---
title: Virtual Realm M2 Runtime Foundation
description: Dependency-ordered implementation blueprint for the first shipping Virtual Realm runtime, static bake loading, ECS materialization, first-person traversal, local Operations View, lifecycle, and recovery.
audience: runtime developers, Engine integrators, security reviewers, RealmForge authors, and QA engineers
updated: 2026-09-19
status: M2A, the admission-only M2B slice, non-visible M2C, CPU-only M2D-A, M2D-B0, M2D-B1, the isolated dependency-injected M2D-B2 static GPU presentation foundation, the M2D-B3 trusted production-composition substrate, and the exact provider-free M2D-B4A through M2D-B4F authority wire contracts and M2D-B4G terminal legacy compatibility accepted; M2D-B4H genuine-source construction is underway with protected per-Realm policy and per-account current-local-Realm/authority-epoch head sources implemented and verified; B4H, lifecycle authority, completed operator-context, activation, checkpoint, handoff, action, and local-policy authority, full authority-provider registration, a physical WebGPU visible-city frame, M2E-M2H, and integrated M2 remain unaccepted
---

# Virtual Realm M2 Runtime Foundation

M2 turns the accepted contracts and RealmForge bake artifacts into the first
shipping Virtual Realm runtime. It proves one local static Cityform, grounded
first-person traversal, the owner-private Local City Operations View, complete
lifecycle cleanup, and device recovery before any live scan, exact Code Matter
reveal, Storylet runtime, public shell, or multiplayer peer is admitted.

M2 is split into eight milestone slices, with M2D divided into independently
accepted M2D-A and M2D-B subgates. No slice or subgate may claim the whole
milestone before the integrated M2H gate passes.

Current piece-9 integration includes the opt-in
[B3 pre-epoch lifecycle installer](#b3-pre-epoch-lifecycle-installation).
Its genuine-source import grew B3 from48 to88 at that historical gate. The
[cycle-free pre-bind association](#cycle-free-pre-bind-gpu-allocation-association)
prepares genuine cohorts before epoch binding. Its B396/core60/wrapper97 and
Entry106 counts are historical slice receipts. The later protected-startup
closure is80 for the reviewed authority component, B3111, wrapper112 and Entry152.
The subsequent [standard adapter cohort allocation routing](#standard-adapter-cohort-allocation-routing)
connects opted-in buffer/texture creation to that original cohort. Adapter64
and owner-controller65 were its historical closures. The subsequent
[private presenter terminal cleanup](#private-presenter-terminal-cleanup-and-retry-ownership)
replaces protected presenter ordinary-job destruction and retains failed cleanup.
The [stable presentation-port allocation association](#stable-presentation-port-allocation-association)
now resolves the selected cohort from an exact original stable-port/epoch pair,
including after retirement. Presenter-specific binding remains separate.
The [original presenter-generation provenance](#original-presenter-generation-provenance)
prerequisite supplies exact local-generation, original-port and adopted-receipt
evidence. The later protected-startup slice adds pre-diagnostic reservation;
neither prerequisite alone accepts the full provider or a visible city.

The first three slices, the CPU-only M2D-A subgate, the M2D-B0 renderer
profile, M2D-B1 draw-packet compilation, the isolated M2D-B2 static GPU
presentation foundation, the M2D-B3 trusted production-composition substrate,
the M2D-B4A exact operator-context wire, the M2D-B4B exact runtime-activation
wire, the M2D-B4C exact runtime-checkpoint wire, the M2D-B4D exact runtime-
handoff wire, the M2D-B4E exact action-authority wire, the M2D-B4F exact
local-operator-policy wire, and the M2D-B4G terminal legacy compatibility
boundary are independently accepted.
M2D-B4H is underway and unaccepted. Two genuine protected sources now own the
per-Realm monotonic local-policy head and the per-account current-local-Realm
selection/authority-epoch head. Both reuse one kernel-only transaction helper;
neither supplies an application port or registers the full provider.
M2C consumes the first two
through an off-active candidate path. M2D-A consumes M2C without activating a
surface or GPU. M2D-B0 admits the complete renderer policy without allocating
it. M2D-B1 compiles exact CPU packets. M2D-B2 proves the dependency-injected GPU
boundary under focused mock and kernel gates. M2D-B3 proves the trusted
registry, owner-coupled GPU epoch, exact dependency-v2 assembly, and Desktop
lease transport. M2D-B4A freezes the provider-independent operator-context
wire. M2D-B4B freezes the provider-independent activation, eligibility,
offer/commit/abort, and active-bundle teardown grammar. M2D-B4C freezes the
provider-independent checkpoint read/prepare/commit/abort/retire grammar,
profile-derived read cap, sanitized projection, and exact nested binding.
M2D-B4D freezes read/write/clear, exact handoff/checkpoint cross-binding, CAS
outcomes, and tombstone lineage. M2D-B4E freezes exact owner-local action
submit/observe context, proposal/receipt/result snapshots, correlation, and
closed failure vocabularies. M2D-B4F freezes exact owner-local policy
read/subscribe context, head binding, safe snapshots, and data-only
invalidation. These wire gates do not implement their services,
register the full genuine authority provider, or prove a physical WebGPU frame:

- [M2A runtime composition](m2a-runtime-composition.md) freezes the app/service
  composition roots, exact dependency ports, lifecycle, capped exact handoff,
  profile ID/digest/object binding, 13-module runtime-contract graph, and entry gates.
- [M2B private-bake admission](m2b-private-bake-admission.md) freezes the
  71-field admission index, chunked resource/evidence/signature inventories,
  protected exact-byte store, exact evidence/signature provisioning and
  verification, Realm-scoped trust, fixed pending/terminal/control bundles,
  head CAS, restart, migration, rollback, and gated collection protocol.

## Current implementation boundary

B4H's current bounded prerequisites now include protected policy/selection
heads, generation/session allocation, private process-owner identity, v3 host
lifecycle transport, participant notification, lifecycle-port composition,
operator-switch cleanup ownership, native diagnostic clock/logger sources,
exact-producer frame accounting, private exact-mount buffer/texture/creation
accounting, separate original-surface reservation accounting and retained
original-owner teardown authentication. A private guarded-frame bridge now
preserves the original producer behind the existing syscall wrapper.
The surface adapter also verifies the historical pairing of its original scalar
receipt and the actual returned kernel view, without returning either object.
These sources are individually verified but are not installed as the full
runtime provider. Genuine telemetry, activation-authorized children, recovery
reconciliation, authenticated acquisition/backend isolation, and the remaining
authority owners still require the ten-piece B4H continuation. The diagnostic
clock is not an activation clock. A real M1C-to-first-submitted-frame route and
the separate visible-city gate remain unaccepted.
(Sources: `webgpu-os/kernel/realm/RealmLifecyclePortComposition.js`;
`webgpu-os/shell/desktop/RealmOperatorMountDrain.js`;
`webgpu-os/kernel/realm/RealmRuntimeDiagnosticsSource.js`;
`webgpu-os/kernel/GpuFrameCoordinator.js`;
`webgpu-os/kernel/GpuDeviceBroker.js`; `webgpu-os/kernel/VRAMTracker.js`;
`webgpu-os/kernel/SurfaceManager.js`;
`webgpu-os/kernel/Syscalls.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`;
`webgpu-os/kernel/realm/RealmProcessOwnerIdentityAuthority.js`;
`webgpu-os/kernel/realm/RealmLifecycleAllocationAuthority.js`.)

The current production application contains the accepted flat contract catalog,
side-effect-free `VirtualRealmEntry`, M2A lifecycle/composition peers, and the
separate opt-in M2 runtime-contract catalog. The trusted RealmForge-to-kernel
path contains the accepted M2B provisioning, protected publication, durable
admission, and restart reconstruction slice. The non-visible M2C implementation
now adds independent runtime verification, candidate eligibility, an immutable
CPU static store, exact ECS materialization, dense presentation slots, and one
isolated disabled/off-active State-First source. Verification uses closed
recursive schemas for every admitted payload kind, exact topology/resource
universe equality, and a bounded one-pass anchor index. Candidate World creation
consumes one exact eligibility preparation and is pinned to the active-bake CSE
binding observed during Engine inspection. `stageStaticCandidate()` is an
additive entry operation; `start()` remains the accepted admission-only M2A/M2B
path and does not silently stage or expose a city. Explicit
`planStaticScene()` now adds accepted M2D-A CPU planning. It authenticates the
static store, verifies its canonical snapshot, retains the transitive render
resource closure, assigns deterministic positive object IDs, and produces an
immutable plan plus digest-bound receipt. The receipt fixes surface, frame,
GPU, visibility, and interaction counts at zero. M2D-B0 now adds one pinned,
canonically admitted renderer profile. The profile freezes the fixed
first-person camera convention, pass and attachment topology, four geometry
defaults, total material resolution, identity/disclosure encoding, bounded
metre-space lights, metadata-only LOD, deterministic segment-frame policy,
double/f32 geometry envelopes, device requirements, and conservative resource
ceilings. Its receipt also fixes surface, frame, GPU, visibility, and interaction
counts at zero. (Sources:
`webgpu-os/apps/the-virtual-realm/VirtualRealmEntry.js`;
`webgpu-os/apps/the-virtual-realm/security/RealmRuntimePackageVerifier.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmStaticBakeLoader.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmStaticStore.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmEcsSynchronizer.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmEngineAdapter.js`;
`webgpu-os/apps/the-virtual-realm/projection/RealmStateFirstSource.js`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmSceneAssembler.js`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticRenderPlanContract.js`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticRendererProfileContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime-contracts/VirtualRealmM2RuntimeContractCatalog.js`;
`webgpu-os/kernel/realm/RealmM2PrivateBakeAdmissionComposition.js`;
`webgpu-os/apps/realmforge/virtual-realm/RealmForgeBakeEntry.js`.)

These accepted code slices are not yet a fully provided or physically visible
M2 runtime. The bounded M2D-B2 foundation provides kernel capability admission,
an owner-bound nine-operation broker, a syscall adapter, one persistent-canvas
surface, bounded transfer/job/frame callbacks, static GPU resource ownership,
geometry/identity/ACES passes, first-frame visibility, device-loss concealment,
and ordered teardown. The accepted M2D-B3 substrate adds the kernel-owned
`AppRuntimeCompositionRegistry`, the exact `RealmM2RuntimeComposition`
dependency-v2 assembler, the owner-coupled GPU epoch port, and guarded `Desktop`
lease transport. `Desktop` passes a closure only when the exact Virtual Realm
app/part opener returns a valid lease; app cleanup completes before lease close,
and late, aborted, or invalid opens retire without mounting or falling back.
M2D-B4A additionally freezes the exact six-field `operatorContext@1` snapshot,
requests, non-disclosing invalidation event, subscription, and disposal receipt.
M2D-B4B additionally freezes the exact six-method `realmRuntimeActivation@1`
wire and its `realmActiveBundleTeardown@1` result capability without invoking
either one. M2D-B4C additionally freezes the exact five-method
`realmRuntimeCheckpoint@1` wire, including closed read and operation results,
without performing a checkpoint call during startup. M2D-B4D freezes the exact
three-method `realmRuntimeHandoff@1` read/write/clear wire while the existing
adapter remains read-only. M2D-B4E freezes the exact two-method
`realmActionAuthority@1` submit/observe wire and performs neither call during
startup. M2D-B4F freezes the exact two-method `localOperatorPolicy@1`
read/subscribe wire and likewise performs neither call during startup.
No full genuine authority provider is registered yet, so an ordinary launch
still truthfully mounts the recoverable unavailable view and allocates no Realm
GPU resource. No physical WebGPU frame has passed an acceptance gate. A genuine
protected local-policy source and current-selection/authority-epoch source now
exist, but no complete `localOperatorPolicy@1` owner exists. The next adapter
must combine Kernel account/generation, protected selection/authority epoch,
and the selected Realm's policy epoch. Lifecycle authority, policy observation
and subscription invalidation, operator-context adaptation, activation,
checkpoint, handoff, action, and provider registration remain unimplemented or
unintegrated. The
first-person controller, Operations View, minimap, and visible bundle swap also
remain unimplemented. Integrated M2 is therefore unaccepted. M2 does not
replace or extend the accepted M0-M1C package
formats. (Sources: `webgpu-os/apps/the-virtual-realm/factory.js`;
`webgpu-os/apps/the-virtual-realm/VirtualRealmEntry.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmCandidateEligibilityContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeActivationPortContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeCheckpointPortContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeCheckpointAdapter.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeHandoffPortContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeHandoffAdapter.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmActionAuthorityPortContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmLocalOperatorPolicyPortContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeDependencyContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationPortContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuPresenter.js`;
`webgpu-os/kernel/GpuPresentationCapabilityAdmission.js`;
`webgpu-os/kernel/AppRuntimeCompositionRegistry.js`;
`webgpu-os/kernel/OperatorPrivateServiceStorageView.js`;
`webgpu-os/kernel/realm/RealmLocalOperatorPolicyHeadStorage.js`;
`webgpu-os/kernel/realm/RealmOwnerCoupledGpuPresentationPort.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`webgpu-os/shell/Desktop.js`.)

## Accepted M1C prerequisite

Full base M2 starts from the exact owner-private M1C version-2 package returned
by `verifyPrivateBake()`. It does not start from a manifest alone. The package
contains the reviewed station, safe text, inert Storylet catalog, exact
resource envelopes, policies, closures, receipts, and cross-bindings required
to prove that the static city is the accepted M1 output. A legacy version-1
package may be inspected by diagnostics, but it cannot satisfy the integrated
M2 gate. (Sources:
`webgpu-os/apps/realmforge/virtual-realm/RealmForgeBakeEntry.js`;
`webgpu-os/apps/realmforge/virtual-realm/publication/RealmBakePackageVerifier.js`.)

The current private publisher does not persist that complete package. It stores
resource record text, the dependency closure, and the manifest, then selects
the manifest's `bakeId`. It omits the remaining package records and external
evidence needed for restart verification. M2 must therefore add an
owner-partitioned admission capsule and index. Existing manifest-only roots
need one explicit recompile, reverify, and admission migration before runtime
selection. (Source:
`webgpu-os/apps/realmforge/virtual-realm/publication/RealmBakePublisher.js`.)

M2 keeps three heads separate:

| Head | Owner | Meaning |
| --- | --- | --- |
| M1 private publication root | RealmForge publication service | Which immutable `bakeId` the authoring flow selected |
| M2 durable admission head | Trusted WebGPU OS admission service | Which complete owner-partitioned package graph the durable storage transition selected; current load and activation verification independently decide eligibility, and a committed-ineligible selection is legal |
| M2 in-memory active bundle | Virtual Realm runtime activation barrier | Which fully staged static store, ECS world, GPU resources, and local view binding are currently visible |

No receipt or pointer implies either of the other transitions.

## Locked M2 product

M2 contains exactly:

- one side-effect-free Virtual Realm application entry;
- one verified owner-private static bake;
- one dedicated Engine scene;
- one ECS materialization of admitted static resources;
- one State-First presentation source;
- grounded first-person traversal and interaction focus;
- one explicit owner-private local Operations View and local minimap;
- read-only inspection and powerless local management proposals;
- deterministic startup, shutdown, device recovery, and rollback;
- sanitized performance, accessibility, and lifecycle evidence.

M2 excludes live filesystem/process/network observations, source reveal,
Storylet scheduling, remote public shells, presence, Travelers, rendezvous,
docking, bridges, dynamic topology, automatic mutation, and live Genesis
Ecology. An optional M2-GE track may load verified static Genesis facilities,
identity bindings, and reserved sockets; it cannot project a live phenotype or
claim ecological activity.

## Source-of-truth planes

| Plane | M2 owner | M2 contents | Cannot do |
| --- | --- | --- | --- |
| Authored truth | Verified RealmForge bake | Static geometry, collision, navigation, anchors, LOD, lighting, audio, local lookup | Observe live OS state |
| Semantic truth | WebGPU OS authority plus publication and admission heads | Active operator, capabilities, durable bake admission, view authority | Render directly |
| Runtime materialization | Engine ECS | Static render/collision/navigation entities and local presentation metadata | Become persistent identity or authority |
| Presentation | State-First renderer and experience peers | Draw, cull, LOD, pick, camera, audio, semantic mirror | Change topology, disclosure, or capabilities |
| Management proposal | Local Operations adapter | Bounded local action proposal | Apply the action or claim success |

The ECS entity handle is a local runtime slot. Stable resource, object, Realm,
bake, anchor, and zone IDs come from verified records.

## Separate M2 contract catalog

The frozen 109-contract M0-M1C catalog remains unchanged. M2 introduces an
opt-in `VirtualRealmM2RuntimeContractCatalog` for runtime evidence records:

| Contract | Responsibility |
| --- | --- |
| `RealmRuntimeCapabilityProfileV1` | Exact Engine, renderer, controller, numeric, feature, 65,536-byte handoff, admission-package, inventory, graph-byte, fixed pending/terminal, trust, root-directory, and recovery limits accepted by this runtime |
| `RealmRuntimeSessionV1` | Local Realm, operator, lifecycle generation, publication root, admission head, visible bundle, policy, and session state |
| `RealmPrivateBakeAdmissionIndexV1` | Owner partition, publication root, exact v2 package artifact, resource envelopes, policies, receipts, Storylet/station evidence, signatures, verifier identity, and self-digest required for durable rehydration |
| `RealmStaticBakeLoadReceiptV1` | Package verification, dependency resolution, limits, staged resources, and selected root |
| `RealmStaticStoreSnapshotV1` | Immutable admitted static resource indexes and generations |
| `RealmEcsMaterializationReceiptV1` | Static object-to-ECS and presentation-slot mapping plus counts and digest |
| `RealmViewTransitionReceiptV1` | Explicit first-person to Operations View transition and safe restoration evidence |
| `RealmDeviceRecoveryReceiptV1` | Lost and replacement device generations, rebuilt resources, restored source, and resumed state |
| `RealmRuntimeDisposalReceiptV1` | Abort, detach, resource release, pointer-lock release, listener removal, and final zero-owner evidence |
| `RealmArtifactStoreActivationReceiptV1` | Immutable capsule/index write/readback, durable admission-head compare-and-swap, owner partition, and crash-recovery evidence |
| `RealmRuntimeHandoffRecordV1` | Exact digest-bound operator/Realm heads, monotonic record/root-manager lineage, profile, service-injected owner/lifecycle/bundle plus required verified checkpoint binding, safe anchor, local policy/cursor, and the sole caller-authored Operations request; its active handoff root retains the complete protected checkpoint graph edge, clear writes a tombstone and never resets generation, and no live handle is serialized |

These records contain no private source, capability tokens, native handles, GPU
objects, mutable stores, or callable functions.

The target is exactly 11 complete definitions in the table order. They live in
a separate 13-module `runtime-contracts/` graph: one primitive module, the 11
definition modules, and one catalog module. The catalog reuses
`VirtualRealmContractRegistry`, never creates a parallel registry, never
exports a combined 120-definition catalog, and never registers a placeholder.

## Composition root

`VirtualRealmEntry` is the only M2 application construction boundary. The
separate trusted Realm service composition root is owned and built by WebGPU OS
before it injects narrow ports. `VirtualRealmEntry` receives an exact dependency
object; it does not read globals, probe paths, import RealmForge UI, or construct
WebGPU OS services.

```text
VirtualRealmEntry.create({
  dependencyVersion,
  engineAdapterFactory,
  surfaceFramePort,
  gpuPresentationPort,
  resourceTelemetryPort,
  lifecyclePort,
  processOwnerPort,
  runtimeHandoffPort,
  runtimeCheckpointPort,
  bakeAdmissionPort,
  runtimeActivationPort,
  operatorContextPort,
  actionAuthorityPort,
  localOperatorPolicyPort,
  clock,
  logger
})
```

This is the exact frozen 16-key dependency-version-2 object, including
`dependencyVersion`; missing,
extra, inherited, accessor, symbol, or wrong-version fields fail before any
acquisition.

`RealmPrivatePublicationHeadPort@1`, the exact-byte content port, evidence/key resolvers, the
M1C package verifier, the admission-head writer, and migration authority are
composed inside the trusted WebGPU OS Realm service. They do not cross the app
boundary separately. `bakeAdmissionPort` exposes only head status and loading
of the current, fully rehydrated, independently verified private package.

The factory constructs the exact `RealmEngineAdapter`; no raw GPU host or kernel
service object crosses the application boundary. Dependency version 2 preserves
the legacy two-method `surfaceFramePort` for compatibility and adds the
non-overlapping nine-method `gpuPresentationPort`. The new port owns B2
capability receipts, bounded transfer/job work, the single persistent-canvas
surface, coordinated frame production, device lifecycle, and terminal receipt
retirement. `RealmGpuPresentationSyscallAdapter` retains raw device, queue,
context, and syscall objects and returns only an immutable caller-bound broker.
`resourceTelemetryPort` exposes bounded owner-attributed measurements rather
than GPU internals. `lifecyclePort` and `processOwnerPort` bind operator switch,
application close, and cleanup before presentation starts. (Sources:
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeDependencyContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`.)

