Spec inventory notes for 02-SPEC-AUDIT
Scope: specification sources only. These notes do not assess code or proof. RULINGS.txt outranks every design statement when the two disagree.
How the design pages were read
- Counted 72
*.dc.htmlartifacts indesign/UI-FINAL-INSTRUCTIONS/. The package README groups them as 54 product screens because state variants share a product row. - I read the
<x-dc>template together with each page's<script data-dc-script>state/renderVals()logic.support.jsreplaces the raw<x-dc>block with a React root, interpolates{{...}}, evaluatessc-ifandsc-for, and binds event props. Therefore the rendered branches and generated labels below are part of the design; an unresolved placeholder in raw HTML is not the rendered specification. - Demo identities, handles, chats, message bodies, account addresses, counts, times, version numbers, sample recovery words, and sample findings are synthetic. Names such as Mara, Kit, Ravi, Theo, Kestrel, Frontier, and Ward are not product entities or required seed data. Their surrounding states, controls, safety copy, and behavior are requirements.
- Design-side click handlers, timers, fake installs, generated findings, sample calls, and browser previews are state demonstrations, not evidence that the product capability is built or works.
EDITS.mdexplicitly marks many of them “needs app capability.” support.jsitself is only the design renderer. It is not product implementation or product proof.
Complete design artifact inventory (all 72 pages)
Identity, recovery, destructive credentials, and onboarding (24 pages)
Create Account.dc.html: first-run account creation entry and a separate “Use recovery phrase” route.Create Password.dc.html: create and confirm a password; six characters minimum and 12+ suggested; password visibility controls.Sign In Final.dc.html: cold sign-in with password, Unlock action, and recovery-phrase fallback.Onboarding Welcome Returning.dc.html: returning-user shortcut that mirrors sign-in and can fall back to recovery.Forgot Password.dc.html: recover the password on the same identity using the password recovery phrase; 12 numbered word boxes in a 4x3 grid; upload a recovery-kit file; verify the phrase. The uploaded state is synthetic but real file reading/recovery is required.Restore Account.dc.html: restore an identity on a machine using a 12-box identity/recovery phrase or uploaded kit, then set and confirm a new password. This is distinct from forgot-password recovery.Recovery Kit.dc.html: show separate 12-word identity and password phrases, say “You need both,” copy both, download a kit file, require “I saved my recovery kit” before Continue. The displayed words are synthetic; download is a real required capability and the design itself has no download handler.Key Lost.dc.html: terminal “This device can no longer open your account” state with only restore-by-recovery-phrase action.006-007.dc.html: identity discoverability choice: public profile with exact searchable lowercase/digit username (3–30), or no public profile and fresh one-use links. One-use-link copy says it cannot be revoked, dies after one use, and expires after 24 hours.Burn Password.dc.html: second sign-in credential that permanently erases local OSL data with no recovery; requires current password, new/confirm fields, and exact typedERASEbefore enabling; can be skipped.Stealth Password.dc.html: second credential that opens a normal, fully working but empty/clean-slate OSL; current/new/confirm fields; can be skipped. It is not a fake productivity decoy.Owned Confirmation Verify.dc.html: ownership/key verification dialog with an exact comparison code, out-of-band comparison requirement, warning that a changed key can mean a new device or attack, and Accept/Cancel.Connection Choice.dc.html: choose Tor (honest 2–6 second travel time) or direct (under one second).Cover Insertion.dc.html: choose FREE “Insert on send” or PRO “Type naturally”; rendered animation illustrates the distinction.Old Messages.dc.html: choose old messages locked against a local compromise (with possible in-transit loss after badly timed restart) or readable to the user (nothing lost, but copied local data can read sent content).Device Storage.dc.html: choose deletion of unsent private messages and/or old messages; retained data is encrypted and nothing deletes without confirmation.Send Checks.dc.html: independently configure checks for unprotected messages, protected messages, and file metadata as Always/Ask/Never; checks are on-device only.Send Mode.dc.html: choose Clipboard, Double Enter (DANGEROUS), or Single Enter (DANGEROUS / MAY BREAK TOS). Dangerous modes require explicit “I understand.” OSL must send nothing unless it can