  "version": "0.1"
}