M2D-B3 implements the trusted transport without widening that application
contract. `AppRuntimeCompositionRegistry` is a kernel-owned, exact,
single-assignment registry for only `os.the-virtual-realm` and
`app.the-virtual-realm`. Requests, leases, and injected dependencies are
reconstructed from own data descriptors only; accessors, inherited fields,
symbols, and later prototype mutation cannot redirect them. Kernel shutdown
drains every returned lease, and a failed concurrent destroy clears its
in-flight marker so the same tracked cleanup remains retryable. `Desktop`
opens that composition with only the mount fence and app-scoped GPU syscalls,
injects the validated dependency object into the existing factory path, and
omits the dependency property when no lease is available. Entry/factory cleanup
runs before the lease closes. A late or aborted open closes without mounting;
malformed lease cleanup is quarantined and retried rather than forgotten.
Non-Virtual-Realm applications cannot receive or invoke this composition.

`RealmM2RuntimeComposition` requires the exact app ID, verified runtime profile,
active-bake CSE binding digest, app-scoped GPU syscalls, and genuine supplied
authority ports. It constructs the real Engine adapter factory with the same
`runtimeActivationPort` used for candidate preparation and consumption, builds
the exact frozen 16-key dependency-version-2 record, and validates that record
before returning the exact `{ dependencies, close }` lease. The owner-coupled
GPU wrapper binds one GPU epoch to the acquired process-owner identity and
generation, requires a distinct owner for each newer lifecycle epoch, rejects
overlap or active-epoch identity drift, and fences release until pending GPU and
child operations plus active receipts reach zero. GPU epoch authority retires
before the source owner; partial release remains retryable. Lease close rejects
an active owner so only the Entry's canonical teardown may release it. GPU
syscall methods are captured once into a private frozen facade. Source-owner
operations are likewise captured before untrusted prototype mutation can
redirect them. A rejected owner acquisition preserves its GPU-first cleanup
phase so composition close can retry it. Raw syscalls, GPU objects, and the
source process-owner port remain private to the trusted composition.

This substrate and B4A through B4G install no genuine authority provider.
Operator context, activation, checkpoint, handoff, action, and local-policy
transactions have exact provider-free request/result contracts. B4G closes the
legacy surface/frame slot with a reviewed terminal singleton. B4H is underway.
Its two bounded sources close protected local-policy and current-selection/
authority-epoch storage. The B4A/B4F adapters, remaining genuine owners, and
acquisition and cleanup composition must satisfy the accepted boundaries before
the full provider may register an opener.

The adapter validates the exact State-First version, source kind, representation
set, dirty flags, rasterizer mode, and required methods before any externally
visible registration. The accepted surface is frozen in
[Playground clean-room foundations](playground-clean-room-foundations.md#exact-production-adapter-seams).

M4 adds a kernel-owned `publicShellExchangePort` only when public presence is
enabled. The M2 application receives no generic mesh-send or raw peer-message
capability.

## Required WebGPU OS foundation work

The contracts are ahead of the executable OS integration. M2 must close these
gaps before scene work is considered production-ready:

| Gap | M2 resolution |
| --- | --- |
| Application discovery and trusted closure transport accepted; no genuine full authority provider | Keep the schema-admissible manifest and side-effect-free entry; freeze the missing authority wires, implement their real owners, then register one exact Virtual Realm opener through the accepted dependency-version-2 lease path |
| Protected policy and current-selection/authority-epoch heads exist; no complete B4A/B4F owner | Reuse both sources through one adapter bound to Kernel account/generation and the selected Realm's policy epoch; reject missing/cleared selection as unavailable without a sentinel, then provide lifecycle reassertion and bounded invalidation before provider registration |
| No production M1 publisher store | Add a versioned ABA-resistant private-publication head and one kernel-only operator/service storage root outside app-writable `/user`; expose only narrow publication observation and admission capabilities |
| Existing content reads are unbounded | Extend `RealmContentStore` additively with bounded cancellable raw exact-byte put/get; M2B cannot adapt legacy full-read/base64 `getBlob()` |
| Generic version/backup restore can bypass head CAS | Exclude the protected service subtree from generic app mutation, trash, versioning, backup, and restore; only the admission service may advance its structured head |
| Published private root cannot rehydrate M1C v2 | Store the complete canonical package, chunked resource/evidence/signature inventories, and a self-digested `RealmPrivateBakeAdmissionIndexV1`; require explicit migration for manifest-only roots |
| M1, admission policy, or signature trust can advance during final selection | Route every mutable authority writer and M2 final selection through `RealmAdmissionSelectionCoordinator`; admit only the versioned M1 observation variant |
| Collector can race immutable staging or later pins | Share one operator/service maintenance fence among admission, durable-root producers, and collection; only verified pending-slot readback makes its addressed intent/proposal graph a root |
| Admission policy was only a digest label | Add the exact internal policy codec/port and assert its revision/digest before initial CAS, recovery retry, and restart load |
| No physically accepted Realm frame | The bounded B2 substrate supports exactly one producer and one persistent application surface, and B3 transports its owner-coupled composition; register the genuine full provider and prove a physical non-black frame with zero validation errors |
| Partial Realm resource ownership | B2 generation-fences static GPU objects, the surface, producer, subscription, and receipt; later gates add cells, broader ECS mappings, audio, atlases, listeners, workers, and activation staging |
| No Realm stable-runtime handoff | Transfer only serializable roots, generations, safe anchors, cursor identity, a service-verified checkpoint binding with retained graph edge, and policy references |
| Local and remote package trust conflated | Use the accepted local compiler-admission verifier in M2; add a distinct transported-shell verifier in M4 |
| Package-verifier ownership is ambiguous | The trusted service behind `bakeAdmissionPort` performs exact M1C package, evidence, and signature verification; `RealmRuntimePackageVerifier` separately enforces M2 capability, local-only, allocation, and materialization policy |
| No Operations workspace | Add one owner-private Plauna read model populated only from the closed local snapshot |
| Weak cache hashes available in unrelated systems | Use the canonical strong content identities from Realm contracts for bakes and recipes, never a 32-bit cache key |

App discovery, kernel boot, operator activation, package selection, Engine
startup, and frame registration form one generation-fenced dependency chain.
An operator switch tears down the old owner before any resource for the new
owner becomes visible.

## Planned module graph

The paths are namespaces, not nested ownership:

```text
webgpu-os/apps/the-virtual-realm/
  manifest.json
  factory.js
  index.js
  VirtualRealmEntry.js
  runtime-contracts/RealmM2RuntimeContractPrimitives.js
  runtime-contracts/RealmRuntimeCapabilityProfileContract.js
  runtime-contracts/RealmRuntimeSessionContract.js
  runtime-contracts/RealmPrivateBakeAdmissionIndexContract.js
  runtime-contracts/RealmStaticBakeLoadReceiptContract.js
  runtime-contracts/RealmStaticStoreSnapshotContract.js
  runtime-contracts/RealmEcsMaterializationReceiptContract.js
  runtime-contracts/RealmViewTransitionReceiptContract.js
  runtime-contracts/RealmDeviceRecoveryReceiptContract.js
  runtime-contracts/RealmRuntimeDisposalReceiptContract.js
  runtime-contracts/RealmArtifactStoreActivationReceiptContract.js
  runtime-contracts/RealmRuntimeHandoffRecordContract.js
  runtime-contracts/VirtualRealmM2RuntimeContractCatalog.js
  runtime/RealmRuntimeLifecycle.js
  runtime/RealmOsLifecycleAdapter.js
  runtime/RealmProcessOwner.js
  runtime/RealmRuntimeHandoffAdapter.js
  runtime/RealmRuntimeCheckpointPortContract.js
  runtime/RealmRuntimeCheckpointAdapter.js
  runtime/RealmGpuPresentationPortContract.js
  runtime/RealmGpuPresentationSyscallAdapter.js
  runtime/RealmCandidateEligibilityContract.js
  runtime/RealmM2StaticRuntimePrimitives.js
  runtime/RealmEngineAdapterContract.js
  runtime/RealmEngineAdapter.js
  runtime/RealmStaticEcsComponents.js
  runtime/RealmStaticBakeLoader.js
  runtime/RealmStaticStore.js
  runtime/RealmDynamicStore.js
  runtime/RealmEcsSynchronizer.js
  runtime/RealmInteractionResolver.js
  runtime/RealmActionDispatcher.js
  runtime/RealmResourceLedger.js
  projection/RealmStateFirstSource.js
  projection/RealmStateFirstPresentationAdapter.js
  rendering/RealmStaticRenderPlanContract.js
  rendering/RealmSceneAssembler.js
  rendering/RealmStaticPrimitiveTemplate.js
  rendering/RealmStaticDrawPacketProjection.js
  rendering/RealmStaticDrawPacketContract.js
  rendering/RealmStaticDrawPacketCompiler.js
  rendering/RealmStaticGpuUploadCompiler.js
  rendering/RealmStaticGpuResourceOwner.js
  rendering/RealmStaticGeometryShader.js
  rendering/RealmStaticIdentityShader.js
  rendering/RealmStaticAcesPresentationShader.js
  rendering/RealmStaticGpuPresenter.js
  rendering/RealmStaticRenderer.js
  rendering/RealmObjectIdPass.js
  rendering/RealmLightingPresenter.js
  experience/RealmFirstPersonController.js
  experience/LocalOperatorPolicyStore.js
  experience/LocalOperatorViewProjector.js
  experience/LocalOperatorCameraController.js
  experience/LocalCityMinimapProjector.js
  experience/LocalZoneSelectionStore.js
  experience/LocalZoneManagementActionAdapter.js
  experience/RealmSpatialAudioPresenter.js
  experience/RealmSemanticMirror.js
  security/RealmRuntimePackageVerifier.js
  security/RealmLifecycleGenerationGuard.js
  security/RealmLocalOnlyClosureVerifier.js
  telemetry/RealmRuntimeMeasurements.js
  telemetry/RealmRuntimeEvidenceBuilder.js

webgpu-os/kernel/
  GpuPresentationCapabilityAdmission.js
  OperatorPrivateServiceStorageView.js
  realm/RealmAdmissionPackageIndexCodec.js
  realm/RealmAdmissionOperationControlCodec.js
  realm/RealmAdmissionPolicyCodec.js
  realm/RealmSignatureTrustPolicyCodec.js
  realm/RealmAdmissionEvidenceBindingCodec.js
  realm/RealmAdmissionRootControlCodec.js
  realm/RealmAdmissionRootDirectoryCodec.js
  realm/RealmAdmissionArtifactDirectoryCodec.js
  realm/RealmAdmissionEvidenceDirectoryCodec.js
  realm/RealmAdmissionGarbageCollectionCodec.js
  realm/RealmPrivateBakeActivationCodec.js
  realm/RealmAdmissionSelectionCoordinator.js
  realm/RealmAdmissionPolicyStorageAdapter.js
  realm/RealmSignatureTrustPolicyStorageAdapter.js
  realm/RealmRuntimeCapabilityProfileRegistry.js
  realm/RealmPrivatePublicationHeadStorageAdapter.js
  realm/RealmPrivateBakeAdmissionService.js
  realm/RealmPrivateBakeActivationGuard.js
  realm/RealmRuntimeActivationService.js
  realm/RealmAdmissionEvidenceResolver.js
  realm/RealmAdmissionEvidenceProvisioningService.js
  realm/RealmAdmissionArtifactDirectoryService.js
  realm/RealmAdmissionArtifactDirectoryMutationArbiter.js
  realm/RealmAdmissionEvidenceBindingDirectoryService.js
  realm/RealmAdmissionRootLeaseService.js
  realm/RealmTrustedActivationClockStorageAdapter.js
  realm/RealmRuntimePinManager.js
  realm/RealmRuntimeCheckpointSourceService.js
  realm/RealmRuntimeCheckpointManager.js
  realm/RealmRuntimeHandoffOutcomeObserver.js
  realm/RealmRuntimeHandoffManager.js
  realm/RealmM1PackageAdmissionAdapter.js

webgpu-os/apps/realmforge/virtual-realm/publication/
  RealmSignatureClosureVerifier.js
  RealmM2PrivateBakeAdmissionClient.js
```

No module in this list constructs another concrete peer. Each owning composition
root passes immutable values and narrow ports between its peers; the app entry
never constructs a kernel/service peer.
`RealmRuntimeActivationService` is the one flat owner of the operator/Realm
visible pointer plus bounded per-process-owner candidate/current/disposal state
and prebound `runtimeActivationPort@1` views; it
receives only narrow guard, runtime-pin, process-owner-child,
active-bake-CSE, pointer/gate, work-status, operator-generation-observation, and
lifecycle-retirement-observation plus cross-session handoff-binding ports. The guard validates eligibility, the pin
manager owns durable lineage, the guard alone receives the clock face, and no
peer duplicates activation state.

## Startup transaction

Startup is one cancellable generation-fenced transaction:

1. Validate the complete exact-key dependency graph, every narrow port,
   version, method, and limit with zero acquisition.
2. Call side-effect-free `engineAdapterFactory.inspect()` and validate the
   frozen `RealmRuntimeCapabilityProfileV1` plus the canonical active-bake CSE
   binding receipt digest without constructing an adapter.
3. Capture current operator identity, local Realm, capability epochs, policy,
   and operator generation.
4. Allocate one new durable lifecycle generation plus its exact retirement
   handle, one local work abort root, and one separate teardown abort root.
   Session work never receives the teardown signal.
5. Acquire one process owner under that generation.
6. Register one lifecycle participant under the owner, then start only
   owner-attributed telemetry.
7. Through `bakeAdmissionPort`, supply the inspected runtime-profile ID/digest,
   read the current discriminated admission status, and capture
   M1 publication root, M2 durable admission head, and both head generations.
   Missing, migration-required, or unavailable status stops before all later
   runtime allocation.
8. For accepted status only, read the typed bounded runtime handoff, reduce it
   through the closed precedence, and retain only its sanitized observation;
   never restore a live handle.
9. Through `bakeAdmissionPort.loadVerifiedPrivateBake()`, resolve the
   owner-partitioned admission index and require a complete private
   version-2 package artifact. Manifest-only publication was already handled by
   `readHead()` as migration-required; a head or authority change during load
   returns the exact unavailable reason and performs no runtime allocation.
10. The trusted service loads and size-checks package, resource envelopes,
   records, and required external evidence under the index ceilings, then
   recomputes all M1C, Storylet, station, policy, receipt, signature, closure,
   audience, and current-trust bindings before returning the frozen result.
11. Run `RealmRuntimePackageVerifier` over that frozen result to enforce
   current Engine compatibility, local-only closure, and allocation policy.
12. Call `runtimeActivationPort.prepareCandidateEligibility()` to repeat the
    bounded dependency, evidence, reviewer, signature-lifetime, current-trust,
    head, policy, and runtime-profile closure before any candidate
    materialization. Retain only its opaque request ID; the proof remains inside
    the trusted activation service.
13. Construct and verify `RealmStaticStore` indexes with Storylet records retained
   in an inert store and with no GPU or ECS exposure.
14. Create the Engine adapter with the inspected profile ID and CSE binding,
    validate the returned adapter brand/version/methods/profile/binding, then
    consume the exact eligibility preparation once with its bundle, Realm,
    lifecycle, admission, package-blob, and RealmForge-digest bindings before
    materializing a candidate ECS world and dense presentation-slot mapping.
    Before later activation work, require
    the exact current CSE V2 active-bake predecessor: canonical inactive genesis
    at entity/pointer generation zero for first activation, or the exact current
    active record for replacement. Each candidate captures but does not consume
    that predecessor until its prepared step-8 swap.
15. Build GPU resources and scene passes through the single-surface frame port
   under the staging resource ledger.
16. Register one State-First source only in the candidate adapter's isolated,
   off-active channel and retain its detach handle. Registration cannot affect
   the prior visible bundle or supply presentation decisions until the active
   pointer selects the candidate.
17. Construct the first-person controller disabled at the verified
   collision-safe Root Spine anchor. It acquires no pointer lock, listener,
   interaction dispatch, or input authority while off-active. Complete CSE V2
   commit steps 1 through 7 for the active-bake transition, producing the opaque
   prepared handle, exact safe prepared-commit receipt/digest, separate expected
   swap-receipt digest, and output-record digest without changing the CSE
   pointer; external-effect intents and the prepared outbox are exactly empty.
   Call `runtimeActivationPort.offerCandidate()` with the opaque
   preparation ID, exact non-serializable candidate/gate handles, and exact
   prepared-CSE handle/safe receipt/commit digest, separate expected swap-receipt digest, and
   exact staged active-bake output-record digest; the activation service preallocates and registers
   its staged single-bundle teardown child.
18. Inside that offer operation, the activation service uses its narrow pin port
    and fixed journal to prepare and activate one Realm-scoped durable
    `runtime-pin` for the exact candidate admission graph, then one-time binds
    that manager operation/root to the staged teardown child. The exact `offered`
    result is returned only after active-pin and binding readback; the app never
    receives manager/root authority.
19. Call `runtimeActivationPort.commitCandidate()`: retain the same admission
    selection fence and one closed frame barrier while the activation guard
    reasserts the prepared proof, current heads/policies/trust/profile/graph, and
    trusted-clock signature lifetime. Under that same fence, reassert and bind
    the exact CSE active-bake predecessor, recomputed safe prepared-commit
    receipt/digest, expected swap
    receipt, and next `CausalStateActiveBakeRecordV2`; all writers
    of that entity must use the same coordinator and only CSE step 8 may remain.
    With candidate source/input still gated, create the exact
    visible-commit authorization receipt and CAS/readback the runtime-pin manager
    to `visible-committed`. Only exact proposal readback may enter one synchronous,
    allocation-free, nonthrowing block whose first phase synchronously rechecks
    the retained work root, `committing` state, operator generation, lifecycle,
    and process owner, then makes the immediate trusted-time safety check against
    that physical manager SHA. Either denial changes no visibility state and
    retires the authorized candidate pin. Success closes
    and reads back old-bundle gates, invokes only the conflict-impossible
    `activeBakeCsePort.commitPreparedSwap(preparedCommitHandle)` step, verifies
    its returned preallocated swap receipt and active-bake output digest against
    the authorized expectations, fills the live-visibility and optional
    supersession receipts, swaps the internal active pointer, transfers the new teardown
    child to active ownership and any superseded old child to disposal ownership,
    then opens the selected State-First source, prevalidated controller/input
    face, and frame barrier before releasing the fence. Durable manager I/O
    occurs while the old pointer remains current and all candidate gates remain
    closed.

An impossible returned swap-receipt mismatch leaves both old and candidate
gates closed, keeps the runtime pointer/ownership unchanged, and enters explicit
CSE-integrity quarantine with its exact bounded receipt and no ordinary-abort
claim. Restart must reconcile the authoritative CSE active-bake record before
any Realm presentation. Durable authorization alone never fabricates live visibility.

A failure before step 19 disposes staging in reverse order and follows the exact
pin journal state. `planned` first resumes exact preparation; `prepared` with
durable nonpublication proof moves through `abandoning`/`abandoned` cleanup;
committed manager publication is first
adopted and activated, then retired/released; any unresolved observation keeps
the journal and blocks collection. Both durable heads remain independently
available. A failure after the external gates open enters the same controlled
shutdown path as an operator close. If manager CAS proves the exact predecessor,
no CSE/pointer mutation occurs and the candidate retires. A third or uncertain
manager value keeps the barrier/input/source closed and enters recovery; no
candidate frame or interaction is exposed.