prove the destination.Onboarding Browser.dc.html: detect supported browsers; per-browser consent, never blanket access; one row per browser; multi-profile Chrome uses an inline profile checklist, not duplicate browser rows; zero-browser state; Not now; fixed honesty copy says OSL never opens passwords or login stores. Browser/profile permutations are synthetic.Onboarding Install.dc.html: merged “Set up your apps” design for Signal, Discord, Telegram, and WhatsApp. Detection is binary DETECTED/NOT DETECTED; detected apps can be enabled/disabled; absent apps are dimmed with a reason and real Windows Install action. The 1.8-second “Installing…” transition is only a demo.Onboarding Detected.dc.html: legacy installed-app list and toggles. The design edit log says this is superseded and must not be implemented separately, even though its file manifest still calls it routed.Onboarding Visibility.dc.html: four independent settings—public-username lookup, friend requests from people the user talks to, message requests from people the user talks to, and OSL Chats profile visibility. SILENT means all four off; VISIBLE means all four on; intermediate combinations are allowed. Strangers still see nothing either way; settings remain editable later.Pro Code.dc.html: skippable Pro-code entry.Onboarding Pro Active.dc.html: activated in-place state, pixel-aligned with code entry: green filled/outlined “Code activated” box and Continue. The edit log specifies enter -> checking -> activated morph; actual validation is an app capability.
Workspace, settings, people, services, and dialogs (35 pages)
Home.dc.html: app launcher for product and carrier surfaces; notification flyout; settings/window controls; edit/toggle app tiles; Friends sidebar with invite/username entry, pending accept/decline, verified friend detail, private note, outgoing invitations and cancellation. A friend’s per-service whitelist rows toggle silently, dim, and become “Not whitelisted”; clicking again restores, with no notification to the friend. Public accounts are read-only visibility information. All shown people/accounts are synthetic.Home Empty.dc.html: same launcher with empty/default service state; OSL Chat, Scrub, and supported social/email app tiles. Product availability labels are requirements, but service/account examples are not data.Home Notifications Empty.dc.html: notifications enabled but no local activity.Home Notifications Off.dc.html: notifications disabled and route to Settings to enable.Inbox.dc.html: filtered encrypted conversation index (All/OSL/Connected/Requests), start-private-conversation action, OSL Chat/Enclave destinations, and request state.Inbox Empty.dc.html: no connected conversations; requires a service connection; empty Requests state.Activity.dc.html: local-only OSL audit trail, explicitly not collection of what other apps do; category counters and a reviewable key-change event.Activity Empty.dc.html: enabled local activity with no events.Activity Off.dc.html: activity recording off with action to enable future local events.People.dc.html: trusted-person/key-verification registry with summary counters, add/verify action, verified/open-chat and waiting/verify states.People Empty.dc.html: zero-state for the trusted-person registry.People Key Change.dc.html: prominent impersonation-risk state: safety number/key changed, review before chat, and review action. It must not be reduced to a quiet notification.Friends Dialog Populated.dc.html: friends dialog showing waiting, recently changed device/re-verify, and verified states.Friends Dialog Empty.dc.html: no-friends dialog and Add friend action.People In Chat Dialog Populated.dc.html: people in current supported chat with per-person verification/readiness; carrier-chat presence alone does not satisfy encryption approval.People In Chat Dialog Empty.dc.html: requires an open supported chat and handles no-friends state.Connections.dc.html: services/accounts/app-connection inventory, Open/readiness/unavailable states, browser surface, and consent-required future Android Workspace surface.Connections Empty.dc.html: no-services state plus no-native-app-status and consent-required device/app surfaces.Service.dc.html: per-carrier profile surface; shown Signal form says OSL opens a separate profile while the user’s normal app stays open.Native Protect Picker Populated.dc.html: choose a verified friend before protecting in an OSL-owned private panel; explicit promise that Discord is not read or controlled.Native Protect Picker Empty.dc.html: no-verified-friends state blocks protection.Local Protected Sheet Initial.dc.html: name and start a local protected chat that remains in OSL.Local Protected Sheet Prepared.dc.html: