---
title: Virtual Realm Certification Plan
description: Deterministic bake, privacy, rendering, grounded traversal, local Cityform operations, Storylet, SecureMesh, bridge, recovery, accessibility, and architecture gates.
audience: QA engineers, security reviewers, rendering developers, and project leads
updated: 2026-08-13
status: approved planning baseline
---

# Virtual Realm Certification Plan

The Virtual Realm ships only after its authored bakes, live projections, Code Matter, Storylets, public shells, SecureMesh station, docking protocol, rendering, recovery, and accessibility pass evidence-backed gates.

## Existing test foundations

The plan can extend these repository harnesses:

- Fixed-step browser loop: `tests/common/TestLoop.js`
- Shared canvas and fatal-error surface: `tests/common/TestPage.js`
- WebGPU vertical-slice setup: `tests/phase1_webgpu/main.js`
- Render, material, bloom, particle, and GPU-tile compile smoke pages under `tests/`
- Shared GPU validation and real pixel readback: `tests/morphfield/morphfield.test.js`
- Numeric visual parity: `tests/car-drive-visual-parity.html`
- Browser width containment runner: `tests/browser-extension-popup-responsive.test.js`
- Three-peer WebRTC regression: `tests/network/collab-core-three-peer-regression.js`
- Deterministic negotiation and reconnect tests: `tests/network/collab-targeted-negotiation-state.test.js`
- Realm Network browser runner: `tests/network/run_realm_browser_tests.py`
- RealmForge reconstruction tests under `tests/realmforge/`
- Isolated Storylet and adversarial harness: `webgpu-os/kernel/storylets/StoryletTestRunner.js`
- M0 browser contract runner: `tests/network/realm/virtual-realm-m0.test.html` and `tests/network/realm/virtual-realm-m0.test.js`
- M0 real-Engine clean-room runner: `tests/network/realm/virtual-realm-m0-engine-foundations.test.html` and `tests/network/realm/virtual-realm-m0-engine-foundations.test.js`
- M0 exact signer-set runner: `tests/network/realm/virtual-realm-m0-signer-completion.test.html` and `tests/network/realm/virtual-realm-m0-signer-completion.test.js`
- M0 owner-local operations, minimap, camera-bound, authority, and connected-exclusion runner: `tests/network/realm/virtual-realm-m0-local-operator-view.test.html` and `tests/network/realm/virtual-realm-m0-local-operator-view.test.js`
- M0 frozen cross-client vectors: `tests/network/realm/virtual-realm-m0-vectors-v1.json`
- Independent M0 Python verifier: `tests/network/test_virtual_realm_m0_vectors.py`

The repository does not yet have a complete final-frame screenshot or perceptual-diff system, a 3D viewport/DPR matrix, automated full device recovery, or Virtual Realm public/private noninterference testing. These remain required work.

## Contract gates

| Gate | Required proof |
| --- | --- |
| `VR-CONTRACT-001` | Every V1 fixture canonicalizes to identical bytes and digests across supported clients |
| `VR-CONTRACT-002` | Exact-key parsers reject unknown fields, duplicate keys, malformed Unicode, unsafe numbers, excessive depth, excessive counts, and oversized payloads before expensive allocation |
| `VR-CONTRACT-003` | Proposals, authority receipts, authoritative observations, deltas, and presentation commands remain distinct record families |
| `VR-CONTRACT-004` | Unknown major versions, forbidden downgrades, stale revisions, expired envelopes, replayed nonces, and stale capability or bridge epochs fail closed |
| `VR-CONTRACT-005` | Public, private, refinement, rendezvous, bridge, and replay ID namespaces cannot be joined without an authorized local mapping |
| `VR-CONTRACT-006` | Contract errors expose bounded reason codes and opaque IDs without echoing protected input |
| `VR-CONTRACT-007` | Synthetic decoy allow and hard-deny trees prove canonical, symlink-safe, pre-enumeration denial before enumerate, stat, open, hash, watch, preview, or retry; no denied name enters logs and the real excluded application is never touched as a test fixture |
| `VR-CONTRACT-008` | Frozen content-address vectors exclude self IDs, self digests, signatures, and transport envelopes; resource references form one acyclic precomputed DAG and self or transitive cycles fail before publication |
| `VR-CONTRACT-009` | Frozen signature-envelope vectors match the exact domain, length prefixes, format, major version, publisher, audience, policy, issue, expiry, nonce, and content digest; an envelope is computed after content and never grants authority |