## Stable checkpoint and handoff transaction

Checkpoint, handoff, and runtime-pin roots are independent protected graph roots;
none is inferred from another. A requested cross-session handoff completes this
transaction before ordinary shutdown begins:

1. While the old active bundle and its runtime pin remain current, freeze one
   bounded static checkpoint draft containing only accepted heads/profile,
   bundle ID, safe anchor, logical cursor, and local policy identity. The draft
   is a request: the trusted checkpoint manager accepts it only when the flat
   checkpoint-source service independently reproduces the exact current bundle,
   pointer/live-visibility receipt, heads/profile, anchor/cursor, and policy.
2. Call `runtimeCheckpointPort.prepareCheckpoint({ localRealmId,
   checkpointDraft, expectedHeadBinding, signal })`. The trusted checkpoint
   manager allocates the checkpoint ID, generation, manager operation, and root
   reference; preissues the hidden handoff-authorization correlation, prepares
   the exact kind-payload graph root; and returns the closed `prepared`
   variant carrying only its opaque `checkpointPreparationId` correlation. The
   frozen root binds the exact checkpoint-source projection digest.
3. Call `runtimeCheckpointPort.commitCheckpoint({ checkpointPreparationId,
   signal })`. The manager first acquires the checkpoint-source service's narrow
   activation-selection lease and freezes its source authorization; the lease
   holds exact current state through checkpoint-head CAS and normal active-root
   readiness. Proceed only on the exact `committed` result: the manager
   CAS/readbacks the checkpoint head, activates its unchanged root through the fixed
   owner-manager journal, and returns the sanitized exact checkpoint binding
   plus a process-local `checkpointHandoffAuthorizationId` only after root
   readiness is proven. Exact predecessor instead completes prepared-root
   abandonment and returns `not-committed` plus its cleanup receipt; it is never
   confused with an older `record` or `missing` observation. Unavailable or
   invalid aborts the handoff attempt. A changed source projection also returns
   `not-committed` after exact abandonment and never publishes fictional state.
4. Pass exact `recordDraft = { operationsViewRequested }` and the required
   authorization separately to `runtimeHandoffPort.write()`. The caller cannot
   author any head/profile/owner/lifecycle/bundle/anchor/cursor/policy field, a
   checkpoint ID, or binding. Through its one-purpose checkpoint-binding verifier, the trusted
   handoff manager injects those fields from the exact safe binding, retains its protected
   checkpoint graph edge in the prepared handoff root, allocates its operation/
   root identities, CAS/readbacks the next monotonic handoff record, activates
   its root, and only then permits `read()` to expose the record.
5. Keep the old runtime pin active until both new roots are proven active. A
   predecessor/proposal uncertainty, third value, invalid journal, or unresolved
   root aborts handoff without claiming a resumable record.
6. The new session first accepts the current admission graph, then validates the
   handoff's exact checkpoint binding plus retained checkpoint graph edge through
   the handoff manager's narrow verifier. It restores
   only serializable safe state and stages a wholly new candidate off-active.
7. Activate the new session's runtime pin, complete the retained-selection-fence
   visible commit, and prove the new bundle current before clearing anything.
8. The new session writes/readbacks the next handoff tombstone, retires/releases
   the handoff root, and completes its journal. Checkpoint retention or retirement
   follows explicit owner policy and cannot be implied by handoff clear. Ordinary
   checkpoint/handoff replacement releases an old root only through the exact
   successor-active retirement receipt; it never writes a tombstone over the
   new head.
9. The old session then retires its own lifecycle, closes its own
   `handoff-displaced-retained` handle through the pointer-preserving branch,
   and keeps that owner/lifecycle's displaced-retained runtime pin owned through
   the post-frame GPU fence and exact child disposal. Only then may that old
   session pin become retired/released and its fixed manager slot be cleaned. It
   never becomes a same-generation replacement/disposal entry owned by the new
   session.

A normal no-handoff close may optionally commit a policy-authorized checkpoint,
but never fabricates a handoff. At every boundary, at least one verified active
root protects any graph needed for restart; no manager releases a root because
an in-memory owner merely disappeared.

## Shutdown transaction

Shutdown ordering is security-significant:

If handoff was requested, the stable transaction above must already have
committed both roots or failed closed before step 1. Shutdown itself never
half-publishes a handoff.

1. Abort the construction-attempt signal if startup is still pending.
2. Abort the lifecycle work root, then retire that exact durable generation with
   its retirement handle through the still-live teardown signal. A later start
   allocates a strictly greater generation; no generation is advanced in place
   or reused.
3. Abort noncommitted activation/checkpoint requests through their
   exact teardown-only calls and the still-live teardown signal. Snapshot only
   this process owner's in-memory child ledger, never a protected-storage list,
   and freeze the current bundle, any handoff-displaced-retained predecessor-
   owner bundle, plus every superseded disposal bundle in
   descending `(visiblePointerGeneration, runtimeBundleId)` order. If commit
   produced a current active-bundle teardown handle, invoke its one idempotent
   `close()` through the still-live teardown root after lifecycle retirement;
   require the applicable exact removed-pointer or preserved-successor plus
   input/interaction/State-First/controller/frame-gate readback and
   retain the close-receipt digest. Every superseded entry must already carry its
   exact gate-close/supersession receipt.
4. Close new interactions and local action dispatch.
5. Exit Operations View if active and preserve only the CPU safe-anchor record.
6. Release pointer lock and restore predictable DOM focus.
7. Detach the State-First source and subscriptions exactly once.
8. Stop audio and presentation peers.
9. For every frozen current/displaced/disposal bundle in the ledger order, await its exact
   post-frame GPU fence or the certified device-loss completion, then destroy
   only that bundle's GPU resources, presentation slots, ECS materialization,
   CSE staging owner, and remaining children in reverse construction order.
   Unregister its terminal teardown child only after all those disposals read
   back complete.
10. Dispose static stores and remaining Realm-session ports.
11. For every ledger entry, and only after that entry's fence, resources, and
    terminal child are complete, retire its exact runtime-pin manager record,
    release its exact Realm-scoped durable root, and finish its fixed manager
    journal. Reconcile every current/disposal pin owned by this process before
    owner release or collection; no singular “current pin” shortcut and no
    storage enumeration are legal. Previously committed checkpoint/handoff roots
    remain governed by their own managers and policy.
12. Close telemetry and retain only its sanitized terminal receipt.
13. Dispose the lifecycle participant exactly once.
14. Release the process owner only after its child count reaches zero.
15. Abort the teardown root last and publish one immutable stopped receipt
    showing no remaining Realm owner.

Shutdown never deletes the immutable bake or source `.proasset` document.

## M2A: entry, contracts, and fail-closed compatibility

The normative work package is
[M2A runtime composition](m2a-runtime-composition.md). This summary cannot
widen its exact ports, ordering, catalog, or acceptance ledger.

### Build

- Add the application manifest, side-effect-free `index.js`, and
  `VirtualRealmEntry.js`.
- Add the separate M2 runtime contract catalog and exact-key validators.
- Add lifecycle participation, process ownership, a durable monotonic
  operator/app generation plus retirement handle, separate work/teardown abort
  ownership, and typed bounded handoff observations.
- Implement the exact side-effect-free Engine-factory inspection contract and
  complete closed capability profile: Engine/adapter/numeric versions, feature
  and method arrays, every M2 limit, and its self-digest. Adapter creation and
  validation begin only in M2C before materialization.
- Add a dependency manifest that rejects ambient globals, raw kernel/GPU
  managers, generic networking, and missing ports.

### Gate

- Importing `index.js` performs no boot, GPU, storage, network, listener, or DOM
  work.
- Application discovery declares one singleton surface intent. M2A startup
  acquires exactly one process owner and lifecycle participant but no surface or
  frame producer; those resources begin only in the rendering slice.
- Every missing, extra, incompatible, or future dependency version fails before
  resource acquisition.
- No module imports a concrete peer or RealmForge runtime implementation.
- Production and release fixtures contain no Playground import or copied
  presentation expression.
- Start, failed start, stop, double stop, and restart produce exact lifecycle
  state, retire through the non-session teardown signal, never reuse a durable
  generation, and allow no late mutation.

### Rollback

Remove the opt-in application entry. M0-M1C contracts and bakes remain usable.

## M2B: static package verification and stores

The normative admission work package is
[M2B private-bake admission](m2b-private-bake-admission.md). It precedes static
store construction: M2B returns a verified package and selected admission
identity, while the off-active static store belongs to the next loader slice.

### Build

- Implement `RealmPrivateBakeAdmissionIndexV1`, its exact-key codec, and a
  content-addressed canonical artifact for the complete 17-key private-v2 package.
- Store resource, authoring-evidence, and signature bindings in deterministic
  bounded inventory roots/chunks so the 71-field index remains within contract
  preflight ceilings.
- Add the kernel-only operator/service storage root, bounded raw exact-byte
  content methods, versioned M1 publication observation, structured M2 head,
  service-generated operation identity, 64 fixed pending and terminal-audit
  slots, fixed proposal plus durable intent/dispatch/recovery-retry/result
  records, prior/current terminal lineage, exact conditional reclamation,
  separate head compare-and-swap, and bounded crash recovery with no historical
  scan.
- Add `RealmAdmissionSelectionCoordinator`, the separate operator/service
  maintenance fence, the exact current admission-policy codec/port and writer,
  one five-role Realm-scoped Ed25519 key/revocation policy, immutable complete
  runtime-profile and evidence-policy registries, authenticated four-kind
  evidence provisioning/resolution, the closed six-row signature table, final
  activation guard, and future Realm-scoped durable-root plus
  root/artifact/evidence-directory boundary. Neither fence may claim
  external-process exclusion, and admission never acquires selection while
  retaining maintenance.
- Store canonical payload bytes by strong content ID. Stable semantic resource
  IDs remain index keys and never become immutable byte-address keys.
- Persist the resource envelopes, policies, receipts, station evidence, exact
  Storylet-authoring evidence, and the four-or-five referenced signature
  envelopes needed to reconstruct and independently verify after restart.
- Add an explicit migration path that accepts a freshly recompiled and verified
  package for a legacy manifest-only root. The runtime never fabricates missing
  records from the manifest.
- Compose the trusted M1C package, evidence, and signature verifier behind the
  app's read-only `bakeAdmissionPort`. Keep `RealmRuntimePackageVerifier` as the
  separate M2 runtime compatibility and local-only verifier.
- Resolve dependency closure inside the trusted service through its exact-byte
  content port under byte/count/depth ceilings.
- Return the exact frozen package and index to the next slice; build resource,
  object, anchor, cell, zone, route, collision, navigation, LOD, lighting,
  audio, local-operations, safe-text, and inert-Storylet indexes only after M2B
  acceptance.
- Verify every cross-record reference and local-only closure.
- Produce an artifact-store activation receipt for durable head selection. The
  static-load receipt is produced later by the off-active loader.

### Gate

- Full M2 accepts only the exact owner-private version-2 package. Unknown keys,
  duplicate IDs, dangling references, digest mismatch, excessive depth,
  unsupported compiler identity, missing evidence, invalid signature, and
  missing content fail closed.
- A valid M1C package above the bound base runtime profile returns
  `runtime-profile-too-large` with zero admission writes; M2 does not pretend
  the current 16 MiB canonical codec can admit the authored 512 MiB ceiling.
- A process restart rehydrates the exact 17-key package from the admission
  graph only after current M1 scope/root/generation/storage SHA and admission
  policy match the selected index; it then reproduces byte-identical canonical
  package bytes, exact payload blob ID, independent RealmForge semantic hash,
  and verified record digests.
- A `bakeId` with no matching admission index is not runtime-selectable.
- Bake receipts and publication evidence cannot become runtime content.
- Storylet definitions, templates, cues, candidate index, subclosure, and
  catalog verify and remain inert; no M2 peer can schedule or dispatch them.
- The local lookup resolves only the current private Realm.
- A failed candidate leaves the prior active store and bake root untouched.
- Unreachable staged immutable content never becomes active.
- Owner-private bake roots, public publication roots, caches, and active-root
  pointers occupy separate partitions and cannot cross operator contexts.
- A failure before dispatch preserves the prior authority; an interrupted CAS
  can leave only the exact predecessor or proposal and must reconcile before any
  success or eligibility claim.
- Publication-root CAS, admission-head CAS, and runtime-bundle activation are
  independently observable and cannot substitute for one another. Visibility
  changes only after the activation guard reasserts current heads,
  admission/evidence/trust/signature closure, trusted-clock envelope lifetime,
  and exact runtime profile under the same retained selection fence as the
  bundle swap.
- A cooperating M1 writer cannot advance from the final observation through M2
  head readback, and a collector cannot delete in-flight immutable bytes before
  verified fixed pending-slot readback roots the addressed intent/proposal graph.
- Future collection remains disabled until bounded artifact and evidence-binding
  directories, manager/registration journals, deterministic cursor batches,
  fixed candidate/progress controls, and exact quarantine/delete observations
  are implemented and their historical backfill is certified.

### Rollback

Keep the package and admission verifiers as diagnostic tools while disabling
runtime selection. Directly reselect a prior immutable index only when its exact
M1 head, current policy/trust, and registered runtime profile still match;
otherwise publish a new versioned M1 selection and build a new M2 index. Never
rewrite an old index or delete immutable evidence during rollback.

## M2C: ECS and State-First materialization

The app/Engine implementation for this slice is accepted. It deliberately stops
before a renderer, surface, controller, or visible activation. The implemented
transaction is:

1. `RealmStaticBakeLoader.prepare()` consumes the exact frozen six-field M2B
   accepted result: status, admission index, verified package, sanitized
   verification summary, publication-head binding, and admission-head binding.
2. `RealmRuntimePackageVerifier.verifyLoadedBake()` independently reconstructs
   and verifies the exact owner-private M1C version-2 package, current runtime
   profile, local-only closure, canonical records and envelopes, topology,
   Storylet closure, both selected heads, and every allocation ceiling. Twelve
   recursive payload schemas are closed at every nested record, the topology
   arrays and resource universe must agree in both directions, cyclic values are
   rejected, and derived-reference work shares the profile's canonical-node cap.
3. `runtimeActivationPort.prepareCandidateEligibility()` must return its opaque
   preparation ID before `RealmStaticStore`, an Engine adapter, an ECS world, an
   entity, or a presentation slot can be allocated. Denial and cancellation
   therefore have zero runtime allocation.
4. `RealmStaticStore.create()` retains all 48 immutable verified resource rows,
   including six inert Storylet rows. Its contract snapshot indexes the 36 rows
   with canonical Realm content IDs; the other verified rows remain available
   through the bounded internal store and are not discarded. The accepted
   reference graph is 522,488 bytes.
5. `RealmEngineAdapter.createCandidateWorld()` consumes that preparation exactly
   once through `runtimeActivationPort`, bound to candidate bundle, Realm,
   lifecycle generation, admission index, package blob, and RealmForge digest.
   It then requires the factory's creation receipt to repeat the exact active-bake
   CSE binding digest returned by inspection. A mismatch, replay, cancellation,
   or fabricated preparation allocates no World.
6. `RealmEcsSynchronizer.materialize()` constructs exactly 19 static topology
   objects, every topology node and topology edge once, with the authored
   `nodeId` or `edgeId` as stable identity. It creates one local positive-safe
   ECS handle and one separate dense presentation slot plus generation for each.
7. `RealmEngineAdapter.materializeStaticBake()` installs exactly `Transform`,
   `Renderable`, `RealmBounds`, `RealmCollisionBinding`,
   `RealmNavigationBinding`, `RealmInteractionIdentity`, and
   `RealmStaticMetadata`. Presentation bounds are finite world-space AABBs
   derived from local bounds and the complete transform; stable identity never
   becomes an ECS handle or slot.
8. `RealmStateFirstPresentationAdapter` registers one immutable source only in
   the candidate adapter's disabled, off-active channel. Representation
   decisions update its private presentation-only map and cannot mutate ECS
   semantics, topology, collision, navigation, disclosure, or authority.

Candidate disposal closes presentation decisions, detaches the State-First
source, destroys ECS rows and releases dense slots, disposes the candidate
world, then releases the CPU store. If detach or resource release fails, the
adapter retains exact ownership, reports `cleanup-pending` with a truthful
nonzero ledger, and permits an idempotent cleanup retry; it never claims disposal
or forgets a still-owned entity or slot. Every adapter method reserved for M2D and later throws a typed policy
denial before allocation. (Sources:
`webgpu-os/apps/the-virtual-realm/runtime/RealmStaticBakeLoader.js`;
`webgpu-os/apps/the-virtual-realm/security/RealmRuntimePackageVerifier.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmStaticStore.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmEcsSynchronizer.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmEngineAdapter.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmStaticEcsComponents.js`;
`webgpu-os/apps/the-virtual-realm/projection/RealmStateFirstSource.js`;
`webgpu-os/apps/the-virtual-realm/projection/RealmStateFirstPresentationAdapter.js`;
`engine/ecs/world/World.js`;
`engine/ecs/storage/ArchetypeStorage.js`;
`engine/render/state/StateFirstPresentationSlots.js`.)

### Build

- Create a dedicated Realm ECS world through injected Engine APIs.
- Map stable static object IDs to runtime entity handles and separate dense
  presentation slots.
- Add only the fixed components required for transform, renderable, bounds,
  collision, navigation binding, interaction identity, and static metadata.
- Register one immutable State-First source over bounded snapshots.
- Apply representation decisions only to presentation metadata.

### Gate

- Every admitted static object maps exactly once and every ECS entity maps back
  to one stable object ID.
- Runtime entity destruction removes storage rows and presentation slots.
- State-First decisions cannot create, remove, reparent, authorize, disclose,
  collide, navigate, or semantically mutate an object.
- Eligibility is consumed exactly once before World allocation, every binding
  field is exact, and adapter creation cannot substitute a different CSE digest.
- Source snapshots are bounded, deterministic, and stable across input order.
- Detach occurs before ECS or GPU resource destruction.

### Current acceptance evidence

- `m2-static-bake-loader`: 24/24 browser cases, zero skips.
- `m2-engine-foundations`: 11/11 browser cases, zero skips.
- `m2-ecs-handle-compatibility`: 28/28 browser cases, zero skips.
- Existing M0 Engine foundations: 6/6 browser cases, zero skips.
- Isolated verifier, Engine-adapter, and current Entry module closures: 51, 27, and 106 modules,
  respectively, with zero skipped modules.
- `m2-ecs-materialization`: 24/24 browser cases, zero skips.
- `test_m2_static_materialization_vectors.py`: 8/8 independent Python vectors.
- M2 runtime/static/import Python proof group: 16/16 cases.

Together these results prove the loader, verifier/store boundary, exact ECS
materialization, positive-safe handles, destruction hooks, falsy component
preservation, dense slot generation, closed payloads, one-time eligibility,
CSE binding identity, retryable ownership cleanup, independent canonical vectors, and the
non-visible cleanup boundary. The non-visible M2C app/Engine slice is accepted.
No M2C result claims production activation, rendering, interaction, or
integrated M2 acceptance.

### Rollback

Dispose the ECS projection while retaining the verified CPU static store.

## M2D-A: deterministic static render planning

The CPU-only M2D-A subgate is accepted. It converts one authentic M2C static
store and its exact off-active State-First snapshot into deterministic input
for a future renderer. It does not create a surface, frame producer, command
encoder, GPU resource, camera, controller, or visible output.

### Implemented transaction

1. `VirtualRealmEntry.planStaticScene()` explicitly stages M2C when needed and
   shares one in-flight planning operation across concurrent callers. Ordinary
   `start()` remains admission-only, and `stageStaticCandidate()` remains
   non-rendering M2C work.
2. `RealmSceneAssembler` accepts exactly six frozen inputs: candidate World ID,
   lifecycle generation, capability profile, authentic `RealmStaticStore`, ECS
   snapshot, and abort signal.
3. Captured `RealmStaticStore` prototype methods enforce the factory-token and
   private-field brand. The assembler recomputes the store snapshot digest,
   cross-checks stats and indexes, repeats bounded reads, and requires exact
   `readResource()` row identity.
4. Seven admitted render-resource kinds seed a deterministic transitive
   dependency traversal. Every retained dependency resolves, payload/content
   ID domains remain distinct, and cycles fail closed.
5. Geometry covers admitted node cells, Root Spine segments, station boxes, and
   relationship routes. Boxes have positive physical sizes; route polylines
   have at least two points; grid geometry remains integral; and coordinate
   spaces match geometry kinds.
6. Object IDs are dense positive plan-local integers. Stable object IDs,
   zero-based presentation slots, and positive slot generations remain separate
   identities. Object semantics and geometry form exact bijections.
7. Material roles, lighting, authored and compiled LOD, projection-role
   bindings, and style-only glyph intent retain exact resource evidence. Glyph
   styles contain no readable code or source content; a style role must resolve
   directly or through one unambiguous projection mapping.
8. The plan and receipt recompute canonical self-digests through
   `admitRealmStaticRenderPlan()` and
   `admitRealmStaticRenderPlanReceipt()`. Final lifecycle fences run before the
   assembler retains or publishes the result.

### Fixed non-claims

The accepted receipt has `executionClass: "cpu-plan-only"`,
`activationState: "off-active"`, `surfaceCount: 0`,
`frameProducerCount: 0`, `gpuResourceCount: 0`, `visible: false`, and
`interactive: false`. Render requirements name color, depth, normal, object-ID,
emissive, and disclosure-boundary attachments plus forward PBR, four-sample
MSAA, bounded shadows, HDR, tonemapping, restrained bloom, distance fog, and
State-First culling. Those are future execution requirements, not claims that
the resources already exist.

### Acceptance evidence

- `tests/virtual-realm/m2-static-render-plan.test.html` with
  `tests/virtual-realm/m2-static-render-plan.test.js`: 30/30 browser cases,
  zero skips.
- `tests/virtual-realm/test_m2d_renderer_import_confinement.py`: 5/5 Python
  cases.
- M2D-A plan/assembler closure: exactly 18 modules, zero errors, zero cycles, and no
  surface, GPU, frame producer, RealmForge runtime, Playground, or physics
  authority.
- `tests/virtual-realm/test_m2b_app_import_confinement.py`: the current Entry
  closure is exactly 106 modules with zero errors and zero cycles.
- `tests/virtual-realm/test_virtual_realm_manifest.py`: 2/2 Python cases; the
  manifest uses the admitted `games` / `Games` classification.
- `tests/virtual-realm/virtual-realm-manifest-registry.test.html`: 20/20 browser
  cases prove isolated registration through the real `AppRegistry` without
  evaluating the application entry.
- `tests/virtual-realm/m2-factory-integration.test.html`: 11/11 browser cases
  prove the exact lazy factory loader and migration path, truthful missing
  composition state, idempotent cleanup, strict malformed-injection denial,
  Entry authority confinement, the injected test composition, first-frame-only
  reveal, device-loss concealment, stable canvas identity, and the terminal
  no-constructor-fallback policy.
- `tests/virtual-realm/m2-desktop-terminal-factory.test.html`: 2/2 browser cases
  execute the real `Desktop._launchPanel()` factory branch. They prove that the
  ordinary no-injection launch returns the recoverable unavailable view instead
  of throwing `VR_M2A_RECORD_REQUIRED`, and they cover teardown, sandbox
  closure, and owner release.