write/open content, encrypt and prepare a cipher-only payload that a kit can open.Local Protected Sheet Ready.dc.html: handoff/open separate carrier profile state while normal app remains open.Privacy.dc.html: local global protection policy, warnings before risky sends/local account scanning, and preview-before-scrub principle.Scrub.dc.html: attended, local-only discovery over explicitly selected local accounts; reads one at a time without credentials; reports possible public exposures; may keep a local record; Stop halts further work; discovery deletes nothing. AutoScrub (discovery plus deletion in reviewed batches) is a Pro capability. Every displayed account/count/result is synthetic.Scrub Review Dialog Empty.dc.html: confirm-list gate and nothing-selected state; only selected findings proceed, so deletion is never unseen/default.Burn Dialog Account.dc.html: destructive scope picker for this chat, this app, or entire local account; entire account includes identity, messages, recovery material, and settings; burn closes OSL and cannot be undone; offline devices receive deletion when reconnecting; choose this device/all devices.Settings.dc.html: one stable-scrollbar settings shell with the following required capability groups:- Account: optional public username change limited to once per 30 days; private invite link; Pro code; view recovery kit; monthly relay use with free-vs-direct accounting; encrypted local and enclave-media storage; prepaid additional data with no account; overage slows rather than bills or sends silently.
- Apps: choose among discovered native/browser profiles per service. Listed accounts are synthetic; profile-selection structure is required.
- Privacy/connection: Mullvad/Tor selection and optional Mullvad-on-launch; send mode; cover mode; pre-send and incoming-content checks.
- Discovery/friending: show OSL use to anyone/allowed people/no one; discovery ping response; OSL friends and OSL Chats contacts remain separate; independent who-can-add rules for each; independent profile visibility, transfer requests, message requests, request note, and optional auto-mirror.
- Security: old-message mode; normal, stealth, and burn passwords; auto-delete unsent/expired messages; best-effort screenshot resistance with explicit statement that capture cannot be fully blocked.
- Whitelist: default deny; person-plus-place scope, never global; verify before allow; key change can auto-revoke; refused sends are loud and never silent plaintext; expiry choices; “where am I exposed” list with explicit revoke/restore.
- Notifications: friend request, whitelist, and completed-scrub categories.
- Appearance/profile: theme, accent/background, display name/vibe, avatar image upload/remove, avatar color, profile background, and per-account visibility.
- Window/sounds: remember last position/size, centered default, or maximized; master sound and sound choice; quiet hours queue alerts and deliver them to Home after quiet hours, dropping nothing; explicit Save/reset and local-machine-only scope.
- About: version, update check, device status.
Settings Account Empty.dc.html: signed identity unavailable because no identity data; Create identity; recovery and traffic-ledger unknown states.Settings Account Loading.dc.html: waiting for local signed-identity ledger.Settings Account Locked.dc.html: unlock required to read device identities.Settings Account Unavailable.dc.html: cannot claim identity state, with Retry rather than fabricated data.Toast.dc.html: transient guidance to start a conversation from a verified friend profile.Update Dialog.dc.html: available update with release copy, Not now, GitHub details, and Install & restart.
OSL Chats, posts, and enclaves (7 pages)
OSLChats.dc.htmlis the flagship chat specification. The following are independent capability checks, not one “chat page works” claim:- Direct/Groups/Enclaves filters; search chats and messages; new chat; pinned/muted/unread/mention states. Incoming @username mentions produce a red channel badge, amber message emphasis, and
@ YOU; opening clears the badge. - Conversation right-click: pin/unpin, mute, settings, and leave group/enclave. A real leave must remove membership and re-key, not just hide the row.
- Message layout: own messages right-aligned in filled bubbles; others left with identity; group sender color; replies, reactions, timestamps, edited marker, timer, selective-recipient badges, view-once/spoiler states, and typing state without moving the message.
- Message right-click context: reaction emoji row, Reply, Pin, Copy, Edit for own messages, Delete, Block sender, and message info including sent/read-or-delivered/auto-delete/E2E status. Blocking shows an Unblock bar.