## Playground clean-room gates

| Gate | Milestone | Required proof |
| --- | --- | --- |
| `VR-CLEAN-001` | M0 and every later milestone | An allow-listed static import scan proves production and release fixtures contain no import, dynamic import, URL resolution, worker, shader include, or asset reference into `tests/playground/**` |
| `VR-CLEAN-002` | M2 and M7 | Shipping bundle and runtime-resource inspection finds no Playground demo WGSL, DOM/CSS, panel text, demo identifier, camera choreography, orbit/director control, authored graph topology, botanical witness scene, or animation constants |
| `VR-CLEAN-003` | M2 | `RealmEngineAdapter` accepts only the explicitly injected Engine namespace; tests with poisoned `window.PE`, loader promises, asset-base globals, raw module paths, and service locators cannot change resolution or behavior |
| `VR-CLEAN-004` | M2 | Missing export, incompatible version, invalid rasterizer mode, missing source bridge, registration failure, and incompatible decision fail closed as explicit unavailable presentation; no native or synthetic fallback claims State-First or live evidence |
| `VR-CLEAN-005` | M2 to M7 | Cancellation before and after every await, supersession, stale generation, stale authority epoch, partial initialization, registration failure, detach failure, double dispose, device loss, and restart produce no late mutation, leaked listener, pointer lock, subscription, source, reservation, or GPU allocation |
| `VR-CLEAN-006` | M3 | Permuted concurrent observations remain causally incomparable without explicit parents; frame order, GPU order, source arrival order, locale, and wall time cannot create a causal edge or universal clock |
| `VR-CLEAN-007` | M3 to M7 | A proposal, selected projection, belief, similarity result, rejected witness, historical record, Storylet, State-First representation decision, or rendered frame cannot consume exclusive state, mint or widen capability, commit a branch, or claim terminal success |
| `VR-CLEAN-008` | M3 to M4 | Selecting and rendering a branch leaves canonical state unchanged; exactly one valid authority commit can advance it; idempotent retry preserves the semantic receipt; conflicting consumption fails; rejected history remains non-authoritative |
| `VR-CLEAN-009` | M4 | Public historical-witness noninterference changes owner-private candidate facts, count, order, topology, timing, identity, eligibility, selection, and receipt material while public output remains byte-identical under identical declared public input |
| `VR-CLEAN-010` | M2 to M7 | State-First representation changes can alter presentation metadata only; they cannot create, remove, reparent, disclose, authorize, collide, navigate, or semantically mutate an entity, bake, observation, or delta |
| `VR-CLEAN-011` | M1 | Every Root Algebra optimization records frozen proof obligations, bounds, law report, counterexamples, versions, numeric policy, baseline digest, immutable-plan digest, exact CPU parity, and compatible WGSL parity; every failure executes the mandatory baseline compiler and emits no optimized kernel |
| `VR-CLEAN-012` | M1 to M7 | Root Algebra outputs cannot enter action authority, disclosure classification, hidden-topology discovery, CSE branch choice, Storylet eligibility, security enforcement, or post-publication bake mutation |
| `VR-CLEAN-013` | M2 and M7 | Exactly two independently authored modes exist: grounded first-person traversal and the bounded owner-private local Operations View. No Playground camera expression, orbit, director, detached observatory, analytic graph navigation, free camera, third-person Traveler, or connected-Cityform overview enters release code or resources |
| `VR-CLEAN-014` | M0 and M7 | The audited-source ledger cites exactly the 15 allow-listed Playground files plus `engine/state/index.js`, assigns each an API/invariant/preview/deferred disposition, and preserves the existing excluded-application assertion without using that application as a source or fixture |