### Rollback

Dispose the retained CPU plan synchronously and idempotently. Then retain or
dispose the independently accepted M2C candidate according to the caller's
lifecycle operation.

## M2D-B: dedicated static renderer

### M2D-B0: renderer-profile admission

M2D-B0 is accepted. `RealmStaticRendererProfileContract.js` defines one pinned
`static-high-v1` profile and a separately digest-bound zero-allocation receipt.
Admission recomputes both canonical identities and rejects any different profile,
even when the substituted profile carries a self-consistent digest.

The accepted profile closes the translation policy needed before draw packets
or GPU objects exist:

- The Engine camera looks down local `-Z`; the fixed quaternion `[0, 1, 0, 0]`
  makes declared world `+Z` the first-person forward direction.
- `geometry-msaa` owns four-sample color, emissive, normal, and depth. The
  single-sample identity pass rerenders admitted geometry with its own depth so
  object ID and disclosure values remain occlusion-correct.
- Every geometry record resolves through one authored semantic-role material or
  one exact geometry-kind default. Ambiguous and missing bindings fail closed.
- Light positions remain metres. Shape defaults and ranges are bounded. Lumens
  remain separate because reviewed photometric evaluation belongs to M2D-B2.
- LOD compilation is membership-only. M2D-B0 admits thresholds and member
  relations but grants no level-selection, visibility, or culling authority.
- Geometry conversion checks the double-precision envelope, effective sizes,
  segment separation, and post-`float32` collapse before later buffer packing.
- Attachment, pass-expanded draw, material, light, LOD, canonical payload,
  device-limit, buffer, texture, and aggregate GPU ceilings are explicit.

M2D-B0 acceptance evidence is 39/39 browser cases, 5/5 Python confinement
proofs, an exact 12-module import closure with zero errors or cycles, and an
independent audit with no findings. (Sources:
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticRendererProfileContract.js`;
`tests/virtual-realm/m2-static-renderer-profile.test.js`;
`tests/virtual-realm/test_m2db_renderer_profile_import_confinement.py`.)

### M2D-B1: deterministic CPU draw-packet compilation

M2D-B1 is accepted. `RealmStaticDrawPacketCompiler` explicitly consumes the
admitted M2D-A plan and exact M2D-B0 reference profile, then retains one
immutable, canonical-digest-bound CPU plan and a separately bound receipt.
`VirtualRealmEntry.compileStaticDrawPackets()` composes the phase only after
`planStaticScene()` succeeds; repeated calls share one operation, stop fences
in-flight work, and reverse cleanup disposes packets before their source plan,
ECS candidate, and store. Ordinary `start()` remains admission-only.

The accepted translation is exact rather than renderer-shaped metadata:

- Every `cell-box`, `station-box`, `root-spine-segment`, and expanded polyline
  segment uses the Engine's one 24-vertex, 36-index unit-cube template.
- Packet order follows admitted geometry order and polyline segment order.
  Models, true inverse-transpose normal matrices, and positive `uint32` object
  identities are packed into exact 128-byte instance records.
- AABBs and bounding spheres enumerate all eight corners of the actual
  float32 model, then round only outward to the adjacent representable float
  when nearest rounding would exclude a corner.
- Authored semantic-role materials take precedence over exact geometry-kind
  defaults. IEC 61966-2-1 conversion is proven for all 256 channel bytes, and
  source hex, linear values, and emissive intensity remain separate.
- Exact 64-byte material, 96-byte light, 32-byte LOD-header, 4-byte threshold,
  16-byte LOD-relation, and 4-byte pass-reference layouts are byte-accounted.
  LOD remains membership-only and lumens remain unevaluated.
- Generation fencing, cancellation, idempotent disposal, immutable snapshots,
  bounded diagnostics, canonical budgets, dependency digests, and forged-plan
  rejection are enforced before any allocation boundary.

The receipt fixes canvas contexts, surfaces, frame producers, command encoders,
GPU resources, visibility decisions, LOD selection, culling, and interaction at
zero/off-active. Acceptance evidence is 36/36 browser cases, 9/9 Python proofs,
an exact 18-module CPU import closure with zero errors or cycles, integrated
Entry evidence inside the unchanged 24-case M2C suite, and two independent
audit passes with no remaining P0, P1, or P2 findings. (Sources:
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticPrimitiveTemplate.js`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticDrawPacketProjection.js`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticDrawPacketContract.js`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticDrawPacketCompiler.js`;
`tests/virtual-realm/m2-static-draw-packet.test.js`;
`tests/virtual-realm/test_m2db_draw_packet_compiler.py`.)

### M2D-B2: GPU presentation

The isolated, dependency-injected M2D-B2 static GPU presentation foundation is
accepted. The production-composed and physical WebGPU visible-city gate remains
unaccepted. Dependency version 2 additively preserves the two-method
`surfaceFramePort` and introduces one non-overlapping
`realmGpuPresentation@1` port. The new port admits exact device capabilities,
schedules bounded allocation/upload work, owns a persistent-canvas surface and
frame producer, observes device generations, and retires capability evidence.

The trusted port exposes only these receipt-bound operations:

```text
requestCapabilityReceipt(request)
getDeviceFacade(receipt)
scheduleTransfer(receipt, options, callback)
scheduleJob(receipt, options, callback)
acquireSurface(receipt, container, options)
releaseSurface(receipt, surface)
registerFrameProducer(receipt, options)
subscribeDeviceLifecycle(receipt, listeners)
retireCapabilityReceipt(receipt)
```

The implemented request binds the B0 profile identity, required feature names, limits,
format capabilities, `bgra8unorm`, `bgra8unorm-srgb`, and opaque alpha. A trusted
kernel adapter issues the receipt only after owner- and device-generation-bound
evidence succeeds. Bucketed public device limits are insufficient for the exact
format/sample matrix, so kernel-owned transient validation probes must test the
required multisample, resolve, integer attachment, and view-format behavior and
destroy every probe on every outcome. A private issuance record, not digest
equality alone, makes the receipt authoritative. Terminal retirement is
idempotent only for the exact WeakMap-known receipt, owner ID, and owner-authority
identity, including after device-loss revocation; forged, cloned, never-issued,
cross-owner, and foreign-authority records remain rejected. (Source:
`webgpu-os/kernel/GpuPresentationCapabilityAdmission.js`.)

The implemented bounded B2 presenter renders all admitted B1 packets. It uses no LOD or
State-First selection and reports `cullingAuthority: "none-off-active"`,
`renderedPacketPolicy: "all-admitted-packets"`, `controllerAuthority: "none"`,
and `interactive: false`. Its three stages are the four-sample geometry pass,
the single-sample depth-correct identity pass, and one fullscreen ACES
presentation pass. The adapter creates the swapchain attachment with the
admitted `bgra8unorm-srgb` view format and caps one-shot jobs at the kernel's
256-operation ceiling. This core slice does not claim PBR light evaluation,
shadows, fog, bloom, readable Code Matter, picking, movement, or interaction.

The application keeps `surface: "window"`. Its factory creates one persistent
render host and a sibling status overlay. The canvas stays hidden while the
presenter is only ready, appears after the first submitted frame, and hides on
loss, failure, or stop without changing identity. Status updates never call
`replaceChildren()` on the render host. The manifest and panel request only
`gpu.surface`; queue writes and submissions remain confined to
broker-authorized transfer/job/frame callbacks.

### Implemented bounded foundation

- `RealmGpuPresentationPortContract` exposes exactly nine receipt-bound
  operations through one immutable owner/app binding.
- `RealmGpuPresentationSyscallAdapter` retains raw kernel objects, enforces one
  persistent canvas, and creates one current texture and sRGB view per frame.
- `RealmStaticGpuUploadCompiler` uploads the exact four B1 buffers. The resource
  owner releases buffers, textures, surface, producer, subscription, and receipt
  in deterministic order.
- `RealmStaticGpuPresenter` executes four-sample geometry, single-sample
  depth-correct identity, and fullscreen ACES presentation for all five admitted
  packets. It has no controller, culling, LOD-selection, or interaction
  authority.
- Device loss revokes surface/device authority before notifying the app,
  conceals the canvas, preserves cleanup failures, and permits a clean newer-
  generation admission.

Focused acceptance evidence is 60/60 GPU-port browser cases and 5/5 Python
proofs; 18/18 syscall-adapter browser cases and 4/4 Python proofs; 27/27 static
presenter cases; 24/24 Entry integration cases; 11/11 factory cases; 24/24
kernel capability-admission cases; 19/19 runtime-recovery cases; 13/13 frame-
coordinator cases; and 13/13 application-surface lifecycle browser cases. The
current Entry, port, and adapter import closures contain exactly 106, 13, and 14 modules.
All focused browser gates report zero skips. Independent final audit found no
remaining P0, P1, or P2 implementation defect in this bounded surface.

### Remaining production build

- Continue B4H by adapting the protected local-policy and current-selection/
  authority-epoch sources into genuine operator-context and local-policy ports.
  Then compose activation, checkpoint, handoff, action, lifecycle, telemetry,
  process-owner, and production M1C sources. Reuse the accepted B4G terminal
  compatibility singleton, then
  register the genuine full composition provider through the accepted trusted
  opener.
- Execute the accepted presenter on a physical WebGPU device and retain a
  visible, non-black frame receipt with zero validation errors.
- Integrate the fuller Engine frame graph, PBR light evaluation, shadows, fog,
  bloom, semantic lighting, accessibility mirrors, and bounded measurements.
- Preserve one surface and producer. Districts, previews, and later remote
  shells remain scene resources rather than additional application surfaces.

### Remaining production gate

- Color, depth, normal, object-ID, emissive, and disclosure-boundary buffers
  match the frozen device profile.
- Every visible object ID resolves to admitted static content.
- No decorative effect resembles live traffic, readable code, or a person.
- Resizing, DPR, hidden-tab, stream-out, and quality-tier transitions retain
  stable object identity and bounded resources.
- Renderer imports no WebGPU OS driver or RealmForge UI.
- A real `Desktop` launch receives the trusted closure and presents at least one
  physical WebGPU frame. Mock-only evidence cannot satisfy this item.

### Rollback

Disable the scene presenter and retain the verified package/store diagnostics.

### M2D-B3: trusted production-composition substrate

The bounded M2D-B3 substrate is accepted independently of physical
presentation and integrated M2. It delivers:

- the kernel-owned `AppRuntimeCompositionRegistry`, with exact
  Virtual-Realm-only identity, single assignment, non-replacement, lease
  validation, descriptor-only request/lease/dependency snapshots, retryable
  concurrent destroy, and shutdown drain;
- guarded `Desktop` opener transport, which carries only the mount fence and
  app-scoped GPU syscalls, injects no property when unavailable, retires
  late/aborted leases without mounting, quarantines failed invalid-lease cleanup
  for retry, and runs Entry/factory cleanup before lease close;
- `RealmM2RuntimeComposition`, which validates supplied genuine authority
  ports, creates the real Engine adapter factory against the same activation
  port, captures GPU syscall methods into a private frozen facade, captures
  source-owner operations against prototype mutation, and returns one exact
  frozen dependency-version-2 closure without leaking raw authority; and
- `RealmOwnerCoupledGpuPresentationPort`, which binds acquisition and retirement
  of each GPU epoch to an exact, restart-distinct process owner and generation,
  synchronously fences release, retires GPU authority before source-owner
  authority, rejects overlap, mismatch, active receipts, and pending work, and
  retains GPU-first cleanup state when owner acquisition is rejected so close
  can retry.

Focused evidence is 11/11 browser composition cases and 5/5 independent Python
proofs, 15/15 owner-coupled GPU browser cases, 8/8 real Desktop terminal and
lease-transport cases, the unchanged 11/11 factory gate, and a current exact
48-module
composition and 15-module owner-coupled-port import closures with zero skipped
modules. The composition closure includes the later B4C checkpoint, B4D
handoff, B4E action-authority, B4F local-policy, and B4G terminal compatibility
validators; the originally accepted B3
behavior is unchanged. The earlier 60/60
GPU-port, 18/18 syscall-adapter, 5/5 GPU-port Python,
and 4/4 adapter-Python gates remain green.

Cleanup is now retryable through the complete retained call chain: the lazy
delegate, application factory, Desktop provisional handoff, composition wrapper,
and mandatory `app-unmount` phase share each in-flight attempt and clear only a
rejection. Successful teardown phases stay cached and are not retired twice.
The direct lazy-loader contract is 27/27; the factory and Desktop gates remain
11/11 and 8/8 with injected transient cleanup failure.

Acceptance is deliberately narrow. It does not accept a registered full
authority provider, invent missing wire protocols, prove a physical WebGPU
adapter/device submission, prove a non-black compositor-presented city frame,
or advance M2E. Ordinary OS launch therefore remains recoverably unavailable
until the separately reviewed genuine provider is installed.

### M2D-B4A: exact operator-context wire contract

M2D-B4A is accepted as a separate, provider-free authority-wire gate. The new
flat `RealmOperatorContextPortContract` freezes `operatorContext@1` without
granting operator, storage, Realm-selection, policy, or runtime authority. It
defines:

- the exact `snapshot`, `subscribe`, and `assertCurrent` port surface;
- a one-field snapshot request and three-field assert-current request;
- a subscribe request bound to operator identity/generation, one callback, and
  one live AbortSignal;
- the exact six-field snapshot: operator identity, protected partition,
  operator generation, local Realm identity, authority epoch, and policy epoch;
- a two-field invalidation event whose only payload is a closed reason code;
- an exact subscription handle and exact successful disposal receipt; and
- frozen request creators used by `VirtualRealmEntry` and
  `RealmLifecycleGenerationGuard`.

All wire records require exact frozen own enumerable data descriptors. Mutable,
inherited, accessor, symbol-bearing, extra-field, exotic, and hostile proxy
records fail closed. Canonical identifiers and decimal uint64 bounds are
enforced; operator generation is positive, while authority and policy epochs
retain the accepted zero-compatible boundary. Already-aborted request signals
are rejected. Callback, signal, and method identity is preserved, while opaque
functions are never invoked, traversed, or serialized by validation.

The invalidation event intentionally cannot carry current or next identity or
context. Its closed reasons are operator change, operator lock, local-Realm
change, authority-epoch change, policy-epoch change, and service stop. A later
trusted adapter must obtain `localRealmId` and `authorityEpoch` together from
`RealmLocalSelectionHeadStorage`, whose protected per-account epoch advances
across Realm changes, and `policyEpoch` from the selected Realm's monotonic
policy head. It must bind Kernel account/generation and reject missing or
cleared selection as unavailable, without inventing a Realm sentinel. Panel
IDs, mount IDs, public-profile data, directory enumeration, and Passport Realm
identity are not substitutes.

Focused evidence is 17/17 hostile browser cases and 6/6 independent Python
closure/confinement proofs. The contract has an exact one-module, import-inert
closure and no ambient, execution, storage, network, GPU, service-locator, or
First Shard authority. Existing runtime composition remains 30/30 and B3
production composition remains 11/11. No production provider or registry
installation was added.

The B4 sequence stays modular and unnested. B4A through B4F are accepted as
provider-free wire peers. B4G is the accepted terminal legacy surface/frame
implementation. B4H must compose the genuine authority owners and this
stateless compatibility singleton through the accepted B3 opener.
Legacy surface/frame calls terminate with `realm-gpu-presentation-required`;
the accepted owner-coupled GPU presentation port remains the GPU route.

### M2D-B4B: exact runtime-activation wire contract

M2D-B4B is accepted as a separate provider-free authority-wire gate. The flat
`RealmRuntimeActivationPortContract` freezes the complete
`realmRuntimeActivation@1` application surface without minting a handle,
retaining activation state, accessing storage, selecting a Realm, moving the
visible pointer, opening a gate, or invoking a provider. Its exact methods are:

1. `readActiveBundle({ signal })` with absent, active, handoff-displaced, and
   CSE-integrity-recovery results;
2. `prepareCandidateEligibility(...)` using the accepted nine-field M2C
   head/bundle/Realm/lifecycle/package request;
3. `consumeCandidateEligibility(...)` using the accepted eight-field one-shot
   materialization request;
4. `offerCandidate(...)` with one eligibility preparation, three distinct
   opaque candidate/CSE handle identities, one safe prepared-CSE receipt, three
   outer digests, and one live signal;
5. `commitCandidate({ eligibilityPreparationId, signal })` with committed,
   denied, predecessor, and recovery-pending results; and
6. `abortCandidate({ eligibilityPreparationId, reasonCode, signal })` with
   aborted, already-terminal, not-found, and recovery-pending results.

The exact new B4B request/result shapes are:

```text
readActiveBundle request
  signal
read result
  absent: status, visiblePointerGeneration
  active: status, runtimeBundleId, admissionIndexDigest,
          visiblePointerGeneration, visibleCommitReceiptDigest
  handoff-displaced: status, runtimeBundleId, visiblePointerGeneration,
                     crossSessionDisplacementReceiptDigest
  recovery-pending: status, reason = cse-integrity-quarantined

offerCandidate request
  eligibilityPreparationId, offActiveCandidateHandle,
  candidateGateSetHandle, preparedCseCommitHandle,
  preparedCseCommitReceipt, preparedCseCommitDigest,
  preparedCseSwapReceiptDigest, activeBakeOutputRecordDigest, signal
offer result
  offered: status, eligibilityPreparationId, runtimeBundleId,
           preparedCseCommitDigest, preparedCseSwapReceiptDigest,
           activeBakeOutputRecordDigest
  denied: status, eligibilityPreparationId, reason,
          candidateOwnership = caller-retained
  aborted: status, eligibilityPreparationId, reason = pin-unavailable,
           abortReceiptDigest

commitCandidate request
  eligibilityPreparationId, signal
commit result
  committed: status, runtimeBundleId, visiblePointerGeneration,
             visibleCommitReceiptDigest, activeBundleTeardownHandle
  denied: status, eligibilityPreparationId, reason,
          candidatePinRetirementReceiptDigest
  predecessor: status, eligibilityPreparationId,
               candidatePinRetirementReceiptDigest
  recovery-pending: status, eligibilityPreparationId, reason

abortCandidate request
  eligibilityPreparationId, reasonCode, signal
abort result
  aborted: status, eligibilityPreparationId, abortReceiptDigest
  already-terminal: status, eligibilityPreparationId, terminalStatus,
                    abortReceiptDigest only when terminalStatus = aborted
  not-found: status, reasonCode = preparation-missing
  recovery-pending: status, eligibilityPreparationId, reasonCode

activeBundleTeardownHandle
  portName = realmActiveBundleTeardown, version = 1, close
close request
  reason, signal
close result
  closed: closed = true, runtimeBundleId, visiblePointerGeneration,
          activeBundleCloseReceiptDigest
  lifecycle-active: closed = false, status,
                    reason = lifecycle-retirement-required
  recovery-pending: closed = false, status, reason
  terminal: closed = false, status = superseded | disposed,
            supersessionReceiptDigest
```

The accepted public correlation name is `eligibilityPreparationId`. Older
M2A/M2B planning text that uses `activationPreparationId` describes the same
service-internal lineage; it does not define a second application token. The
M2C preparation and consume shapes, denial vocabulary, result correlation, and
legacy two-result cleanup abort remain intact. Prepare and consume reject an
already-aborted work signal. Both legacy cleanup abort and the complete B4B
activation abort accept a cancelled signal structurally so cleanup cannot be
stranded; the future provider must still bind the exact private teardown root.
Consumption is single-use candidate-materialization authority, not permission
to erase every service correlation needed by a later offer. The existing test
fixture's deleted map entry demonstrates replay denial only and is not a
production state-machine specification. Before B4H installs a real provider,
the current loader/Entry legacy-abort call sites and their fixture must migrate
atomically to the rich reason/result contract on the same `abortCandidate`
method. B4B intentionally preserves both validators during that bounded
compatibility interval; it does not claim a provider can return two ambiguous
wire shapes to one migrated caller.

The safe `CausalStatePreparedCommitReceiptV2` is exactly 16 fields:
`format`, `version`, `transactionId`, `activeBundlePointerGeneration`,
`activeBakeCsePredecessorDigest`, `expectedPreRoot`, `transitionDigest`,
`effectsDigest`, `stagedPostRoot`, `stagedEventHead`,
`idempotencyReceiptDigest`, `outboxDigest`, `commitReceiptDigest`,
`signatureSetDigest`, `activeBakeOutputRecordDigest`, and
`preparedCommitDigest`. Its format is
`particle-realms.causal-state-prepared-commit`, its version is exactly `2`, and
all root/head/digest fields are canonical Realm content IDs. Offer validation
requires the outer `preparedCseCommitDigest` and
`activeBakeOutputRecordDigest` to equal their nested receipt values. It also
admits the separate `preparedCseSwapReceiptDigest`. The wire layer does not
claim cryptographic self-digest verification: a future trusted activation
service must recompute the receipt digest and validate each private handle
brand before ownership transfers.