- Composer:
+ | input | send; attach file, encrypted GIF, encrypted client-tallied poll (not anonymous), selective audience (ONLY THESE/HIDE FROM), spoiler, and next-message disappearing timer from one second through 24 hours. Recipient-visible “sent only to you” honesty tag is mandatory. - Attachments: real picker and drag/drop; metadata stripping; VIEW ONCE enforcement; PLAINTEXT extracts text and sends no file/metadata; self-destruct timer; screenshots on view-once notify. These are app capabilities; the design demo is not proof.
- Timers: next-message timer distinct from chat default, deletes for everyone after read, cannot stop screenshots; edits are encrypted revisions with local history; one synchronized pinned message per chat.
- Calls: encrypted voice/video status, mute/end, explicit “OSL cannot listen or record.” Voice channels dock above the profile so chat remains usable; mute, screen share, shared browser, leave; Home ends call; moderator can mute-for-all or kick.
- Shared browser: host renders/streams one synchronized page into the encrypted call; peers’ browser/cookies/IP never touch the site. Current rendering is synthetic.
- Friends/profile: friends dropdown with verified/online state and DM navigation; any avatar, including own, opens profile with handle/fingerprint, verified/key-changed status, bio, stats, Message/Posts/Block/Edit as appropriate.
- Stories: viewer with progress/navigation; text, color, or real uploaded image; per-story audience; auto-burn; screenshot shield; view receipts. Receipts off means counts are not recorded at all. Own viewer may show seen-by/likes only within verified circle.
- Posts: text/image or image-only; accent/font customization; real image preview/remove; like/echo/reply/view counts; reply scope; burn timer; BURN NOW for own posts.
- Groups/enclaves member rail: role-grouped counts, role colors, online/you/bot tags; click profile; right-click role/mute/kick/ban.
- Membership invitation: group invite is signed; non-Steward enclave invite is a proposal requiring Steward plus one member approval before key issue; real membership change re-keys.
- Enclave roles: ranked Steward/Builder/Everyone and custom roles; a role can edit only lower roles; per-role POST/INVITE/MANAGE ROLES/BURN permissions; all role changes signed and visible.
- Enclave categories/channels: custom categories, create/delete, click collapse, double-click rename, right-click/ellipsis rename-new-delete, drag reorder/move; per-user category name/order/collapse state while channel creation/deletion syncs and is signed/announced. Typed TEXT/VOICE channel creation, duplicate suffixing, custom icon/category, view/post or join/speak rules, slow mode, NSFW/spoiler, and per-channel override beating enclave default.
- Enclave moderation/joining/housekeeping: invite-link/two-approval/questions rules; link expiry/use caps and pause; AutoMod on member devices; self-assign roles; voice moderation; ban list; granular permissions; auto-clean 24h/7d/30d; leaver scrub; read receipts; quiet hours; scheduled messages; threads, forum channels, events/RSVP, stage voice, join vetting, hide prior history, pins, sealed audit log.
- Bots: scripted participant with mandatory banner that it reads every message in this chat and nothing outside; minimum named-channel permissions, never admin; Discord bridge read-only and channel-scoped; commands send as the user’s message.
- Beacon comments: members can comment in a side thread under one-way steward announcements.
OSLChats No Active Thread.dc.html: populated conversation list with no selection and instruction to select a conversation.OSLChats No Friends.dc.html: Direct-filter empty state.OSLChats Groups Empty.dc.html: Groups-filter empty state.OSLChats Enclaves Empty.dc.html: Enclaves-filter empty state.OSLFeed.dc.html: encrypted posts only to chosen audiences, never public; compose posts; audience (verified friends/close circle/one enclave); retention (stays/24h/7d); likes/replies/media; encrypted stories; private profile editing and local Saved-post view. Displayed authors/posts/stats are synthetic.OSLServers.dc.html: join/create enclave; navigate text/read-only system/broadcast/voice channels; signed-build and automatic key-change channel semantics; channel-level timers; member/role rail; post/reaction; broadcast subscription where publisher sees count but not subscriber list. All named spaces and messages are synthetic.
Carrier strip and overlay states (5 pages)
Strip.dc.htmlis a reusable Discord/Telegram/Signal carrier overlay, with these independent checks:- Carrier/chat identification and protection state must be provable. If the composer or destination cannot be proven, actions disable and the UI says not to type protected text there; no plaintext fallback.