## Bake and dependency gates

| Gate | Required proof |
| --- | --- |
| `VR-BAKE-001` | One canonical RealmForge document compiled twice produces byte-identical manifests and resource digests |
| `VR-BAKE-002` | Every reference resolves through an exact sorted dependency closure |
| `VR-BAKE-003` | Authoring preview and runtime match declared color, depth, object-ID, anchor, and collision tolerances |
| `VR-BAKE-004` | Compiler, adapter, primitive, material, numeric, Storylet, and renderer versions bind the bake root |
| `VR-BAKE-005` | Failed publication preserves the prior verified root |
| `VR-BAKE-006` | Canonical topology fixtures produce identical Root Spine, territory, parcel, reserved-growth, HLOD, route, anchor, collision, navigation, and streaming digests |
| `VR-BAKE-007` | Insert, rename, move, removal, mount, cycle, cross-link, overflow, and huge-tree fixtures preserve every anchor outside the smallest required deterministic repack region |
| `VR-BAKE-008` | Required route, junction, grade separation, building, rail, conduit, socket, collision, and navigation clearances either pass exactly or fail compilation with an omission or rejection receipt |
| `VR-BAKE-009` | Private, public, and refinement jobs run from independent source projections and ID namespaces; private coordinates, weights, depth, routes, caches, and relocations cannot affect public or refinement layout |

## Privacy and protected-content gates

| Gate | Required proof |
| --- | --- |
| `VR-PRIV-001` | Different private machines with identical public inputs produce byte-identical public manifests and identical canonical semantic-scene digests; pixel comparisons are regression evidence only inside one frozen reference renderer, browser, driver, device, resolution, DPR, and tolerance profile |
| `VR-PRIV-002` | Public dependency closure cannot reach private, refinement, unlabeled, or forbidden resources |
| `VR-PRIV-003` | Unauthenticated capture contains only documented beacon and public-shell data |
| `VR-PRIV-004` | Seeded secrets never appear in manifests, traces, logs, telemetry, Chronicle, GPU labels, crash reports, or public caches |
| `VR-PRIV-005` | With identical declared public inputs and publication schedule, private filesystem, source, process, topology, and private-activity changes do not alter the dedicated public beacon or shell-publication payload, envelope class, scheduled-send decision, skyline, shell digest, or public Storylet eligibility |
| `VR-PRIV-006` | Protected cleanup removes geometry, collision, navigation, interaction, atlas pages, keys, and accessible caches within bounds |

## Safe-text gates

| Gate | Required proof |
| --- | --- |
| `VR-TEXT-001` | Malformed UTF-8, unpaired surrogates, NUL, disallowed controls, forbidden bidi controls, and purpose-incompatible line breaks fail before DOM, GPU, audio, Chronicle, or network publication |
| `VR-TEXT-002` | NFC normalization, byte limits, grapheme limits, language tags, direction metadata, and canonical text digests match frozen international test vectors |
| `VR-TEXT-003` | HTML, Markdown, CSS, script, URL-like, and prompt-injection strings are never interpreted; DOM uses text-only insertion, the semantic mirror escapes content, and GPU text consumes only validated shaped glyph runs |
| `VR-TEXT-004` | RTL isolation, combining marks, emoji sequences, fallback fonts, missing glyphs, and GPU shaping preserve the validated semantic text without introducing hidden controls or renderer disagreement |
| `VR-TEXT-005` | Mixed-script and visually confusable display names carry policy-bounded spoof metadata while the verified identity badge or fingerprint remains visually and semantically separate from the name |
| `VR-TEXT-006` | City names, station labels, destinations, Traveler names, Storylet captions, announcements, signs, and semantic-mirror strings can enter a remote artifact only through an audience-matching `RealmSafeTextV1` reference in the complete dependency closure |