An accepted offer result carries only safe preparation, bundle, and digest
evidence. A denied offer has the closed reasons `preparation-missing`,
`preparation-state`, `candidate-binding-invalid`, `candidate-gates-open`, or
`prepared-cse-invalid` and explicitly returns `candidateOwnership =
caller-retained`. A post-transfer pin failure is instead `aborted` with reason
`pin-unavailable` and one abort receipt digest. Commit denial is closed to
`activation-stale`, `immediate-liveness-denied`, `immediate-time-denied`,
`prepared-cse-invalid`, or `aborted`; recovery is closed to
`manager-authority-unresolved` or `cse-integrity-quarantined`.

Successful commit is the only result that contains a live value: one exact
frozen `realmActiveBundleTeardown@1` handle with only `close`. Close accepts the
closed reasons `application-close`, `operator-switch`, `device-loss`,
`handoff-complete`, and `activation-recovery`, then returns exactly one of:
closed bundle/pointer/receipt evidence; lifecycle-active no effect;
recovery-pending no effect; or superseded/disposed terminal evidence. The full
activation abort reasons are `application-close`, `operator-switch`,
`device-loss`, `handoff-cancel`, and `activation-recovery`; its terminal and
recovery variants are likewise closed and preparation-correlated.

All public records are exact frozen plain records with enumerable own data
properties. Validation snapshots descriptors and fails closed on mutable,
missing, extra, inherited, accessor, symbol-bearing, exotic, shape-shifting,
and inspection-throwing values. Forward operations require a live
AbortSignal-compatible capability. Opaque candidate handles are checked only
for non-null identity and pairwise distinction: validation never reflects,
invokes, freezes, clones, or serializes them. Port methods and the teardown
method are likewise inspected as own callable descriptor values but never
executed by validation.

Focused acceptance is 30/30 hostile browser cases and 7/7 independent Python
proofs. The exact combined activation, eligibility, and shared-validation graph
contained 15 cycle-free modules at B4B acceptance. The flat-peer layering
repair moved the shared error and record/head validation helpers into the
import-inert `RealmRuntimeValidationPrimitives` leaf. Its current measured
closure is exactly three modules—activation, candidate eligibility, and the
leaf—and explicitly excludes the aggregate dependency contract and B4E. It has
no provider or ambient execution authority and no First Shard dependency.
Existing loader, ECS materialization, and B3
production-composition gates remain green. M2D-B4B adds no activation service,
storage, process-owner transfer, CSE swap, visible pointer mutation, frame,
first-person controller, Operations View, minimap, or ordinary-launch success.
Those remain separately gated.

### M2D-B4C: exact runtime-checkpoint wire contract

M2D-B4C is accepted as a separate provider-free authority-wire gate. The flat
`RealmRuntimeCheckpointPortContract` freezes the complete
`realmRuntimeCheckpoint@1` application surface without allocating an identity,
retaining a preparation, reading protected storage, acquiring a source lease,
mutating a durable head, activating or retiring a root, or authorizing a
handoff. Its exact methods are:

1. `readLatest({ localRealmId, maximumBytes, signal })`;
2. `prepareCheckpoint({ localRealmId, checkpointDraft, expectedHeadBinding,
   signal })`;
3. `commitCheckpoint({ checkpointPreparationId, signal })`;
4. `abortCheckpoint({ checkpointPreparationId, reason, signal })`; and
5. `retireCheckpoint({ localRealmId, expectedHeadBinding, signal })`.

The complete request and result grammar is:

```text
readLatest request
  localRealmId, maximumBytes = 1048576, signal
read result
  missing: status, observedCheckpointGeneration = 0,
           exactStorageSha256 = null
  record: status, checkpoint
  cleared: status, observedCheckpointGeneration, exactStorageSha256,
           tombstoneDigest
  invalid: status, reasonCode
  unavailable: status, reasonCode

prepareCheckpoint request
  localRealmId, checkpointDraft, expectedHeadBinding, signal
prepare result
  prepared: status, checkpointPreparationId
  busy: status, reason
  unavailable: status, reason

commitCheckpoint request
  checkpointPreparationId, signal
commit result
  committed: status, checkpoint, checkpointHandoffAuthorizationId
  not-committed: status, checkpointPreparationId, reason,
                 checkpointAbandonmentReceiptDigest
  unavailable: status, checkpointPreparationId, reason
  invalid: status, reasonCode

abortCheckpoint request
  checkpointPreparationId, reason, signal
abort result
  aborted: status, checkpointPreparationId, checkpointAbortReceiptDigest
  already-terminal: status, checkpointPreparationId, terminalStatus,
                    optional checkpointAbortReceiptDigest
  not-found: status, reason = checkpoint-preparation-missing
  recovery-pending: status, checkpointPreparationId, reason

retireCheckpoint request
  localRealmId, expectedHeadBinding, signal
retire result
  cleared: status, observedCheckpointGeneration, exactStorageSha256,
           tombstoneDigest
  busy: status, reason = checkpoint-handoff-edge-active
  invalid: status, reasonCode
  unavailable: status, reasonCode
```

The B4C byte ceiling is not caller-selected. `readLatest.maximumBytes` must be
the accepted runtime profile's `maximumAdmissionControlRecordBytes`, exactly
`1048576`. `RealmRuntimeCheckpointAdapter` receives the already accepted frozen
profile, rejects any other limit, snapshots that value, and emits the exact
three-field request. This replaces the earlier permissive adapter request that
included app, operator, process-owner, and lifecycle fields. Those values stay
private adapter bindings and do not cross the B4C read wire. The adapter applies
the lifecycle-generation guard before and after the call, validates the exact
result, and returns the original frozen observation.

Every forward request requires a live AbortSignal-compatible capability. B4C
also requires a live signal on `abortCheckpoint`; a future provider must bind it
to the exact teardown flow so a general work signal cannot exercise cleanup
authority. The opaque preparation ID matches
`checkpoint-preparation:v1:<64-lowercase-hex>`, is at most 96 UTF-8 bytes, and
is single-use, owner-bound, and lifecycle-bound by the future service. The
handoff authorization matches
`checkpoint-handoff-authorization:v1:<64-lowercase-hex>` and appears only after
a committed checkpoint. The contract validates syntax and placement. It does
not mint either correlation or treat either as a storage capability.

The closed reason domains are exact:

- Read/retire invalid: `oversized`, `future-version`, `malformed`,
  `live-value`, `digest-invalid`, or `checkpoint-binding-invalid`.
- Read/retire unavailable: `root-recovery-pending` or
  `manager-authority-unresolved`.
- Prepare busy: `checkpoint-preparation-busy` or
  `checkpoint-edge-capacity`.
- Prepare unavailable: `secure-random-unavailable` or
  `manager-authority-unresolved`.
- Commit not committed: `checkpoint-head-predecessor-retained` or
  `checkpoint-source-changed`.
- Commit unavailable: `checkpoint-source-unavailable`,
  `root-recovery-pending`, or `manager-authority-unresolved`.
- Commit invalid: `checkpoint-preparation-missing`.
- Abort reason: `application-close`, `operator-switch`, `device-loss`,
  `handoff-cancel`, or `checkpoint-recovery`.
- Abort recovery: `checkpoint-commit-authority-unresolved`.
- Abort terminal status: `abandoned`, `committed`, or `retired`.

The result families keep observation and operation reconciliation distinct.
`readLatest()` reports the durable head it observes. `commitCheckpoint()`
instead reports the outcome of one preparation. Only `committed` carries a new
safe checkpoint and handoff correlation. Exact predecessor retention or source
change is `not-committed` with a preparation-correlated abandonment-receipt
digest. Source unavailability retains retryable preparation state. An uncertain
head or root observation remains unavailable for manager recovery. It cannot be
reported as an old record, a missing head, or a successful commit. The locked
committed and invalid variants omit `checkpointPreparationId`; the stateless
wire validator therefore correlates only result variants that carry it.

`abortCheckpoint()` preserves the same distinction. A prepared entry may
become `aborted`; a committing entry can only become `recovery-pending`.
Arbitrary or evicted correlations are `not-found` and allocate nothing.
Idempotent terminal replay names only `abandoned`, `committed`, or `retired`.
Only an `abandoned` terminal may carry the retained
`checkpointAbortReceiptDigest`. The app receives only receipt digests. Full
abort and abandonment receipts, root identities, journals, paths, and storage
capabilities remain private to the future manager.

The exact expected-head binding contains `checkpointGeneration` and nullable
`exactStorageSha256`. Generation `0` requires null SHA and is legal only for a
never-initialized head. Every positive generation requires a canonical storage
SHA. The exact draft carries the admitted index digest, publication head,
admission head, runtime profile identity/digest, runtime bundle, safe anchor,
optional logical cursor, and local policy identity/digest. Its top-level
admission index must equal the nested admission-head value. These are bounded
requests against accepted M1C/M2 state; B4C grants no publication or admission
mutation authority and changes no accepted M1C contract.

The safe checkpoint projection carries observed generation, exact storage SHA,
checkpoint ID, accepted index/heads/profile/bundle/anchor/policy, optional
cursor, creation time, record digest, and one exact
`RealmRuntimeCheckpointBindingV1`. Validation requires the projection and
binding to agree on generation, SHA, checkpoint ID, admission index, both
heads, profile, bundle, anchor, optional cursor presence and value, policy, and
record digest. The binding additionally retains process owner, positive
lifecycle generation, visible pointer generation, live-visibility receipt,
checkpoint-source projection digest, checkpoint-source authorization digest,
and its own binding digest. B4C checks exact frozen shape, canonical identifiers,
decimal uint64 text, storage-SHA/content-ID syntax, and cross-record equality.
It deliberately does not recompute a cryptographic digest or verify a private
source lease.

`RealmM2RuntimeComposition` now validates the exact checkpoint port before GPU,
runtime-profile, or source process-owner acquisition, then preserves that same
port identity in the 16-key dependency-version-2 lease. `VirtualRealmEntry`
passes its validated runtime profile into `RealmRuntimeCheckpointAdapter`.
Normal startup constructs the adapter but performs zero checkpoint calls, so
B4C adds no launch-time mutation or authority use. The exact checkpoint fake was
migrated atomically to return the canonical missing observation rather than the
earlier empty record.

B4C remains provider-free and unnested. The future
`RealmRuntimeCheckpointSourceService` must independently reproduce current
bundle/pointer/live-visibility/head/profile/anchor/cursor/policy state and hold
its narrow selection lease through head CAS and active-root readiness. The
future `RealmRuntimeCheckpointManager` must own secure-random issuance, bounded
correlation replay, fixed authorization cells, exact CAS/readback,
successor-active retirement, restart recovery, and retryable root cleanup. No
part of that authority is implemented by the B4C wire, adapter, Entry, or
composition change. The First Shard remains excluded. (Sources:
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeCheckpointPortContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeCheckpointAdapter.js`;
`webgpu-os/apps/the-virtual-realm/VirtualRealmEntry.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`webgpu-os/apps/the-virtual-realm/runtime-contracts/RealmRuntimeCapabilityProfileContract.js`;
`MD/webgpu-os/virtual-realm/m2b-private-bake-admission.md`.)

Focused B4C acceptance is 45/45 hostile browser contract cases and 7/7
independent Python proofs. At that gate, the contract closure was exactly one
import-inert module with zero imports, cycles, or parse errors, and the
checkpoint-adapter, Entry, and `RealmM2RuntimeComposition` closures were 15,
96, and 36 acyclic error-free modules. B4D and B4E preserve the B4C ABI; the
current Entry and composition closures are 106 and 48 modules.

### M2D-B4D: exact runtime-handoff wire contract

M2D-B4D is accepted as the complete provider-free
`realmRuntimeHandoff@1` application grammar. Its port is exactly
`{ portName, version, read, write, clear }`; validation observes callable
identity but invokes no method. Every request, result, handoff head, draft,
handoff record, checkpoint binding, status, reason, and field catalog is an
exact frozen own-data shape. Mutable, inherited, accessor, symbol-bearing,
exotic, widened, inspection-throwing, and shape-shifting values fail closed.
The contract has zero imports and retains no state.

The read ABI is exactly:

```text
read({ operatorIdentity, localRealmId, maximumBytes, signal })
```

`maximumBytes` is not caller policy. It must equal the already validated frozen
runtime profile's `maximumRuntimeHandoffBytes`, currently `65536`. A read result
is exactly one of:

- `missing { observedHandoffGeneration: "0", exactStorageSha256: null }`;
- `record { observedHandoffGeneration, exactStorageSha256, record }`;
- `cleared { observedHandoffGeneration, exactStorageSha256, tombstoneDigest }`;
- `invalid { reasonCode }`; or
- `unavailable { reasonCode }`.

Record and cleared observations require positive canonical uint64 generations
and `sha256:<64 lowercase hexadecimal>` storage identities. The record's
generation must equal the observed generation. Invalid is closed to
`oversized`, `future-version`, `malformed`, `live-value`, `digest-invalid`, and
`checkpoint-binding-invalid`. Unavailable is closed to
`root-recovery-pending` and `manager-authority-unresolved`; it cannot be
collapsed into missing state.

The write ABI is exactly:

```text
write({
  operatorIdentity,
  localRealmId,
  recordDraft: { operationsViewRequested },
  checkpointHandoffAuthorizationId,
  expectedHeadBinding,
  signal
})
```

The checkpoint correlation is canonical
`checkpoint-handoff-authorization:v1:<64 lowercase hexadecimal>`. The expected
head is exactly `{ handoffGeneration, exactStorageSha256 }`: generation `0`
requires null SHA, while every positive generation requires a storage SHA.
`recordDraft` is deliberately only one Boolean preference. It cannot contain a
checkpoint record, prior runtime state, manager operation, root, graph edge,
pin, lease, path, capability cell, or handle.

Write returns exactly `written`, `predecessor`, `invalid`, or `unavailable`.
Written is `written: true` plus the exact next generation, new handoff root
reference, exact storage SHA, record digest, and checkpoint-binding digest. If
an expected head is supplied to validation, the successful generation must be
exactly expected plus one and uint64 overflow is forbidden. Predecessor is
`written: false` plus the exact expected generation/SHA and proves no effect.
The public invalid vocabulary adds only
`handoff-authorization-invalid` to the six read reasons. Every internal
authorization failure—unknown, foreign, stale, replayed, unretained,
mismatched, or already settled—must map to that one result so the application
cannot distinguish protected identity or checkpoint state.

The clear ABI is exactly:

```text
clear({ operatorIdentity, localRealmId, expectedHeadBinding, signal })
```

Clear returns exactly `cleared`, `already-clear`, `predecessor`, `invalid`, or
`unavailable`. A `0`/null expected head is legal but cannot produce `cleared`;
its settled idempotent form is only `already-clear { cleared: false }` with no
tombstone digest. `Predecessor`, `invalid`, and `unavailable` remain legal. A
positive already-clear result carries its exact observed generation/SHA and
must include the existing tombstone digest. A new clear is `cleared: true`,
advances a positive expected head exactly once, and returns the cleared root
reference, successor storage SHA, and tombstone digest. Predecessor is a
correlated no-effect result. The future provider may return cleared only after
tombstone readback, handoff-root retirement/release, and checkpoint-edge
release readback all settle; partial settlement remains
`unavailable/root-recovery-pending`.

The safe `RealmRuntimeHandoffRecordV1` has four exact shapes: generation one or
replacement, each with or without `logicalCursorId`. Generation one forbids
`previousHandoffStorageSha256`; every generation after one requires it. The
record binds operator and local Realm, generation, handoff root and manager
operation, process owner and lifecycle, publication/admission heads, runtime
profile, runtime bundle, checkpoint binding, safe anchor, Operations View
request, local policy, optional cursor, and record digest. Its nested
`RealmRuntimeCheckpointBindingV1` must agree field by field on process owner,
lifecycle, admission-index digest, both heads, profile, bundle, anchor, cursor
presence/value, and policy. The port contract validates shape, syntax, and
cross-equality; it does not claim cryptographic recomputation, authorization
validity, head CAS, root readiness, retained graph-edge ownership, runtime-pin
ownership, or durable recovery.

The existing `RealmRuntimeHandoffAdapter` remains a read-only M2A reducer. Its
constructor now validates the exact port and frozen 65,536-byte profile cap.
`read()` creates the exact request, fences it with pre/post lifecycle checks,
validates the response, and creates a descriptor-derived safe record snapshot
before existing canonical checkpoint-binding and handoff-record digest
verification. It then applies operator, local-Realm, prior-lifecycle, profile,
publication-head, admission-head, checkpoint-binding, and optional-cursor
checks. Accepted operator identity remains private to the internal observation;
the public application status exposes no record, checkpoint binding, operator,
process owner, runtime bundle, handoff root, or manager operation. There is no
adapter write or clear API, and the integration fake throws if either port
method is called.

`RealmM2RuntimeComposition` validates `runtimeHandoffPort` before GPU syscalls,
runtime-profile validation, or source process-owner acquisition and preserves
the same port identity in the exact 16-key dependency-version-2 lease. Thus a
malformed handoff capability can allocate no GPU epoch or owner. The adapter,
composition, and application still gain no protected handoff owner and do not
restore a live runtime.

B4D deliberately installs no provider, storage, protected handoff head, CAS,
journal, authorization issuer/cell, root manager, checkpoint-retention edge,
runtime pin, cross-session activation, pointer mutation, CSE mutation, gate
opening, or live handle. Focused acceptance is 60/60 hostile browser cases and
10/10 independent Python proofs. The contract, adapter, Entry, and composition
closures at B4D acceptance were exactly 1, 16, 97, and 37 acyclic error-free
modules. The then-current scoped B4A-B4D/Entry/composition Python group passed
37/37. Browser regressions passed B4A 17/17, B4B 30/30, B4C 45/45, M2A
composition 30/30, and B3 production composition 11/11. Every tested closure
excluded the First Shard.
(Sources:
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeHandoffPortContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeHandoffAdapter.js`;
`webgpu-os/apps/the-virtual-realm/runtime-contracts/RealmRuntimeHandoffRecordContract.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`tests/virtual-realm/m2-runtime-handoff-port-contract.test.js`;
`tests/virtual-realm/test_m2db4d_runtime_handoff_port_contract.py`.)

### M2D-B4E: exact action-authority wire contract

M2D-B4E is accepted as the complete provider-free
`realmActionAuthority@1` application grammar. The port is exactly:

```text
{
  portName: "realmActionAuthority",
  version: 1,
  submitProposal,
  observeResult
}
```

Port validation observes and preserves the two callable identities but invokes
neither one. Public data validators are exact-shape, descriptor-first, and
size-bounded; after proving the complete deeply frozen input they preserve its
identity. Dedicated creators and snapshot helpers produce detached deeply
frozen values. Mutable, inherited, accessor, symbol-bearing, exotic, cyclic,
functional, inspection-throwing, and shape-shifting data fails closed.
The contract imports only the existing M0 action Proposal, AuthorityReceipt,
and Result definitions plus the shared value preflight. Its complete closure is
16 modules rather than one import-inert module; it imports no runtime provider,
adapter, kernel authority, storage, networking, GPU, or test module.

Every operation that can carry protected action data is bound to this exact
context:

```text
{
  operatorIdentity,
  operatorGeneration,
  localRealmId,
  lifecycleGeneration,
  authorityEpoch,
  policyEpoch,
  activeBundleBinding: {
    runtimeBundleId,
    admissionIndexDigest,
    visiblePointerGeneration,
    visibleCommitReceiptDigest
  }
}
```

Operator and lifecycle generations are positive canonical uint64 text.
Authority and policy epochs permit canonical zero because their provider
activation is still absent. Bundle generation is positive. Both bundle digests
are exact `sha256:256:<64 lowercase hexadecimal>` content IDs. The context is a
fresh deeply frozen snapshot; only method and `AbortSignal` identities cross as
opaque capabilities.

The submit ABI is exactly:

```text
submitProposal({ ...context, proposal, signal })
```

The proposal is the frozen M0 `RealmActionProposalV1`, but B4E tightens its
boundary. `proposal.realmId` must equal `localRealmId`; audience is exactly
`owner-private`; disclosure is exactly `local-private`; presence-session,
rendezvous-frame, rendezvous-epoch, and bridge-epoch fields are absent.
`actorId` is intentionally not equated with `operatorIdentity`. Every action
must match its exact parameter discriminator. Content IDs use the full
`sha256:256:` syntax, while `operationNonce` is exactly 64 lowercase
hexadecimal characters. Proposal lifetime is finite, positive, strictly
ordered, and no longer than 300,000 milliseconds.