- Protection/wrap animation and composer feed only sealed content to the carrier; reveal affects only the local screen; lock seals the strip and requires the OSL password to reopen.
- Plan status, quick settings, burn, verified-sender whitelist, expiration timer, view-once, lock, reveal, and proof/log controls.
- Whitelist is person-plus-chat scoped; allow/refuse/wait states; modified-build warning says OSL can detect modification but cannot know what modified code does after decrypting.
- Timer accepts seconds/minutes/hours/days up to 30 days, deletes OSL’s copy and stops decrypting, and cannot stop screenshots; receipt/history panel states what actually happened.
- View once permits one opening for the chosen seconds, then OSL will not decrypt again, including for sender; off means normal timer applies.
- Burn scope chat/app/account, device/all-device reach, explicit both-sides request semantics, typed/gated confirmation, refusal instead of partial completion, and proof receipts read back from the wire rather than self-claimed.
- Quick settings: warnings; behavior on key/room changes; wordbank vs AI cover text; send method; clipboard clear; findability; whitelist; logs; full Settings.
- First-use coach marks persist dismissal and can be replayed by dev hook. The rendered script currently contains seven steps (Lock, Composer, Reveal, View Once, Burn, Verified Senders, Quick Settings), despite conflicting design prose described below.
Discord Overlay Checking.dc.html: Discord in-situ pre-send “Checking protection…” state before Send.WhatsApp Overlay Empty.dc.html: capture-only empty protected-chat state with Ready-to-enter/Copy.WhatsApp Overlay Draft.dc.html: captured protected draft state with visible byte-budget behavior (README specifies 28/1000) and Copy.WhatsApp Overlay Error.dc.html: capture/place failure with Retry; must not present failure as success.
Public website (1 page)
Website Home.dc.html: public early-access site with Free/Pro download purchase actions and explicit $5 one-month prepaid-code/no-renewal/no-stored-payment terms; honest beta message-protection explanation (local encryption, carrier sees encrypted form plus who/when, ordinary-text disguise not yet present); Scrub explanation (local scan, user-confirmed deletion, arriving at v1); links to technical explanations/features. Demo text and counts are synthetic marketing illustrations, while the limitation copy is specified.
Design-level conflicts and ambiguities to resolve by higher rulings
1. Onboarding Install.dc.html is marked kind:"retired" in its own shipping manifest and cites D10(a), while README.md, HANDOFF.md, and EDITS.md call its merged “Set up your apps” page the shipping design and say Onboarding Detected is superseded. Its manifest also says the canonical runtime route is intentionally unpaired. Treat this as a mismatch record, not permission to invent a replacement.
2. Onboarding Detected.dc.html still says kind:"routed" although the design edit log says do not implement it separately.
3. Strip.dc.html rendered code has seven coach steps and omits Timer and Plan from the tour. README.md says eight steps; the later EDITS.md prose lists nine anchors (Lock, Composer, Reveal, View Once, Timer, Burn, Verified Senders, Plan, Quick Settings). The rendered page is the design under the user's source rule, so seven is the pixel/runtime target unless a ruling overrides it.
4. Settings.dc.html calls the stealth password “Opens a decoy workspace,” contradicting the standing design decision and Stealth Password.dc.html meaning: clean-slate, fully working OSL, not a fake decoy. Use the standing decision unless a ruling is more specific.
5. Route metadata is not reliable capability truth: OSLFeed.dc.html is mapped to osl-mail although OSL Mail is cut; Website Home.dc.html maps to settings/appearance; Strip.dc.html maps to signal-qa. Use rendered structure/copy plus rulings, not these stale route labels.
6. The package README says “73 files” while there are 72 .dc.html pages; likely the count includes support.js. It also says 54 product screens because state variants collapse. Do not use 73 as a capability count.
7. 006-007.dc.html says a one-use link cannot be revoked, while Home.dc.html shows cancelable outgoing invites. These may be different invite types, but the design does not define the distinction. Do not silently merge them.