## Code Matter gates

| Gate | Required proof |
| --- | --- |
| `VR-CODE-001` | Revealed source matches authorized bytes, Unicode, line endings, offsets, and revision |
| `VR-CODE-002` | Sealed public marks never derive from protected bytes |
| `VR-CODE-003` | Structured output exposes only declared token classes and fields |
| `VR-CODE-004` | Expired or revoked leases cannot load or render new chunks |
| `VR-CODE-005` | Atlas eviction and reuse cannot expose another object's glyphs |
| `VR-CODE-006` | Sealed, structured, revealed, proposed, and historical states remain distinguishable without hue alone |
| `VR-CODE-007` | Every readable glyph instance in a code-built 3D object maps to the authorized object revision, byte range, token, line, column, and active reveal lease |
| `VR-CODE-008` | Private source changes cannot alter a public sealed object's glyph distribution, silhouette, timing, collision, or public scene digest |
| `VR-CODE-009` | Concurrent workers, restart, crash, rotation, envelope rewrap, allocator corruption, and recovery never repeat one `(vaultKeyId, keyEpoch, IV)` tuple; uncertain allocator state fails before encryption |
| `VR-CODE-010` | Lost persistent key material yields explicit sealed-key-unavailable state and requires fresh operator-authorized source ingestion; ciphertext is never guessed, silently decrypted, or presented as recovered |

## Live-projection gates

| Gate | Required proof |
| --- | --- |
| `VR-LIVE-001` | Boot, filesystem, process, IPC, syscall, permission, storage, network, and Code Matter each have one typed observation family, one owning port or source authority, and one pure projector before RealmDelta reduction |
| `VR-LIVE-002` | One frozen trace reproduces a boot-to-process-to-syscall-to-IPC-to-storage/network first-person route with exact causal observation IDs, source sequences, semantic axes, bake binding, and anchor binding |
| `VR-LIVE-003` | Syscall observations and route deltas never contain arguments, return payloads, paths, values, source bytes, raw handles, capability tokens, credentials, command lines, stack traces, or dispatch authority |
| `VR-LIVE-004` | Boot readiness, syscall completion, IPC delivery, storage completion, and network success appear only after their authoritative terminal observations; missing, denied, stale, failed, or cancelled evidence cannot animate success |
| `VR-LIVE-005` | Filesystem and storage projections share the canonical underlying storage observation source without duplicating one VFS event as two entities or traffic events |
| `VR-LIVE-006` | Snapshot-plus-subscription race, source restart, sequence gap, out-of-order delivery, duplicate observation, staged bake transition, buffer overflow, and reprojection recovery preserve deterministic state or fail visibly closed |

## View and visual gates

| Gate | Required proof |
| --- | --- |
| `VR-VIEW-001` | 1280 x 720 at DPR 1 has correct backing extent and stable composition |
| `VR-VIEW-002` | 1920 x 1080 at DPR 1 and 2 preserves normalized framing and hit targets |
| `VR-VIEW-003` | 2560 x 1440 at DPR 1 and 1.5 preserves skyline and glyph readability |
| `VR-VIEW-004` | 3440 x 1440 has no stretched projection, culling holes, or edge-only interactions |
| `VR-VIEW-005` | Portrait and landscape mobile sizes follow an explicit supported or unsupported contract |
| `VR-VIS-001` | Canonical station color, depth, normal, object-ID, emissive, and disclosure-boundary buffers match baselines |
| `VR-VIS-002` | Every quality tier preserves gameplay silhouettes and object IDs |
| `VR-VIS-003` | SecureMesh idle, discovered, authenticated, active, degraded, revoked, and departed states remain deterministic and distinct |
| `VR-VIS-004` | Bloom, fog, exposure, signs, landmarks, and glyphs meet legibility limits |
| `VR-VIS-005` | Four-sample MSAA and analytic glyph-edge smoothing preserve thin geometry, signs, Code Matter, depth, and object-ID agreement; any one-sample fallback passes its declared quality-tier baseline |

## View-mode and traversal gates

- Grounded first person is the only mode that moves a Traveler through collision, navigation, gates, bridges, Code Matter inspection, multiplayer, or replay.
- The only non-first-person mode is the explicit owner-private Local City Operations View; no orbit, freecam, avatar-follow, third-person Traveler, debug-camera, analytic graph, spectator, or remote-city route exists.
- The controller traverses floors, steps, slopes, doors, gates, bridges, and moving platforms.
- Head clearance and collision resolution prevent geometry penetration.
- Pointer lock enters, releases, and restores focus correctly.
- Every required interaction works with keyboard, mouse, and gamepad.
- Motion comfort mode removes forced movement and preserves task completion.