`manage-local-zone` is admitted only when the proposal includes both
`capabilityEpoch` and `expectedStateRevision`, and its nested
`zoneManagementProposalDigest` is a canonical content ID. That admission is not
permission. The frozen M0 authority receipt rejects `allowed` for this action,
so B4E cannot turn a local Operations request into mutation authority.
Selection and focus remain presentation-only and are not action variants.

Submit returns exactly one of:

- `receipt`, echoing the complete context plus `authorityReceiptId`,
  `authorityReceiptDigest`, `resultCorrelationId`, and the frozen receipt;
- `invalid { reasonCode }`; or
- `unavailable { reasonCode }`.

The outer receipt digest must equal `receipt.receiptDigest`; a caller cannot
replace one while retaining the other. Proposal and receipt cross-bind proposal
identity/digest, Realm, actor, target/revision, action, policy revision,
idempotency key, and local-scope epoch presence. An allowed receipt alone may
carry the complete capability ID/scope/epoch tuple, and that tuple follows the
proposal capability epoch exactly. Its lifetime is contained by the proposal
lifetime and its settlement is `pending-result`. Every non-allow receipt omits
all capability fields, is `not-dispatched`, and still receives a mandatory
`action-result-correlation:v1:<64 lowercase hexadecimal>` ID.

Receipt decisions are exactly `allowed`, `denied`, `conflict`, `expired`,
`revoked`, and `failed-before-dispatch`. Allowed maps only to `authorized`.
Denied and conflict both map to the generic
`action-authorization-invalid`, preventing an identity, capability, replay, or
policy oracle. Expired maps to `proposal-expired`, revoked to
`authority-revoked`, and failed-before-dispatch to either
`cancelled-before-dispatch` or `dispatch-preparation-failed`.

The observe ABI is exactly:

```text
observeResult({
  ...context,
  proposalId,
  proposalDigest,
  authorityReceiptId,
  authorityReceiptDigest,
  dispatchId,
  idempotencyKey,
  resultCorrelationId,
  signal
})
```

The seven correlation fields must equal the accepted submit receipt. Observe
returns `pending`, `terminal`, `invalid`, or `unavailable`; it never returns
`missing` or `not-found`. Pending and terminal repeat the complete context and
correlation set. A non-allow receipt is already terminal and cannot remain
pending. Terminal adds the frozen M0 result and cross-binds proposal, receipt,
dispatch, idempotency, target, action, optional epoch presence, and
`resultId === resultCorrelationId`. A terminal result carries
`resultingStateRevision` if and only if its outcome is `succeeded`. Non-allow
outcome/reason must exactly match the originating receipt.

The submit and observe data envelopes are each capped at 65,536 canonical
bytes. Submit invalid reasons are exactly `oversized`, `future-version`,
`malformed`, `live-value`, `digest-invalid`, `proposal-binding-invalid`, and
`action-authorization-invalid`. Observe invalid reasons are exactly
`oversized`, `future-version`, `malformed`, `live-value`, `digest-invalid`, and
`result-correlation-invalid`. Both operations share only
`authority-unavailable`, `action-capacity-unavailable`, and
`settlement-recovery-pending` as unavailable reasons.

`RealmRuntimeDependencyContract` now validates the full action port, so direct
Entry construction cannot bypass B4E. `RealmM2RuntimeComposition` validates
activation, checkpoint, handoff, then action before it validates GPU syscalls,
awaits the runtime profile, or acquires the source process owner. The identical
action port is retained in the exact 16-key dependency-version-2 lease. Normal
Entry startup calls neither action method and exposes no receipt through public
status. No adapter, action provider, dispatcher, executor, replay cache,
single-spend ledger, entropy/clock source, result store, settlement journal,
Operations View, ECS mutation, renderer mutation, filesystem write, or network
route is added.

`RealmRuntimeValidationPrimitives` now owns the shared dependency error,
exact-record, identifier, uint64, abort-signal, and head-binding implementations
as one import-inert leaf. `RealmRuntimeDependencyContract` imports and re-exports
the exact same bindings, preserving its public API and error-constructor
identity. `RealmCandidateEligibilityContract` imports the leaf directly, so the
B4B peer no longer reaches the aggregate dependency catalog or B4E.

B4E validates wire syntax, safe snapshots, and correlation only. It does not
recompute proposal, receipt, or result digests and cannot prove that any
identifier is unpredictable or unique. The future B4H trusted owner must mint
correlations, enforce single-spend and exact-retry behavior, reassert current
operator/Realm/lifecycle/authority/policy/bundle bindings immediately before
dispatch, make dispatch and durable settlement atomic, and recover partial
settlement without reporting false completion.

Focused acceptance is 75/75 hostile browser cases and 11/11 independent Python
proofs. At B4E acceptance, the B4E contract, shared runtime dependency, Entry,
and production-composition closures were exactly 16, 21, 103, and 45 acyclic error-free
modules. The B4B activation root is exactly three modules after the shared
validation-primitives leaf removes its former aggregate dependency and B4E
reachability. The combined scoped
B4A-B4E/Entry/composition Python group passes 48/48. Browser regressions pass
B4A 17/17, B4B 30/30, B4C 45/45, B4D 60/60, B4E 75/75, M2A composition 30/30,
and B3 production composition 11/11: 268/268 with zero skips. (Sources:
`webgpu-os/apps/the-virtual-realm/runtime/RealmActionAuthorityPortContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeDependencyContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeValidationPrimitives.js`;
`webgpu-os/apps/the-virtual-realm/VirtualRealmEntry.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`tests/virtual-realm/m2-action-authority-port-contract.test.html`;
`tests/virtual-realm/m2-action-authority-port-contract.test.js`;
`tests/virtual-realm/m2-action-authority-port-contract.main.js`;
`tests/virtual-realm/test_m2db4e_action_authority_port_contract.py`.)

### M2D-B4F: exact local-operator-policy wire contract

M2D-B4F is accepted as the complete provider-free
`localOperatorPolicy@1` application wire. The port is exactly
`{ portName, version, readPolicy, subscribe }`. Its validator preserves both
method identities and invokes neither. Request validators likewise preserve
opaque `AbortSignal` and callback identities; subscription validation preserves
the opaque disposal function. Policy, read-result, invalidation, and disposal-
receipt validation returns detached, deeply frozen data snapshots.

The read request is exactly the six-field owner-local context—
`operatorIdentity`, `operatorGeneration`, `localRealmId`,
`lifecycleGeneration`, `authorityEpoch`, and `policyEpoch`—plus a live signal.
Authority and policy epochs may be zero only here, preserving B4A's
unavailable-context representation. A successful `policy` result requires both
epochs positive, echoes every context field, and carries exactly a nested
`head` plus the accepted M0 `LocalOperatorViewPolicyV1`. The head contains
`policyId`, `policyRevision`, and `policyDigest`. The digest syntax is exactly
`sha256:256:<64 lowercase hexadecimal>`; owner and Realm bind to the context,
and all three head fields bind to the policy.

Read statuses are only `policy`, `invalid`, and `unavailable`. Invalid reasons
are `oversized`, `future-version`, `malformed`, `live-value`,
`digest-invalid`, and `policy-binding-invalid`; unavailable reasons are
`policy-unavailable` and `policy-recovery-pending`. No missing/not-found oracle
or protected provider detail is representable. Read and policy data are capped
at 65,536 canonical bytes.

Subscribe repeats the positive-epoch context, exact head, opaque
`onInvalidated` callback, and live signal. Optional correlation to an accepted
read requires equality of every context and head field. The only notification
is exactly `{ eventKind, reasonCode }`, with event kind
`local-operator-policy-invalidated` and reason `context-invalidated`,
`policy-invalidated`, or `service-stopped`. It is data-only and cannot carry a
replacement policy, foreign Realm, connected-city state, projection, handle,
or authority. Subscription and disposal are exactly
`{ subscriptionId, dispose }` and `{ subscriptionId, disposed: true }`.

B4F reuses the M0 policy contract; it creates no parallel schema. It validates
digest syntax and cross-binding, not digest-to-body truth. It owns no provider,
policy store, monotonic protected head, recovery journal, clock, network,
World/ECS/GPU state, view, minimap, controller, renderer, or mutation path.
B4H now contains separate protected policy and current-selection/authority-epoch
head sources, both reusing the same kernel-only transaction helper. Coherent
source-to-port adaptation, lifecycle reassertion, B4F observation/subscription
invalidation, and provider composition remain live-owner work. B4G has closed
the final peer boundary.

The existing dependency-v2 record remains exactly 16 keys. Its pre-existing
`localOperatorPolicyPort` slot now receives full B4F validation. Trusted
composition validates policy immediately after action authority and before GPU
syscalls, capability-profile inspection, or process-owner acquisition, then
forwards the identical accepted object. Entry startup calls neither method.

B4F also hardens the M0 acceptance joins that consume this policy. A supplied
policy must match a zone-management proposal or minimap snapshot on
`policyId`, `policyRevision`, `localRealmId`, and `ownerIdentity` before its
permissions or limits can be used. The hostile gate proves that schema-valid
foreign policy substitution fails while both valid base acceptances remain
unchanged.

Focused acceptance is 60/60 hostile browser cases and 11/11 independent Python
proofs. At B4F acceptance, acyclic error-free closures were 11 modules for B4F, 23 for the
shared dependency contract, 105 for Entry, 47 for production composition, and
29 for the renderer root. The scoped B4A-B4F/Entry/production-composition
Python group passes 59/59, or 64/64 with renderer confinement. Browser
regressions pass B4A 17/17, B4B 30/30, B4C 45/45, B4D 60/60, B4E 75/75, B4F
60/60, M2A composition 30/30, and B3 production composition 11/11: 328/328
with zero skips. (Sources:
`webgpu-os/apps/the-virtual-realm/runtime/RealmLocalOperatorPolicyPortContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeDependencyContract.js`;
`webgpu-os/apps/the-virtual-realm/contracts/LocalZoneManagementProposalContract.js`;
`webgpu-os/apps/the-virtual-realm/contracts/LocalCityMinimapSnapshotContract.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`tests/virtual-realm/m2-local-operator-policy-port-contract.test.html`;
`tests/virtual-realm/m2-local-operator-policy-port-contract.test.js`;
`tests/virtual-realm/m2-local-operator-policy-port-contract.main.js`;
`tests/virtual-realm/test_m2db4f_local_operator_policy_port_contract.py`.)

### M2D-B4G: terminal legacy surface/frame compatibility

M2D-B4G is accepted. `RealmLegacySurfaceFramePort.js` closes the existing
`surfaceFramePort` slot without changing dependency version 2 or its 16 keys.
The exact port is `{ portName, version, acquireSurface, registerFrameProducer }`,
branded `surfaceFrame@1`. Both methods synchronously return the same exact
terminal result:

```javascript
{ status: 'unavailable', reasonCode: 'realm-gpu-presentation-required', recoverable: false }
```

`recoverable: false` is local to this retired route. Retrying it cannot acquire
a surface or frame producer. The separate owner-coupled
`realmGpuPresentation@1` route retains its existing capability, ownership,
generation, device-loss, and cleanup requirements. This result is not evidence
that that route is available, authorized, or currently presenting.

The config-free `createRealmLegacySurfaceFramePort()` returns one frozen
null-prototype singleton. Its methods are frozen zero-argument arrow functions;
the shared terminal result is also frozen and null-prototype. Methods ignore
all supplied arguments and their receiver without inspection, coercion,
retention, logging, invocation, promise assimilation, or signal subscription.
There is no admitted request schema: every attempted legacy request terminates
identically, including malformed input, revoked proxies, and aborted signals.
The synchronous return remains safe for existing `await` callers. Extra factory
arguments fail with `VR_M2DB4G_OPTIONS_FORBIDDEN` without inspecting their values.

`validateRealmLegacySurfaceFramePort()` accepts only that same module singleton
and returns it unchanged. Every other input receives
`VR_M2DB4G_PORT_REQUIRED` at `$.surfaceFramePort`. The error contains no supplied
data or cause. Copies, wrappers, cross-module-instance ports, accessor objects,
and transparent or revoked proxies are rejected without reflection. Structural
equality cannot prove that a caller-supplied callable is terminal; exact identity
prevents a look-alike adapter from wrapping raw surface or frame syscalls.
Providers must import the canonical module, not duplicate or serialize its port.

`RealmRuntimeDependencyContract` validates this existing slot. Trusted
`RealmM2RuntimeComposition` validates it after B4F and before inspecting GPU
syscalls, the runtime profile, or process-owner authority, then forwards its
identity unchanged. Startup has no legacy consumer. The no-consumer proof reads
the exact approved Entry import closure; fixture call counters do not claim to
observe terminal-method invocations. Existing M2A/B3 cases additionally prove
that attempted legacy calls leave raw GPU and process-owner effects unchanged.

The module has no imports, stateful registry, resource owner, observer,
disposal phase, clock, logger, store, network, or runtime authority. Its fixed
reason and typed admission errors are the complete diagnostic surface; accepting
a logger would add an unnecessary callback route and potential request leak.
The compatibility implementation requires no B4H source service.

Acceptance evidence: 24/24 hostile B4G browser cases and 8/8 independent Python
confinement tests. B4A-B4G plus M2A and B3 pass 352/352 browser cases with zero
failures or skips. The scoped B4A-B4G/Entry/composition/renderer Python group
passes 72/72. Exact acyclic error-free closures are B4G 1, shared dependency 24,
Entry 106, trusted composition 48, and renderer 30 modules. B4A-B4F peer
contract closures remain unchanged. M0-M1C's 109-definition catalog and M2's
11-definition/13-module extension remain unchanged.

Additional factory and real Desktop lease-transport regressions pass 11/11 and
8/8 respectively. Registry snapshots copy only the outer dependency record;
Desktop, the lazy factory, and Entry preserve the nested terminal port identity.
Those 19 transport cases bring this turn's complete browser check to 371/371.

B4G registers no provider. Rollback leaves launch recoverably unavailable and
never restores a raw legacy GPU adapter.

(Sources:
`webgpu-os/apps/the-virtual-realm/runtime/RealmLegacySurfaceFramePort.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeDependencyContract.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`tests/virtual-realm/m2-legacy-surface-frame-port.test.html`;
`tests/virtual-realm/m2-legacy-surface-frame-port.test.js`;
`tests/virtual-realm/test_m2db4g_legacy_surface_frame_port.py`;
`tests/virtual-realm/m2-runtime-composition.test.js`;
`tests/virtual-realm/m2-runtime-production-composition.test.js`.)

### M2D-B4H: genuine authority-provider composition

M2D-B4H is underway and unaccepted. The bounded kernel-only policy and selection
owners are implemented: `RealmLocalOperatorPolicyHeadStorage` and
`RealmLocalSelectionHeadStorage`. Each requires a branded protected
`OperatorPrivateServiceStorageView` bound to the captured account and operator
generation. Passport, mounts, panels, runtime profiles, and directory enumeration
cannot supply their account, Realm, or epoch authority.

These are typed protected-head sources under trusted module construction, not
proof of hostile same-origin isolation. The exported
`storageManager.bindOperatorServiceRoot()` still accepts caller-created
`OperatorScope` and current-scope callbacks; descriptors and the branded-view
factory are publicly importable. The brand proves construction by that factory,
not authenticated Kernel issuance to a permitted caller. `OPFSDriver` also
obtains the origin-wide storage root, bypassing manager guards when hostile
same-origin code calls the native API directly. Before activating a B4A/B4F
adapter or full provider, establish both authenticated kernel-controlled
acquisition and enforced backend isolation against native same-origin
OPFS/import bypass. Tokens, same-origin workers, and source import allowlists
alone satisfy neither the complete isolation requirement nor provider
acceptance. This unresolved dependency belongs to pieces 3 and 10 and creates
no eleventh piece. See the
[current shared-origin enforcement gap](security-privacy.md#current-shared-origin-enforcement-gap).
(Sources:
`webgpu-os/storage/StorageManager.js`;
`webgpu-os/storage/OPFSDriver.js`;
`webgpu-os/kernel/OperatorPrivateServiceStorageView.js`;
`webgpu-os/kernel/schema/OperatorScope.js`.)

The policy source owns one explicit Realm's head. It validates the canonical M0
policy and recomputes its content digest, preserves a stable `policyId`, treats
`policyRevision` as opaque, increments uint64 `policyEpoch` by exactly one, and
records the predecessor's exact storage SHA-256. An unchanged policy writes
nothing. `virtual-realm-local-policy-v1` admits only the Realm-hashed policy
control path, with no delete, listing, or content namespace. Policy payloads
retain the existing 65,536-byte bound and protected heads the 131,072-byte bound.
The accepted persisted policy bytes and trusted three-method API are unchanged.

The selection source owns one per-account `/selection/head.json` record in
`virtual-realm-local-selection-v1`, capped at exactly 4,096 bytes. Its exact
stored fields are `format`, `version`, `operatorIdentity`, nullable
`localRealmId`, `authorityEpoch`, and `previousStorageSha256`. The private
account storage principal supplies `operatorIdentity`. The positive uint64
epoch advances globally across that account's Realm selections, not separately
per Realm; A-to-B-to-A and source reopen cannot reset the exact epoch/SHA
binding. Missing storage is an internal epoch-zero/null-SHA observation.
Clearing writes a positive-epoch null-Realm tombstone and retains predecessor
lineage. The service permits no head deletion, listing, or content access.

Selection replacement accepts exactly
`{ localRealmId, advanceAuthority, expected, signal }`. Its expected binding is
null for missing storage or the exact frozen `{ authorityEpoch,
exactStorageSha256 }` pair for an existing head. An unchanged selection with
`advanceAuthority: false` writes nothing, including at maximum epoch.
`advanceAuthority: true` requires and retains the currently selected non-null
Realm; it cannot select a different Realm, operate on missing/cleared state, or
grant a capability. A changed or explicitly advanced head increments the epoch
once; exhaustion rejects before storage. Callers cannot supply a next epoch.

The policy and selection wrappers reuse `RealmProtectedHeadStorage`, a narrow
transaction helper
with fixed kernel-owned domain hooks, not a registration system or an
application-supplied schema. The helper owns native-signal and scope fences,
bounded canonical exact-byte reads, exact expected epoch/SHA comparison,
successor owner/epoch/predecessor checks, canonical domain validation before
dispatch, protected CAS receipts, exact readback, and uncertainty recovery.
Each domain privately brands its frozen diagnostics so backend errors cannot
forge or disclose source diagnostics. Every asynchronous boundary reasserts
the captured scope. A failure after dispatch reports an unknown outcome and
requires an explicit recovery read; private `writeSequence` state prevents an
older or overlapping read from clearing that fence.

The policy and selection sources expose only trusted `readCurrent`,
`assertCurrent`, and
`replaceCurrent`. Returned records contain frozen domain data and bindings,
not bytes, backend paths, source objects, or the retained writer. These trusted
source methods are not B4A/B4F application ports. The next missing adapter must
capture one coherent Kernel account/generation, selection Realm/authority
epoch, and matching per-Realm policy epoch. Missing or cleared selection fails
unavailable without a fabricated sentinel; a selected Realm alone grants no
ownership or policy permission. Lifecycle reassertion and bounded data-only
invalidation must be implemented before the full provider can use those ports.
No source registers an opener, changes the exact 16-key dependency record, or
enters the existing Entry/B3 composition closures.

Piece 3 now has the read-only kernel prerequisite
`RealmLocalOperatorSnapshotSource`, not the B4A/B4F adapters. Its factory accepts
exactly `{ operatorContext, selectionStorageView, policyStorageView }`, captures
the active `OperatorContext` account/generation synchronously, and requires both
correctly branded service views to match that capture. It exposes only
`readSnapshot({ signal })` with an exact frozen request and native AbortSignal.
It never accepts preassembled runtime ports or caller-authored epoch values.

The source reads selection S1, opens and reads that selected Realm's verified
policy P1, then reasserts S1's exact authority epoch and storage SHA. Synchronous
operator and both-view fences surround each await, on success and failure.
Under the protected sources' trusted/cooperative writer premise, the monotonic
selection binding rejects A-to-B-to-A and establishes a coherent point-in-time
cut at P1. It does not hold a selection lock or promise currentness after return.
The existing per-Realm admission selection coordinator cannot substitute for
this check: the account-wide selection head does not join that lock domain.

A successful result has exactly nine fields: `status: 'snapshot'`,
`operatorIdentity`, `operatorGeneration`, `localRealmId`, `authorityEpoch`,
`policyEpoch`, `selectionStorageSha256`, `policyStorageSha256`, and the verified
frozen `policy`. Missing or cleared selection returns exactly
`{ status: 'unavailable', reasonCode: 'selection-unavailable' }` without policy
I/O. Missing policy returns the analogous `policy-unavailable` result only
after the final S1 assertion. Failed joins and source failures expose fixed
diagnostics, not backend errors. No result contains a writer, storage view,
source handle, profile, path, inferred `operatorPartitionId`, or fabricated
`lifecycleGeneration`. This is private snapshot evidence, not a B4A snapshot,
B4F port, live subscription, authority receipt, or lease. (Sources:
`webgpu-os/kernel/realm/RealmLocalOperatorSnapshotSource.js`;
`webgpu-os/kernel/OperatorContext.js`;
`webgpu-os/kernel/realm/RealmAdmissionSelectionCoordinator.js`.)