8. Settings.dc.html includes Mullvad and Mullvad-on-launch controls, but no Mullvad design page exists in this package; Onboarding Install.dc.html manifest records Mullvad onboarding as intentionally unpaired. Capability and UI parity must be audited separately.
9. OSL Chats design breadth is largely labeled synthetic by EDITS.md. Presence of working JavaScript in the design files proves only mock interaction, never transport, cryptography, deletion, view-once, calls, screen sharing, co-browsing, membership re-key, or real file handling.
Design counts
- 72
.dc.htmlartifacts inspected and accounted for: 24 identity/onboarding, 35 workspace/settings/dialog, 7 Chats/feed/enclave, 5 carrier/overlay, 1 website. - 54 product-screen groups claimed by the package README after state variants are collapsed.
- README/EDITS/HANDOFF contain 20 literal “app capability”/“needs app capability” markers and 16 uses of “synthetic.” These are flags, not a capability count; one marker often covers several behaviors. The largest family (
OSLChats.dc.html) must be split into the independent checks above for BUILT/PROVEN grading. - Capability granularity is not canonical. Counting one row per page would produce false green signals; the final audit should count atomic claims (for example, “voice panel renders,” “real encrypted voice works,” and “real multi-account call works” are separate).
Owner rulings inventory
The complete line-by-line inventory is in adjacent file .02-rulings-inventory.tmp.md. It was produced after reading all 2,977 lines and is the lossless source for the final audit: it lists each ID, its atomic requirement package, supersession, and ambiguity. Do not discard that file after using it.
Ruling counts and scope
- Exactly 75 distinct D-series IDs: 66 base IDs (
D1–D50,D53–D68; no D51/D52) and nine lettered addenda/corrections (D17a,D18a,D21a,D33a,D45(a),D45(b),D45(c),D54(a),D64(a)). - RULINGS also contains binding pre-D material: five opening machine-checkable rulings; decisions 1–20 and corrections; global self-healing, sidebar, and carrier-fidelity rulings; S1–S7; Q1–Q7; T1–T7; R1–R4; purchase/voucher/VM/test-resource rulings; “nothing left unbuilt”; and enclave self-moderation.
- A ruling ID often bundles multiple independently testable requirements. Seventy-five IDs must not become only 75 SPECIFIED rows.
Current authoritative outcomes (supersession applied)
- Voice, beacons, custom roles, forum channels, events/RSVP, and stage voice ship. Earlier absent/cut rulings are obsolete. Enclaves have no hard member cap; group chats cap at 20. Stage voice must refuse visibly at a measured limit rather than silently degrade (
nothing left unbuilt,D2,D16,T4,R1). - No global sidebar/rail and no separate Inbox, People, Privacy, Activity, or Connections routes. Honest content must be rehomed in Home notifications or Settings. Design pages that draw the old rail lose (
20(l), global sidebar ruling,D12(a),D41). - OSL Mail is post-V1/deferred and preserved, not a V1 gate. External email carriers remain relevant (
R2as refined byD9(d)). - Windows-only V1. Linux is a build/screenshot harness, not the product. Local Hyper-V
OSL-QA-1is permitted for genuinely separate installation; Azure stays dead/read-only and calibration VPSs are forbidden (S1, VM correction,D13). - All screen-driven carrier adapters must detect carrier UI/accessibility drift, self-repair, and visibly refuse instead of guessing; overlay appearance must match real carrier UI and be proven by real-account reference captures/structural diff, with blank-capture rejection (universal self-healing and carrier-fidelity rulings).
- Direct remains shipped default until the exact packaged-build Tor/default proof condition is rerun. Tor and OSL LAN are mutually exclusive with visible explanation (opening Direct ruling, decision 19).