| Gate | Required proof |
| --- | --- |
| `VR-OPS-001` | Operations entry requires explicit local input, current authenticated owner identity, a record with only `localRealmId` and no foreign/viewed-Realm slot, current authority receipt, positive capability epoch, active private bake, spatial-layout receipt, and policy revision |
| `VR-OPS-002` | Isometric and eagle-eye pitch, altitude, zoom, heading, pan, focus, and loaded cells remain inside policy and local Cityform bounds; changing angle or LOD reveals no new authority or content |
| `VR-OPS-003` | Connected Cityform, PublicRealmShell, remote RealmPose, PresenceSession, RendezvousFrame, bridge, remote Traveler, remote route, destination, resource, object-ID, pick, accessibility, and telemetry records are absent before scene assembly |
| `VR-OPS-004` | Different authenticated, docked, moving, disconnected, and revoked connected-city populations produce byte-identical operator snapshots and minimaps for identical declared local inputs |
| `VR-OPS-005` | Every minimap zone, anchor, route endpoint, landmark, and cell resolves inside the accepted local private-bake lookup; foreign, dangling, duplicate, unsorted, excessive, or unloaded records fail closed |
| `VR-OPS-006` | Select and focus change presentation only. Visibility, alert-threshold, and rebake requests remain powerless until the generic proposal, authority receipt, authoritative observation, and delta chain completes |
| `VR-OPS-007` | Storylets, remote packets, station events, presence, rendezvous, bridges, picks, and minimap clicks cannot enter Operations View, widen its projection, grant authority, or claim a zone result |
| `VR-OPS-008` | Exit, authority revocation, owner change, expiry, policy replacement, bake activation, device loss, cancellation at every await, and double disposal release all operations resources once and restore the saved first-person anchor or collision-safe Root Spine fallback |
| `VR-OPS-009` | First-person visor minimap and full Operations View share one accepted local-only map projection and equivalent semantic/accessibility output; owner-private state never enters public shells, shared Chronicle, telemetry, crash reporting, network packets, or in-application capture |
| `VR-OPS-010` | The local SecureMesh Exchange may appear only as local geometry and a content-free boundary-state marker; no remote identity, shell, destination, route beyond the socket, or bridge geometry appears |