Piece 9 now has a separate reserved-generation prerequisite,
`RealmLifecycleGenerationHeadStorage`. It is not `lifecyclePort@1` and does not
make the highest reserved generation a current or retired lifecycle. Its exact
factory accepts `{ storageView, appId }`, snapshots the bounded app ID, and
requires the captured account's genuine protected
`virtual-realm-lifecycle-generation-v1` service view. The closed service admits
only `/generations/<SHA-256(appId)>.json`, at 4,096 bytes, with no control delete,
directory listing, or content namespace. The retained head is per
`(operatorIdentity, appId)`, not per Realm, runtime profile, window, or transient
operator generation. A fresh current scope for the same account does not reset
it. The persisted exact six fields are `format`, `version`, `operatorIdentity`,
`appId`, `lifecycleGeneration`, and `previousStorageSha256`; decoding verifies
the account and app binding independently of the path hash.

The source exposes exactly frozen `{ readCurrent, allocateNext }`. Requests
are exact frozen `{ signal }` and `{ expected, signal }`; `expected` is null
for observed absence or the exact frozen `{ lifecycleGeneration,
exactStorageSha256 }` predecessor. `readCurrent` returns only `status`,
`lifecycleGeneration`, and `exactStorageSha256`: missing is `missing`, `0`, null;
present is `generation`, a positive canonical uint64, and its exact storage
SHA. A successful allocation returns `{ status: 'written', current }` after
protected CAS, receipt validation, and exact readback. Every successful
allocation advances by one. There is no unchanged allocation, caller-selected
value, reset, delete, liveness assertion, or retirement method. Maximum uint64
rejects before dispatch. The shared transaction helper now also accepts zero
domain input fields; all fixed-hook, exact-request, and recovery rules remain.

Only a confirmed allocation result may reserve a generation for its caller.
A read is never an allocation receipt, including during recovery. A dispatched
write with uncertain completion may have consumed a generation; after a fresh
recovery read the next attempt reserves a **new** value. Never issue the value
merely observed in the head. Concurrent writers use the existing cooperative
same-origin Web Locks/CAS boundary, not an external-process CAS claim. Storage
is retained OPFS: source reconstruction does not reset it, but hostile native
storage writes, browser-data deletion, rollback, eviction, or a restored old
profile are not prevented by this source. Full lifecycle admission must not
silently treat lost trusted lineage as a proven new incarnation.

Piece 9 also includes the kernel-only `RealmLifecycleSessionAuthority`. Its
exact factory accepts `{ operatorContext, generationStorageView, appId,
workSignal, teardownSignal }`. It captures the real active `OperatorContext`,
checks the genuine generation service view's account/generation, and requires
two distinct live native AbortSignals. It constructs the counter itself,
freshly reads its predecessor, and confirms a **new** allocation before issuing
a session. It accepts no caller-authored reservation, source port, generation,
or receipt. Both signal roots, the real operator, and the view are fenced on
success and failure around every asynchronous construction step. Failed
construction may consume a generation but publishes no session or handle;
retry constructs a fresh source and reserves a new value, never adopts a read.

The frozen session has exactly `lifecycleGeneration`, `retirementHandle`,
`assertCurrent`, `observeRetirement`, and `dispose`. Its ordinary assertion
accepts exact frozen `{ signal }` using the original work root and returns
`{ lifecycleGeneration, current: true }` only while this session remains live.
Real operator transition, genuine work/teardown abort, explicit disposal, or
retirement invalidates its work and detaches its owned listeners. Synthetic
abort events and caller event payloads are not authority. Separate live
sessions for the same account/app may coexist: a later high-water reservation
is neither global liveness supersession nor retirement of an earlier session.

The frozen single-method `retirementHandle.retire({ reason, signal })` requires
the authentic object receiver and the original live teardown root. Copies,
proxies, and unbound extracted calls reject. It cannot allocate, read a source,
change another generation, or register a participant. The issued-session
closure receives no storage view or counter. Consequently it can retire after
operator switch, work abort, or `dispose()` without reopening old-account
storage. `reason` is a validated bounded audit label, not cause evidence.

Before issuance the factory privately prepares the SHA-256 content address of
one bounded canonical terminal record with exactly eight fields: `format:
'particle-realms.lifecycle-retirement-receipt'`, `version: 1`,
`operatorIdentity`, `operatorGeneration`, `appId`, `lifecycleGeneration`,
`allocationStorageSha256`, and `retired: true`. The bound is 4,096 bytes and
the digest uses `sha256:<64 lowercase hex>`. Preparation is not retirement.
The digest never escapes until the synchronous, no-await, storage-free
retirement transition has ended this generation's ordinary authority. Every
valid repeat returns the same frozen `{ lifecycleGeneration, retired: true,
lifecycleRetirementReceiptDigest }`, regardless of the audit label.

The trusted, exact-session observer accepts frozen `{ signal }` through the
same teardown root. Before retirement it returns the exact triple with
`retired: false` and a null digest; afterward it returns the same terminal
receipt. Work invalidation and `dispose()` are not terminal evidence.
`dispose()` takes no arguments, returns true once then false, and leaves only
the exact teardown capability/observer usable until that root aborts. No method
accepts a caller's digest as retirement proof. Internal consumers must use the
genuine bound observer, not a structurally similar result or copied digest.

Only the counter has a normative persistence requirement at this boundary.
This session's handles and terminal state are intentionally process-local;
reopen cannot reconstruct an old handle, infer retirement from the high-water
mark, or prove orphan/resource cleanup. Durable activation, checkpoint,
handoff, and pin reconciliation remain required and must treat absent terminal
observations as unavailable/recovery-pending. A retirement receipt proves
generation-authority termination, not completion of subsequent resource cleanup.
No general post-switch storage bypass or persisted retirement ledger is added.

This is not yet [`lifecyclePort@1`](m2a-runtime-composition.md#lifecycleport1).
The separately versioned host-attempt binding now captures Entry's real roots
without widening that allocation wire or the frozen dependency record. A genuine
lifecycle port must consume the captured roots, authenticate process-owner/participant registration, preserve queued
non-reentrant intents and same-generation suspend/resume, and connect exact
retirement observations to the genuine owners. Those integration and restart
reconciliation gates remain open; no provider is registered. (Sources:
`webgpu-os/kernel/realm/RealmLifecycleSessionAuthority.js`;
`webgpu-os/kernel/realm/RealmLifecycleGenerationHeadStorage.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmOsLifecycleAdapter.js`;
`webgpu-os/apps/the-virtual-realm/security/RealmLifecycleGenerationGuard.js`.)

The approved additive host route preserves its earlier exact lease shapes. Legacy leases stay
`{ dependencies, close }`. An explicit version-2 lease is exactly frozen
`{ leaseVersion: 2, dependencies, attemptBinding, close }`; mixed, inferred,
unknown-field, mutable, or accessor-bearing shapes are not upgraded. Registry
rejection uses the existing retryable cleanup quarantine. Its v2 public lease
preserves the binding's receiver identity while snapshotting dependencies as
before. Desktop forwards only that binding in the separate own data field
`virtualRealmRuntimeAttemptBinding`. Factory validates it and passes it as
Entry's optional second argument. An absent field preserves v1 behavior;
inherited, accessor, or explicitly undefined injection is rejected. The original
sixteen dependency keys, `lifecyclePort@1`, and both frozen catalogs are unchanged.

The zero-option kernel `createRealmRuntimeAttemptBinding()` returns exactly
frozen `{ binding, captureAttempt, close }`. Only `binding` crosses to Entry; the
trusted host retains the other two closures. The exact frozen binding is
`{ portName: 'realmRuntimeAttemptBinding', version: 1, bindAttempt }`.
`bindAttempt` synchronously accepts exactly frozen
`{ constructionSignal, workSignal, teardownSignal }`, containing three distinct,
live native AbortSignals, and returns exactly frozen `{ bound: true }`. It
snapshots root identities, not controllers, account labels, or generations.
Entry captures the method and receiver privately, invokes once inside its
existing startup failure boundary before inspection, validates the synchronous
receipt, and rechecks root liveness before inspection can run. This is capture,
not allocation: startup still proceeds through inspection, operator snapshot,
the existing lifecycle allocation call, generation guard, process owner, and
participant registration. No generation is reserved eagerly by the hook.

At the existing allocation call, a genuine host implementation can privately
call `captureAttempt(Object.freeze({ signal }))` using that attempt's exact
construction root. Capture also requires its work and teardown roots still
live. The host must independently authenticate the operator, reserve a new
confirmed generation, and fence construction around asynchronous allocation;
neither captured roots nor a `{ bound: true }` receipt supplies those proofs.
An identical live rebind is idempotent. Another attempt cannot replace it until
the previous teardown root genuinely aborts, and all three replacement roots
must be new, even across roles. Weak membership prevents reuse without retaining
old roots strongly. Synthetic abort events and shadow `aborted` properties do
not change native liveness. Reentrant record inspection cannot reopen a closed
controller. `close()` is synchronous and idempotent, returning frozen
`{ closed: true }`, but refuses a live teardown root; it never aborts roots to
manufacture successful cleanup. Closure proves only release of this binding,
not resource cleanup, owner retirement, pin release, or durable recovery.

Promise and arbitrary thenable receipts are invalid because binding is
synchronous. Rejection from a standard native Promise is consumed through
pinned native methods and guarded constructor/species descriptors without
reading caller `then` or `catch`. Exotic Promise constructors/species are not
assimilated. This and the native-root checks assume trusted host intrinsics;
they do not establish hostile shared-origin isolation or cross-realm transport.
No controller is exposed by the app binding, no full provider is registered,
and no Operations View, camera, or first frame is enabled. The host rendezvous
remains within flat piece 9, not an eleventh piece. (Sources:
`webgpu-os/kernel/realm/RealmRuntimeAttemptBinding.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeValidationPrimitives.js`;
`webgpu-os/kernel/AppRuntimeCompositionRegistry.js`;
`webgpu-os/shell/Desktop.js`; `webgpu-os/apps/the-virtual-realm/factory.js`;
`webgpu-os/apps/the-virtual-realm/VirtualRealmEntry.js`.)

The next approved continuation adds an explicit version-3 lease, exactly frozen
`{ leaseVersion: 3, dependencies, attemptBinding, hostLifecycle, close }`.
It preserves both earlier lease projections, all sixteen app dependencies,
the existing attempt binding, and Entry's startup order. Version 3 is the
host-composition lease version, not a new dependency catalog. A version-2 lease
cannot acquire the channel by appending an extra field. Invalid v3 leases use
the existing raw-close quarantine; no accepted wrapper is published before
dependency, attempt-binding, and channel validation succeeds.

`createRealmRuntimeHostLifecycleChannel(source)` is an import-inert kernel
transport constructor. It accepts an exact frozen five-field source:
`{ portName: 'realmRuntimeHostLifecycle', version: 1, setSuspended, requestClose, notifyDeviceLost }`.
The source's own enumerable data methods are captured once and invoked with
their original receiver. Accessors, inherited fields, extra strings or symbols,
mutable records, and unknown discriminators are rejected. Its output is exactly
frozen `{ channel, retire }`; the registry keeps `retire` private and supplies
only the wrapped channel to Desktop.

The three requests are exact frozen records. `setSuspended` accepts
`{ suspended: boolean }`; `requestClose` accepts `{ reason }`, a canonical
bounded runtime identifier of at most 256 characters; `notifyDeviceLost` accepts
`{ deviceGeneration }`, a positive safe integer. These are bounded host
notifications, not credentials, generation allocations, or action grants.
Caller-controlled reasons, errors, and receipt data do not escape validation.
Failures use fixed frozen `VR_M2DB4H_HOST_LIFECYCLE_*` errors without a raw cause.

Source callbacks are synchronous enqueue/accept operations and must return
exactly frozen `{ accepted: true }`. They must not return or await participant
delivery, Entry shutdown, lease close, or registry destruction. The host-facing
methods return owned Promises, publish each pending operation before any source
callback can reenter, and invoke the captured source in a later microtask.
Invocation order follows enqueue order. At most 64 notifications may be pending;
the next call fails before enqueue and settled calls release capacity. Returned
Promises and arbitrary thenables are invalid receipts, never assimilated.
Standard native rejected Promises, whether returned or thrown, are consumed
using the existing guarded native rejection helper without reading arbitrary
`then` or `catch` properties. This assumes trusted host intrinsics and is not
hostile shared-origin isolation.

`retire()` takes no arguments, synchronously fences new and queued dispatch,
and returns one stable Promise resolving to exactly frozen `{ retired: true }`
after the transport's already-owned invocations settle. It does not call raw
provider cleanup or abort roots. The registry fences at lease-close entry and
at destruction entry, even while another opener is held; it then retires owned
notifications before invoking the captured raw close. Raw cleanup failure keeps
the lease retryable and the channel permanently fenced. Late opener completion
after cancellation or destruction is retired before handoff. A source that
returns its own retirement or lease-close Promise is rejected without creating
a self-drain dependency cycle.

Desktop keeps each v3 channel in a module-private WeakMap keyed by the exact
process entry and associated native mount root. It forwards the existing
attempt binding for v2 and v3, but never exposes the channel on the app context,
entry fields, or `cleanup.app`. Per-window minimization, document suspension,
and existing GPU-recovery pause routes use the private channel. Suspension
delivery is serialized and coalesces to the latest desired state; a failed
unchanged notification waits for an explicit retry instead of spinning.
Exact-record checks prevent an old mount from notifying a replacement mount.

Close notification is coalesced for the captured old host, including a window
closed or a process force-terminated while its factory mount is still held.
Forced termination keeps its existing nonblocking shell behavior and cannot
claim that the late factory cleanup has completed. Graceful cleanup still awaits the
real delegate cleanup before raw lease close; notification failure logs a fixed
safe warning and cannot skip that cleanup. Acknowledgement is not proof that
the application stopped. Device-loss notification requires the kernel's real
`GpuRuntimeCoordinator` to report the matching logical generation as lost or
recovering through its pinned getters. A ready-state generic event cannot
authorize that notification. Dedupe commits only after acceptance, so rejected
delivery can retry. This checks logical coordinator state under trusted kernel
construction, not physical GPU cause, kernel isolation, or authenticity of all
legacy generic recovery behavior. Previously accepted queued notifications
remain historical notifications on the captured old channel, never authority
over a replacement mount.

The v3 transport continuation remains inside flat piece 9. It supplies host notification
transport; the participant-source continuation is specified below. `OperatorContext` participant
registration is boot-only; a per-app source cannot register there after boot.
Its transition invalidates the ordinary scope before change notification, so
terminal delivery must retain the authentic registration identity while
rejecting new work. `RealmOsLifecycleAdapter` still accepts its existing mutable
exact eight-field registration request. Its queued callbacks and Entry's stop
intent are not teardown-completion receipts. The participant source must authenticate
the genuine private process-owner identity, retain original callbacks/roots,
and preserve these distinctions without changing the frozen wires. Activation-
authorized child ownership, operator-switch drain, full provider registration,
restart reconciliation, renderer suspension, and a physical city remain open.
(Sources: `webgpu-os/kernel/realm/RealmRuntimeHostLifecycleChannel.js`;
`webgpu-os/kernel/AppRuntimeCompositionRegistry.js`; `webgpu-os/shell/Desktop.js`;
`webgpu-os/kernel/GpuRuntimeCoordinator.js`; `webgpu-os/kernel/OperatorContext.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmOsLifecycleAdapter.js`;
`webgpu-os/apps/the-virtual-realm/VirtualRealmEntry.js`.)

The kernel-private `RealmLifecycleParticipantAuthority` now consumes the genuine
identity and host-transport prerequisites. Its exact frozen factory input is
`{ identityAuthority }`, not an arbitrary `authenticate` method or a separately
supplied equal-label operator context. Its exact frozen result is
`{ registerParticipant, hostLifecycle, close }`. This is a participant source,
not a full `lifecyclePort@1`, process-owner port, or installed provider.

Two separate module-private lookup paths establish provenance without changing
existing public shapes. `captureRealmLifecycleAllocationParticipantSource`
requires the genuine allocation source and returns only
`{ subscribeOperatorChange }`, tied to its original captured coordinator/scope.
`captureRealmProcessOwnerParticipantSource` requires the genuine identity source
and returns only `{ capture, subscribeOperatorChange }`. Copies, proxies and
caller-authored methods cannot pass either WeakMap lookup. Existing allocation6,
owner-source1, owner-binding6, identity-source3, and identity-handle2 remain intact.

Private identity capture accepts exactly frozen `{ appId, ownerId, signal }`
using the original native work root. It returns a stable frozen binding
`{ identity, assertCurrent, assertRetained }`. `identity` is the original frozen
five-field observation; copying it confers no authority. Both assertion methods
take no arguments. `assertCurrent` validates the real captured session/scope and
rechecks retained ownership after trusted currentness callbacks.
`assertRetained` checks the original unreleased owner and open identity source
without storage I/O or ordinary work-root currentness. It survives work abort or
operator invalidation, but not owner release, source close, or replacement.

`registerParticipant` preserves the adapter's existing mutable eight-field
request: `{ appId, ownerId, onSuspend, onResume, onClose, onOperatorChange,
onDeviceLost, signal }`. It snapshots own enumerable data descriptors before
validation, rejecting accessors, missing/extra/symbol fields and inherited
requirements. Each callback must be callable. Registration synchronously returns
exactly frozen `{ participantId, dispose }`, so the existing adapter can await
it without changing its wire. Opaque participant identifiers use native secure
UUIDs and carry no account labels. A final currentness check is followed by
closed/terminal/competing-registration checks immediately before the no-callback
claim/publication interval. One stable genuine owner binding can issue one
participant across sources. Identical live registration repeats coalesce;
callback replacement and re-registration after disposal are rejected.

The source's `hostLifecycle` is the existing v3 synchronous acceptance wire,
not a second wrapped channel. Every valid call returns exactly frozen
`{ accepted: true }`. It retains the latest suspension state and the first
terminal cause in constant space. At most one suspension invocation and one
terminal invocation are pending per participant. Suspension received before
registration is replayed after successful publication; queued ordinary delivery
requires genuine current owner/work authority. Close, device loss or actual
operator invalidation received before registration latches a terminal source
and prevents later registration. Once registered, the first terminal cause wins
and schedules only its originally captured callback; later terminal calls do
not repeat it. Queued suspension is fenced by terminal state or disposal.

Callbacks run in later microtasks with their original receiver and zero
arguments. They must synchronously return `undefined`, matching the real
`RealmOsLifecycleAdapter` enqueue wrappers. Source-returned promises and arbitrary
thenables are not awaited or assimilated, including a callback that returns its
own participant-disposal Promise. Standard native rejected Promises, returned or
thrown, use the guarded rejection sink. Fixed warning messages report callback
rejection without leaking errors, owner identifiers, roots or event payloads;
logging failure cannot break delivery or cleanup. One callback failure does not
poison independent later notifications. Acceptance still proves only enqueueing,
not callback success, Entry shutdown, or actual renderer suspension.

The original coordinator subscription accepts only exactly frozen
`{ onOperatorChange }` and returns frozen `{ dispose }`. It uses pinned original
`OperatorContext` methods, ignores event payloads, and emits one zero-argument
notification only after the actual captured scope becomes stale. Synthetic
unchanged events cannot authorize invalidation. Setup rechecks currentness and
closure and removes a failed subscription. Subscription disposal is synchronous
and idempotent; it proves only listener disposal. Neither this subscription nor
the participant source makes the operator transition await Realm cleanup.

The authentic participant's zero-argument, receiver-gated `dispose()` immediately
fences delivery and shares one Promise that awaits only source-owned invocation
settlement. It then drops callback/receiver/binding references and returns frozen
`{ participantId, disposed: true }`. It remains usable after operator invalidation
or source-owner release, but cannot retire an identity or clean up resources.
The source's zero-argument `close()` refuses an undisposed participant or pending
disposal, fences closure before unsubscribing, and returns stable frozen
`{ closed: true }`. Reentrant unsubscribe cannot publish a new registration.
No new construction, work or teardown root is manufactured or aborted.

This implements genuine participant notification within piece 9. The lifecycle
composition below supplies its separate source cleanup owner. Boot-owned
operator-switch drain is supplied by the later host cleanup continuation;
activation-authorized process children,
resource telemetry, recovery and full-provider/backend isolation remain unfinished. The existing
adapter's queued stop intent is still not a teardown receipt. No renderer pause,
physical frame, first-person controller, Operations View or minimap is accepted.
(Sources: `webgpu-os/kernel/realm/RealmLifecycleParticipantAuthority.js`;
`webgpu-os/kernel/realm/RealmProcessOwnerIdentityAuthority.js`;
`webgpu-os/kernel/realm/RealmLifecycleAllocationAuthority.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmOsLifecycleAdapter.js`;
`webgpu-os/kernel/OperatorContext.js`.)