- Normal offline send refuses immediately; there is no silent outbox/background retry. Low Data Mode parks zero bytes at relay and requires simultaneously online recipient, local resendable wait, and no silent parking fallback (
Q2,D24). - Recovery kit authorizes replacement and revokes all old devices. It restores identity/name/friends/receive ability, not message history; key change is shown. Losing all devices and kit is unrecoverable and tombstones the public name. Warn when issuing kit (
Q1). - Personal export must round-trip into a clean local OSL as a functioning account with identity/keys/friends/conversations/content/attachments/settings/memberships/device/recovery material; checksum-only proof is insufficient (
Q4/Q5,T2). - Destructive confirmations show real counts, everyone affected, what survives, and end with “cannot be undone”; the gate fails if shown and destroyed counts differ (
T3). - Central OSL moderation/reporting/content inspection/global reputation is forbidden. Enclave-local roles, permissions, removal/mute/restriction, signed local deletion, and post-decryption client-side local filtering ship. AutoMod cannot delete for others or create central evidence (
S5refined by enclave self-moderation,D14). - Co-owners can remove owners, destroy the enclave, and lock others out. No dispute/appeal defense exists; the grant UI must warn plainly (
S6 resolved). - Malware scan/quarantine for protected downloads, signing/root-key compromise recovery, carrier-version support/repair-time policy, and unattended cleanup retry/self-heal all ship; unrecoverable cleanup alerts go only by Telegram, with no staffed-response promise (
S2–S4,T6). - English-only launch, but all user-facing strings must be externalized now (
Q7). - Public profile split: relay may see only globally unique public name; display name, picture, status, bio, and per-enclave presentation are scoped ciphertext; disclose size/timing leakage and avoid byte-identical cross-enclave correlation (
D17,D17a). - Public-name format remains internally inconsistent: decision 11 says case-preserving
[A-Za-z0-9_], 1–16; D47 says lowercase, 3–30. No explicit supersession resolves this. - App onboarding is binary Detected/Not Detected; account claiming is Settings. D39 restores Onboarding Detected as a shipping page even though D4/D10/design history had superseded it (
D4,D5,D39). - Decoy/tutorial/recovery-protection refusal are deleted. Stealth is real clean-slate OSL. Recovery words always render while OS capture protection is requested (
D1,D9,D48,D55). - Password minimum is 12 with strength score >=3; safety number is 60 digits grouped by five plus QR. The design’s six-character floor and 12-digit examples are void (
D12(c/d)). - The eye is a click toggle revealing exact words; second click hides. “Hold to peek” is void. Strip coach is nine steps and click-to-reveal under the ruling even though the current rendered design script has seven (
D11,D12). - Send modes are exactly Single Enter, Double Enter, Clipboard. No Manual mode and no screenshot-resistance switch. Single/Double risks remain explicit (
D12,D50). - Cover default encodes bits in safe-ASCII word choice only, with no links/emoji/markdown. Capitalization/spelling channels stay off until carrier readback proves them. Error correction plus readback/self-heal/refusal handles residual corruption (
D33,D33a). - Wordbank cover must not be detected above 50% on balanced data; the recorded near-100% detector result is failure. AI cover still has a human-naturalness bar (
D37). - AI cover is absent from the shipping Windows binary because
llama-cpp-sys-2cannot cross-compile to windows-gnu. Linux model/library proof cannot establish Windows capability (D66). - Timer minimum is one minute and maximum currently 30 days. Key destruction must work on both devices for every supported carrier; optional carrier-message deletion is best effort only when live adapter capability supports it, and failure is disclosed. Email is key-only; X timer design is bound but does not itself promote X to release (
D15,D20,D22,D25). - Relay storage expiry and recipient view expiry are separate clocks: storage starts at send and deletes uncollected objects at expiry; full view window starts only when recipient opens (
D40). - Local data is permanent/unmetered and usable at zero relay allowance; relay expiry must never lock/hide it (
D23). - Clipboard current rule is consent, not location: user-pressed Copy/use of the expected value is allowed anywhere; autonomous read/write/hidden clipboard workspace is banned. Audit must point to the pressed control and matching value (
D54,D54(a), superseding T1/D31/D49). - Identity-choice onboarding contains only State A. Mint/link generation belongs in Friends add: single-use, 24-hour, only latest minted link active, real interactions, consensual Copy (