## Storylet gates

| Gate | Required proof |
| --- | --- |
| `VR-STORY-001` | Every factual cue references an authorized observation or explicit authored construct class |
| `VR-STORY-002` | Identical definitions, events, seeds, ticks, scope, and epoch produce identical instance IDs and semantic timelines |
| `VR-STORY-003` | Public Storylets pass private-data noninterference |
| `VR-STORY-004` | No Storylet can directly call files, processes, permissions, drivers, SecureMesh, or capability grants |
| `VR-STORY-005` | Operational Storylets wait for authoritative confirmation before success presentation |
| `VR-STORY-006` | Revocation, disconnect, unload, and epoch change cancel affected instances |
| `VR-STORY-007` | Replay disables every action port and performs zero live operations |
| `VR-STORY-008` | Shared clients agree on definition, recipe, participants, epoch, phase, and completion |
| `VR-STORY-009` | Historical, proposed, constructed, estimated, and live presentations remain distinct |
| `VR-STORY-010` | Hostile descriptors, hidden parameters, prompt-injection text, and invalid versions fail closed |
| `VR-STORY-011` | Duplicate IDs, ambiguous `(state, event)` transitions, stale expected revisions, invalid signatures, excessive payload depth, and incomplete dependency closure fail closed |
| `VR-STORY-012` | Scheduler tests cover canonical candidate ordering, priority, concurrency classes, cooldown ticks, deterministic ties, supersession, and bounded work |
| `VR-STORY-013` | Definition, episode state, persistence, trigger evaluation, scheduling, authority, presentation, Chronicle, and telemetry remain separate peers |
| `VR-STORY-014` | Every action-kind Storylet proposal adapts into the one generic `RealmActionProposalV1` path with the same idempotency key, consumes `RealmActionAuthorityReceiptV1`, and correlates exactly one reconciled authoritative result; replay cannot redispatch it |
| `VR-STORY-015` | Capability, presence-session, rendezvous, and bridge epoch changes invalidate every matching pending proposal, shared decision, reservation, pose dependency, and protected presentation before reuse |
| `VR-STORY-016` | Missing or mismatched definition hashes produce a stopped or explicitly migrated replay, never a present-day reroll |
| `VR-STORY-017` | Async failure cannot become semantic success from an earlier generic fired event |
| `VR-STORY-018` | Remote Storylet packages contain no function, script, module, worker, shader, WASM, URL, executable expression, private trigger, or hidden asset reference |
| `VR-STORY-019` | Shared clients derive the same `RealmStoryletInputSnapshotV1` digest from identical canonical facts, watermarks, logical ticks, hysteresis state, participants, policy, and active epochs; wall time, arrival order, locale, GPU values, and private facts cannot alter it |
| `VR-STORY-020` | Frozen logical-clock vectors reject tick regression, skipped or duplicated authority ticks, wrong clock epochs, wrong coordinator terms, and non-canonical hash links |
| `VR-STORY-021` | Frozen PCG-XSH-RR 64/32 vectors match exact unsigned 64-bit state evolution, little-endian seed derivation, XSH-RR output, draw counts, bounded rejection sampling, and semantic-real mapping on every supported client |
| `VR-STORY-022` | Candidate selection, tie-break, phase variation, and decorative randomness use domain-separated substreams; adding or removing draws in one purpose cannot shift another purpose's semantic output |
| `VR-STORY-023` | Coordinator lease expiry pauses or cancels at a safe boundary; mutually signed failover advances one term; partitions and conflicting decisions produce quarantine and split-brain evidence rather than unilateral progress |
| `VR-STORY-024` | Persisted outer instance heads restore pause, interruption, degradation, failed-pivot, repair, channel reservations, pending correlations, and cleanup obligations exactly; cancellation and crash recovery release every owned presentation and reservation through idempotent cleanup |

## Network and bridge gates

| Gate | Required proof |
| --- | --- |
| `VR-NET-001` | The V1 two-Cityform release scenario forms one expected authenticated remote peer and never duplicates either Traveler; a separate three-Cityform infrastructure robustness case verifies the existing mesh without adding group docking to V1 scope |
| `VR-NET-002` | A relay route never presents as direct |
| `VR-NET-003` | Latency, jitter, loss, and backpressure affect bounded presentation but not authority |
| `VR-NET-004` | Disconnect during bridge bake cannot activate a stale recipe |
| `VR-NET-005` | Reconnect requires new authentication, grant, and epoch |
| `VR-NET-006` | Directional grants remain independent |
| `VR-NET-007` | Hidden destinations cannot be enumerated before authority |
| `VR-NET-008` | Version or digest disagreement fails closed to station-only state |
| `VR-NET-009` | Revocation rejects protected traffic before protected presentation remains usable |
| `VR-NET-010` | Maximum-separation camera-relative rebase changes no semantic RealmPose, TravelerPose, collision result, navigation anchor, pick identity, audio relationship, Storylet state, Chronicle record, or bridge digest |
| `VR-NET-011` | A visitor cannot self-assert pose through host collision, navigation, gate, presence, or bridge boundaries; only host-authoritative `TravelerPoseV1` drives remote rendering, picking, and traversal |
| `VR-NET-012` | A DockingOffer cannot replay across identity, direction, gate, transcript, shell, PresenceSession, RendezvousFrame, protocol, compiler, nonce, expiry, or expected-previous-epoch changes and never claims a new active bridge epoch |
| `VR-NET-013` | Grant, recipe, both bridge digests, and BridgeEpoch activation agree on the offer digest, generation-nonce digest, active encounter epochs, directional grants, prospective bridge epoch, policy, and participants before protected traffic opens |
| `VR-NET-014` | Authentication, arrival, RendezvousFrame creation, docking, bridge activation, remote movement, revocation, and departure never inject a connected-Cityform or remote Traveler record into the Local Operations View or minimap |

## Performance gates

| Gate | Required proof |
| --- | --- |
| `VR-PERF-001` | Empty personal city meets approved CPU, GPU, memory, draw, and dispatch budgets |
| `VR-PERF-002` | Dense city and station traffic meet P50, P95, P99, and deadline-miss limits |
| `VR-PERF-003` | Repeated district streaming returns GPU bytes and resource counts to a plateau |
| `VR-PERF-004` | Glyph atlas, HLOD, particle, light, and audio budgets remain bounded |
| `VR-PERF-005` | Network fault simulation cannot create unbounded presentation work |
| `VR-PERF-006` | Storylet candidate and timeline work stays within its logical-tick budget |

## Recovery gates

| Gate | Required proof |
| --- | --- |
| `VR-RES-001` | Forced device loss pauses, rebuilds once, reloads the bake, and preserves camera and authority state |
| `VR-RES-002` | Device loss during arrival creates no duplicate Traveler |
| `VR-RES-003` | Device loss during docking creates no duplicate bridge or Storylet instance |
| `VR-RES-004` | Missing protected content returns to sealed state rather than fabricating it |
| `VR-RES-005` | Failed new bake activation leaves the prior verified bake active |

## Accessibility gates

| Gate | Required proof |
| --- | --- |
| `VR-A11Y-001` | Reduced motion suppresses decorative and forced movement while retaining function |
| `VR-A11Y-002` | High contrast and color-vision matrices preserve authority, danger, route, and Storylet meaning |
| `VR-A11Y-003` | Keyboard and gamepad can reach and cancel all required actions |
| `VR-A11Y-004` | The semantic mirror synchronizes nearby entities, routes, permissions, Storylets, prompts, and errors |
| `VR-A11Y-005` | Captions cover station announcements and semantic audio |
| `VR-A11Y-006` | Pointer-lock release restores predictable focus |

## Architecture gates

- Peer modules do not import concrete peers.
- Only application composition roots construct peers.
- No renderer imports a WebGPU OS driver.
- No OS adapter imports renderer code.
- No Storylet module imports a privileged concrete service.
- No production or release-fixture module imports, dynamically resolves, bundles, or copies a Playground demo, wrapper, shader, UI, camera, loader, or fallback.
- Engine and CSE capabilities enter only through composition-root-injected, version-checked adapters; no Realm peer reads an ambient global or probes a raw module path.
- State-First representation, historical witnesses, belief, similarity, and presentation remain outside authority and canonical-state ownership.
- Local operator contracts and peers are flat, owner-private, and independent of station, SecureMesh, public-shell, rendezvous, bridge, and Traveler peers; only `VirtualRealmEntry` may wire their accepted ports.
- Local Code Matter vault, nonce, tokenizer, line-stream, reveal-lease, and private-atlas peers remain separate; none imports SecureMesh, station, docking, bridge, or public-shell modules in V1.
- Bake dependency closure excludes bake receipts, signature envelopes, activation evidence, and every post-manifest validation or publication record.
- No RealmForge UI or mutable preview handle enters runtime modules.
- No god-object manager or nested runtime ownership tree appears.
- No Node.js or npm dependency exists.
- Only explicit exclusion assertions may name The First Shard; no source path, test, documentation content, scan result, design, mechanic, or dependency from it appears.

## Release evidence

The release candidate stores:

- Bake and dependency receipts.
- Privacy and secret-sentinel reports.
- Canonical final-frame and buffer baselines.
- CPU and GPU timing distributions.
- Resource and memory plateaus.
- Network and revocation traces.
- Device recovery traces.
- Storylet deterministic-replay evidence.
- Accessibility results.
- Import-boundary and exclusion reports.

## See also

- [Contract catalog](contracts.md)
- [Implementation roadmap](implementation-roadmap.md)
- [Security and privacy](security-privacy.md)
- [Rendering and experience](rendering-experience.md)
- [Storylets](storylets.md)
- [Playground clean-room foundations](playground-clean-room-foundations.md)