D47,D53,D54). - Story viewer asks before opening: named default, anonymous literal “user,” or hidden/no-count. Choice applies at open, not retroactively; relay learns no viewer identity; disclose small-audience inference (
D8). - New-joiner history is forward-only after signed epoch, default off, served by a named/visible member, entire eligible post-epoch window, and never gives pre-join keys. Refuse if this cannot be met (
D18,D18a). - Plaintext attachment means text encoded as an encrypted attachment with view-once/timer, never unencrypted (
D6). - Whitelist rows toggle silently/reversibly with visible local state, no notification and no confirmation (
D7). - Disconnect deletes credentials/tokens, mappings, cached geometry/appearance, and cover-history pointers locally; relink is fresh; already-sent carrier messages survive and disconnect is not deletion (
Q3). - Supported mail carriers are Gmail, Outlook, Proton, Yahoo, AOL, iCloud. GMX and mail.com are removed without damaging shared IMAP (
D35,D36). - Purchases ship through Stripe/BTC/XMR for unlinkable vouchers/top-ups, no stored payment data, explicit payment-rail privacy/wait/error disclosures, and no-refund. Ratified paid packs are Starter $2.99/5GB, Standard $5.99/50GB, Archive $11.99/150GB, no paid daily-message cap; Free retains cap. Re-measure real cost before sale (
in-app purchases, voucher correction, decision 8,D28,D45,D57). - Metering uses unlinkable vouchers and must disclose timing/cohort correlation; at low volume say “unlinked,” not “anonymous” (
decision 6, vouchers correction). - Carrier shipping is proof-gated per carrier. X/Instagram/Messenger catalogue presence does not establish Ready/sending. X is not promoted by timer design (
opening conditional-carrier ruling,D20). - Owner-controlled signed-in accounts may be used only within strict safety constraints: no public posting, CAPTCHA, 2FA/password entry, or messaging non-owner identities; evidence names the personal account and deletion risk (
D38). - Window & Sounds and Security Settings sections ship with real existing-path wiring; settings is one multi-section page and comparisons target regions, not invented pages (
D45(a/b),D57). - Five routes intentionally ship without design parity target—timed-delete-scheduler, settings/schedule, auto-whitelist-rules, friend, behaviour—but still require behavioral proof (
D65).
Proof/process rulings that directly change PROVEN grading
- Nothing is proven until it is present in canonical
integration/full, Rust builds,tsc --noEmitpasses, and the live wiring executes. Source grep or an isolated branch is insufficient (D19,D29,D32,D34). - Every UI capability/control/state needs behavioral contract, actual execution proof, observed red proof, and explicit dead-control reporting. Screenshot claims require before/after and multiple states/animations/actual clicks (
UI-plan merge,D58,D61). - Machine-grade shipping screens against rendered authoritative pages before owner review. Structure/copy/routes precede pixels. Synthetic content is excluded; structural verdict controls when whole-frame pixel identity is impossible. Unavailable reference fails except D65’s five explicit exceptions (
D26,D27,D45(c)). - A screen’s visual acceptance is not behavioral proof. Conditional review stays conditional until wiring works; verdict history cannot prove today’s binary or today’s capture freshness (
D62,D67,D68). - Current approved limits are D44: 8GB target machine; <=750MiB working set; <=2s cold start; <1% idle CPU; 100ms typical/250ms worst keypress, <=10% 8h growth, 5GB disk, and 100k-item Scrub <=30m are provisional and must be measured/labeled before V1. D21 is void (
D21a,D44). - Account readiness requires verifier plus dated owner attestation, refreshed from generated
proof/account-preconditions.json; attestation expires after seven days; store presence alone never proves sign-in (D59,D63). - Package checksums establish artifact identity only. They do not prove start, render, interaction, transport, or end-to-end behavior.
Ruling ambiguities that must remain visible
- Decisions 20(b)–(i) say “accepted” but omit the actual clauses; recover them from the cited decision/plan source before claiming their substance specified.
- Decision 17 delegates blocked wake-up connection behavior but records no selected behavior.
- D42 uses unmapped A/B review labels; its exact affected screen must be recovered from review artifacts.
- D62 says ten conditional screens but enumerates seven; use named screen IDs, not its count.
- D15’s one-minute floor is owner-confirmed; its 30-day upper bound is explicitly delegated/overturnable.
- D68’s accepted behavior verdict does not remove the need to inspect code and current proof; no ruling makes an owner screenshot review into end-to-end proof.