The kernel-private `RealmLifecyclePortComposition` now owns the genuine
allocation, identity and participant sources together. Its exact frozen input
is `{ operatorContext, generationStorageView, appId }`. It constructs those
sources in dependency order, with no generation reservation or storage I/O.
The participant source alone acquires its original-context notification
subscription. Failed construction closes successfully created sources in
reverse order; no caller receives an incomplete composition.

The exact frozen result is `{ lifecyclePort, attemptBinding, hostLifecycle,
ownerIdentity, observeRetirement, close }`. The application receives only the
existing frozen `realmLifecycle@1` port: `{ portName, version,
allocateGeneration, assertGenerationCurrent, registerParticipant,
retireGeneration }`. Its four methods reuse the genuine sources and preserve
the existing mutable request wires and authentic returned handles. The
sixteen-dependency record, Entry, B3, and v1/v2/v3 lease shapes do not change.

`attemptBinding` is an exact same-wire three-field forwarding capability. Its
original controller still validates and retains Entry's native roots. The
forwarder stops new bindings once composition closure starts, so a later fresh
teardown root cannot reopen an unfinished close. `hostLifecycle` remains the
participant's raw five-field source for the already approved v3 wrapper, never
another app dependency. Both suspension and terminal source notifications remain
available while closure is blocked on a live participant; the participant's
successful source close rejects subsequent notifications.

The host-private `ownerIdentity` facade exposes only `{ acquire, authenticate }`.
It delegates to the genuine private identity authority under the composition's
intake fence. It is not a genuine source accepted by the private identity lookup
and is not `processOwnerPort@1`. Returned authentic `{ ownerId, release }` handles
retain their original receiver-gated cleanup operation. Host-private
`observeRetirement` exposes only the existing exact-handle, live-teardown
observation. Neither helper appears on the app lifecycle port.

Every synchronous forwarded operation guards against reentrant close. A close
attempt made from request reflection or trusted currentness hooks fails with
`OPERATION_PENDING` before changing composition state; the outer operation can
still return its authentic handle. The allocation Promise is returned unchanged,
not wrapped or adopted. An allocation already pending when close begins can
therefore still deliver its genuine retirement handle, which remains usable for
cleanup. Closure cannot convert a successful issuance into an inaccessible
post-call error.

The zero-argument synchronous `close()` first fences new attempts, allocation,
currentness, registration, and owner acquisition/authentication. It then closes
participant, identity, and allocation sources in that order. A phase advances
only after its own source successfully closes. An unmet prerequisite throws a
fixed `CLEANUP_REQUIRED` error and retains completed phases and the outstanding
source ownership for retry; recursive close during this work is rejected with
`CLOSE_IN_PROGRESS`. Retirement and observation remain callable until allocation
closure. Existing participant disposal and authentic owner release handles stay
available throughout incomplete closure. Close never performs these app-owned
operations, aborts roots, or awaits Entry/adapter callbacks on their behalf.

Successful close returns one stable frozen `{ closed: true }` receipt. It proves
only that the three owned source leases closed. Fixed, guarded lifecycle debug
events contain no operator, owner, signal, storage, or callback payloads. This
composition completes the genuine four-method lifecycle port within flat piece
9, not full B4H. The separate host cleanup continuation supplies boot-owned
operator-switch drain. Activation-authorized process children,
resource telemetry, durable reconciliation,
full-provider/backend isolation, and visible-city acceptance remain unfinished.
The following diagnostics continuation supplies only the clock/logger sources.
(Sources: `webgpu-os/kernel/realm/RealmLifecyclePortComposition.js`;
`webgpu-os/kernel/realm/RealmLifecycleAllocationAuthority.js`;
`webgpu-os/kernel/realm/RealmProcessOwnerIdentityAuthority.js`;
`webgpu-os/kernel/realm/RealmLifecycleParticipantAuthority.js`.)

The shell-private `RealmOperatorMountDrain` supplies the next piece-9 boundary:
the existing boot-owned `desktop-shell` participant now waits for actual
Virtual Realm mount cleanup through `Desktop.drainOperator()`. OperatorContext
already revokes the old scope and awaits participant drains before activating,
binding, or resuming a replacement profile. No new participant, registration
window, coordinator phase, or app lifecycle wire is introduced.

Desktop retains one private record per exact process entry only for the
terminal `os.the-virtual-realm` / `app.the-virtual-realm` factory path. It does
so before the before-mount hook, composition open, or factory await. These
records retain original closure references, not a later app-ID lookup. Multiple
same-app attempts therefore remain independently owned after forced removal
and relaunch. No registry, cleanup ledger, or controller is placed on the app,
its dependency record, the mount context, or the Entry options.

Drain publishes one shared attempt before requesting original mount
cancellation. Early cancellation starts available cleanup but is not proof of
completion. The drain waits the entire mount continuation, including a held
readiness result, then awaits the original provisional handoff's actual
cleanup. The existing factory wrapper completes its delegate before closing
the composition lease. Finally, the drain retires work associated with the
original registry-open request. Removing a window, an empty process table,
a host notification acknowledgement, or a force-close timeout proves none of
these steps. Generic-app forced close remains bounded and UI removal remains
nonblocking; a retained Realm obligation still blocks operator admission.

The kernel-only `AppRuntimeCompositionRegistry.retireOpen(originalRequest)`
authenticates the exact registry and original object through private WeakMaps,
without reflecting request properties. Equal-looking copies, foreign objects,
and wrappers never passed to `open` cannot select another request's cleanup.
Every original object actually attempted through `open` has cleanup ownership
before validation or destruction rejection. Invalid, unsupported, or already
destroyed-registry attempts retain cleanup-only identity without invoking
an opener or acquiring new runtime authority. Fresh rejected attempts have
empty cleanup; a reused request retains any earlier handles. Their normal open result or
error is preserved; retirement is not admission.

Retirement synchronously fences further opens for that request, waits all its
pending opens, then closes every remaining active or quarantined handle with
the fixed `composition-open-retired` reason. Final handoff checks the fence
after the signal read, so callback reentry cannot return a retired lease. The
registry reuses its existing retirement handles; per-request, explicit lease,
and whole-registry cleanup share those handles. A failed handle stays owned
for retry. Success shares one Promise and frozen `{ retired: true }` receipt.
Unknown identities and failed cleanup use fixed errors without provider detail.
No operator drain destroys the registry or consumes its single opener slot.

The mount record is removed only after mount settlement, actual cleanup, and
registry retirement succeed. A failure becomes the fixed
`REALM_OPERATOR_DRAIN_CLEANUP_REQUIRED` error, reaches the existing coordinator's
participant-drain failure path, and remains retained after process removal.
Its retry preserves completed delegate/lease work. Supersession, lock, recovery,
concurrent drains, and later operator mounts use the same ownership boundary.
Guarded debug events report retention, cancellation, cleanup failure, and
completion without carrying app data, operator identifiers, or source errors.

This accepts shell/registry cleanup ownership with real coordinator and
Desktop transport. The browser fixtures explicitly control delegate and lease
cleanup; they are not a complete provider or physical-resource certificate.
The future provider must make its cleanup accurately represent Entry stop and
reverse source closure, and must still prove every awaited boundary end to end.
M1C admission, full process-child authority, provider/backend isolation,
reconciliation, genuine resource telemetry, and visible-world acceptance
remain separate gates. The B4H ledger stays at ten flat pieces.
(Sources: `webgpu-os/shell/desktop/RealmOperatorMountDrain.js`;
`webgpu-os/shell/Desktop.js`; `webgpu-os/kernel/AppRuntimeCompositionRegistry.js`;
`webgpu-os/kernel/OperatorContext.js`; `webgpu-os/kernel/KernelBootstrap.js`.)

The diagnostics continuation adds two separate kernel-owned modules within
piece 9, without another nested milestone or provider registration:
`RealmRuntimeDiagnosticsSource` owns revocable clock/logger facades;
`RealmBrowserRuntimeDiagnosticsSource` binds them to native browser measurement
and the existing OS logger. Their exact frozen result is `{ clock, logger,
close }`. The clock preserves its four-key `realmRuntimeClock@1` wire and the
logger its six-key `realmRuntimeLogger@1` wire. No app dependency key, Entry
option, lifecycle lease version, or host-attempt binding changes.

The low-level factory requires exactly one frozen `{ monotonicSource, logSink }`
record. Each source is an exact frozen one-method data record, `{ now }` or
`{ write }`. It captures each function and original receiver once. Construction
invokes neither supplied method; only a fixed console breadcrumb is emitted.
These callbacks are a trusted-host seam, not authenticated operator acquisition
or evidence of backend isolation. The browser factory accepts no arguments and
captures native `Performance.prototype.now` with its performance receiver and
the existing `OsLogger.prototype._write` with `osLogger`. Missing sources reject;
there is no wall-clock/network-clock measurement fallback, timer, new log store,
or app fallback. OsLogger retains its existing wall-time entry timestamps.

With the browser adapter, `monotonicNow()` returns genuine finite, nonnegative
milliseconds, retaining
fractional precision and permitting equal samples. Backward or invalid samples
reject without replacing the last good value. Callback reentry and closure
during a sample cannot return an old owner's measurement. Native source errors
become fixed frozen diagnostic errors without raw cause details.
`logicalTick()` independently advances from `"1"` through the uint64 maximum,
`"18446744073709551615"`, as canonical decimal text. Exhaustion rejects before
increment and cannot wrap or reset. This counter is source-instance-local
diagnostic ordering, intended to be mount-owned by the future provider. It is
not an activation/signature clock, durable epoch, authority lineage,
simulation clock, or distributed causal clock. Neither method accepts arguments.

The logger accepts only 21 existing event names: twelve from
`REALM_RUNTIME_EVENTS`, five M2C load/ECS events, and four B3 ownership/composition
events. All four existing levels are retained. Dispatch creates an exact frozen
`{ level, eventName, metadata }` record. The private projection inspects only the
following thirteen own enumerable data descriptors, in this fixed order, then
reuses `projectLogMetadata` for the OS's bounded scalar projection:

| Runtime input | OS metadata output | Accepted value |
| --- | --- | --- |
| `state` | `state` | Existing lifecycle state |
| `priorState` | `phase` | Existing lifecycle state |
| `nextState` | `state` | Existing lifecycle state |
| `admissionStatus` | `status` | Existing lifecycle state |
| `failureClass` | `causeCode` | One of three reviewed failure classes |
| `reason` | `reason` | One of thirteen reviewed reason codes |
| `reasonCode` | `reason` | One of thirteen reviewed reason codes |
| `sequence` | `sequence` | Nonnegative safe integer |
| `retired` | `ok` | Boolean |
| `verifiedResourceCount` | `count` | Nonnegative safe integer |
| `verifiedGraphBytes` | `bytes` | Nonnegative safe integer |
| `staticEntityCount` | `itemCount` | Nonnegative safe integer |
| `presentationSlotCount` | `count` | Nonnegative safe integer |

For overlapping outputs, a later accepted value takes precedence. Absent
metadata yields an empty frozen record; plain records with either ordinary or
null prototypes are accepted. Invalid metadata containers drop the event.
Unknown fields, getters, symbols, nested values, arbitrary strings, identities,
source objects, paths, hashes, and raw errors never reach the sink. A fixed
descriptor walk avoids enumerating attacker-controlled key collections.
This diagnostic projection is deliberately lossy and is not resource telemetry,
an audit ledger, or full runtime evidence.

Logging contains reflection errors, sink exceptions, native rejected Promises,
and synchronous logging reentry. Arbitrary thenables are not assimilated.
Logger methods always return `undefined`; a failed sink cannot interrupt the
existing runtime lifecycle. Fixed guarded console breadcrumbs report source
creation/closure and rejection classes without payloads. The browser adapter
uses the fixed OS source `os.the-virtual-realm`; existing OsLogger persistence
ownership is unchanged.

`close()` accepts no arguments, publishes terminal closure before clearing both
captured source references, and returns one stable frozen `{ closed: true }`
receipt. Later clock calls reject; later log calls do nothing. Close neither
flushes, clears, resets, nor shuts down the shared OS logger. The future provider
must retain diagnostics until Entry stop and reverse-source teardown finish:
the existing lifecycle reads its clock directly during transitions. Closing
these facades early can interrupt transition recording. No provider installs
these sources in this continuation, and no telemetry, physical cleanup,
activation, or visible-world acceptance is claimed.
(Sources: `webgpu-os/kernel/realm/RealmRuntimeDiagnosticsSource.js`;
`webgpu-os/kernel/realm/RealmBrowserRuntimeDiagnosticsSource.js`;
`webgpu-os/kernel/OsLogger.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeLifecycle.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeDependencyContract.js`.)

The frame-accounting continuation supplies a separate, exact-producer source
inside the existing `GpuFrameCoordinator`. It does not wrap global statistics
as Realm owner telemetry. The bounded source audit establishes these distinctions:

| Existing source | What it actually records | Required boundary before Realm owner use |
| --- | --- | --- |
| `GpuFrameCoordinator` | Successful frame callbacks, skips, deferrals, errors, normalized callback CPU intervals, and reported/default submissions and GPU timings | Capture the exact producer record; then bind it to the genuine Realm owner in the future provider. The exact-record observer is implemented in this continuation. |
| `VRAMTracker` | Requested buffer bytes, estimated texture/surface bytes, and pipeline/shader creation counters | Private exact-mount scopes isolate broker-routed buffers, textures and creation counters. A separate original-manager-surface scope attributes canvas reservations; it is not yet joined to a GPU mount or Realm. Compat surfaces and other resource families remain outside this source. App-wide quota totals retain their existing meaning. |
| `GpuDeviceBroker` | Exact mount authority during allocation and command admission; rolling submission admission counters | Original-lease capture now preserves private allocation attribution. Binding that GPU lease to the genuine Realm owner remains future provider work. Admission counters do not establish native submission success or queue completion. |
| `ResourceManager.getStats()` | Shared host/GPU/scheduler and frame statistics | Do not relabel aggregate statistics as one Realm process's allocations. |
| `NaviResourceService` | Signed task/branch reservations and admitted caller-supplied consumption/settlement vectors | Leave Navi accounting unchanged; it is not a Virtual Realm process measurement source. |

Requested bytes are not physical VRAM. Tracker removal is not native-object
destruction proof: the broker's tracked destroy wrapper releases accounting
before invoking native destruction. Pipeline/shader counters are creation
accounting, not garbage-collection-aware live-object counts. Missing resource
families must remain unavailable, not become invented zero measurements.
(Sources: `webgpu-os/kernel/VRAMTracker.js`;
`webgpu-os/kernel/GpuDeviceBroker.js`;
`webgpu-os/kernel/GpuFrameCoordinator.js`;
`engine/core/ResourceManager.js`;
`webgpu-os/kernel/navi/NaviResourceService.js`.)

`captureGpuFrameProducerTelemetrySource(handle)` accepts only an original
handle returned by `GpuFrameCoordinator.registerProducer()`. A private WeakMap
joins the handle to its original record. Native map accessors are captured at
module initialization; later WeakMap prototype replacement cannot forge the
lookup or intercept its private map. Copies, proxies, revoked proxies, strings,
and matching public IDs cannot select a record. Capture invokes no clock,
callback, external timing provider, scheduler, or resource operation.

The exact frozen observer is `{ snapshot, close }`, with zero-argument methods.
`snapshot()` returns this eleven-field frozen projection:

| Field | Meaning |
| --- | --- |
| `sourceName`, `version` | Fixed `gpuFrameProducerAccounting`, `1` |
| `registered`, `generation` | Original registration state and GPU generation, not a Realm lifecycle generation |
| `frames` | Successful synchronous producer callbacks |
| `submissionsReported` | Successful callbacks unless their result has `submitted === false`; no actual queue-submission claim |
| `skipped`, `deferred`, `errors` | Original producer's coordinator counters |
| `cpuEncodeMs` | Normalized interval around callback execution using the coordinator clock |
| `gpuTimeReportedMs` | Normalized caller/external-provider GPU timing reports, not independently verified GPU timing |

Both timing records are frozen `{ sampleCount, last, average, max }` values over
at most the latest 60 samples, each normalized by the existing coordinator into
0 through 1,000 ms. `sampleCount` is the retained window size, not a lifetime
sample count. Empty histories have null `last`, `average`, and `max`; a valid
sample of zero remains zero. The last value comes from the actual history tail,
including after history replacement. Invalid counters, registration/generation,
sparse histories, or out-of-domain retained samples reject with fixed errors.
Identifiers, owner authorities, source objects, callbacks, and raw errors are
omitted. This is a bounded diagnostic projection, not a disposal certificate.

Legacy `handle.telemetry()` now also reads its original record, preserving its
existing output fields. It no longer looks up the current producer by owner and
surface names. A retained old handle therefore cannot observe a replacement
producer, even when the names match. The separate coordinator-wide keyed query
retains its existing behavior. Original-record observations survive unregister,
retired-cache eviction, and coordinator destruction; an in-flight callback's
final accounting still updates that same original record. `registered: false`
alone does not prove that the callback has finished.

Observer `close()` severs only that observer's reader and returns a stable
frozen `{ closed: true }` receipt. Later snapshots reject, while another observer
or the still-running producer remains unchanged. Holding the original handle
permits a new observation; closing one observer does not revoke that handle.
No producer is unregistered, no timer or log callback is invoked by observation,
and no resource or coordinator is closed. Existing bounded snapshots and fixed
failure codes provide diagnostics without adding observer-triggered work.
(Source: `webgpu-os/kernel/GpuFrameCoordinator.js`.)

Full `resourceTelemetryPort@1` remains unfinished. Its future begin operation
must join the genuine process-owner identity, lifecycle generation, original
work root, and genuinely attributed accounting sources. The exact-producer
handle alone does not establish that Realm binding. A separate retained cleanup
binding is essential: Entry closes telemetry after work abort and generation
retirement, but still attempts process-owner release if telemetry close fails.
Retry must therefore remain possible after owner release; live authentication
or participant `assertRetained()` cannot authorize that cleanup retry. The
retained binding now authenticates the original teardown authority through the
private process-owner telemetry prerequisite described in this section. It
never accepts a matching string or copied receipt. Keep this source mapping and its
remaining work within flat piece 9; activation children still depend on piece 4.
(Sources: `webgpu-os/apps/the-virtual-realm/VirtualRealmEntry.js`;
`webgpu-os/kernel/realm/RealmProcessOwnerIdentityAuthority.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`.)

The frame-source gate passes **28/28 browser cases**. Ten freshly rerun
adjacent suites add diagnostics32, runtime30, Entry25, production composition11,
factory11, attempt binding32, operator transition18, original-open retirement14,
lifecycle composition37, and Desktop terminal transport17: **255/255 distinct
browser cases**, with zero final failures or skips. The sweep first exposed an
outdated shared Desktop fixture that bypassed construction and omitted the new
Navi body's inert constructor state. Restoring those three existing defaults
in the fixture makes operator-transition18 and terminal-transport17 pass with
no console errors; production Desktop and Navi remain unchanged.

The scoped Python group passes **244/244**, including fifteen new source and
confinement checks. A separate read-only HTTP probe replaces only the served
legacy telemetry lookup with its old owner/surface-keyed behavior: exactly
three cases fail (replacement producer, retired-cache eviction, and destroyed
coordinator), while the other25 pass. Production source bytes are unchanged by
the probe. An earlier probe failed at module startup and supplies no mutation
evidence. Source review also hardened private WeakMap intrinsics and dense
timing-history checks. The import-free source adds no module dependency;
Entry106, B3-composition48, dependency16, and both ten-piece ledgers remain
unchanged. No full OS bundle, broad all-app frame audit, or documentation
generator was run; the excluded application was not imported or inspected.
(Sources: `tests/virtual-realm/m2-frame-producer-telemetry-source.test.js`;
`tests/virtual-realm/test_m2db4h_frame_producer_telemetry_source.py`;
`tests/virtual-realm/m2-desktop-terminal-factory.test.js`.)

The mount-allocation continuation adds the second bounded accounting source.
`captureGpuOwnerAllocationTelemetrySource(ownerAuthority)` accepts exactly one
original opaque lease returned by `GpuDeviceBroker.openOwner()`. Its private,
native-pinned WeakMap selects the original tracker scope without resolving the
current owner by app name. Capture never grants GPU admission, process-owner
identity, Realm authority or cleanup completion. Observation remains valid
after broker release because accepted resources can still be accounted then.

The exact frozen observer is `{ snapshot, close }`. Both methods take zero
arguments and remain bound when detached. Close affects only that capture,
returns a stable frozen `{ closed: true }`, and leaves sibling captures,
allocations and owner admission unchanged. A host getter closing the observer
during either snapshot check produces the fixed closed error, not a raw error
or a post-close projection. Snapshot returns exactly these eleven fields:

| Field | Retained accounting | Forgotten accounting |
| --- | --- | --- |
| `sourceName`, `version` | `gpuMountAllocationAccounting`, `1` | Same discriminators |
| `tracking` | `retained` | `forgotten` |
| `bufferRequestedBytes`, `bufferCount` | Outstanding scoped buffer records | Both `null` |
| `textureEstimatedBytes`, `textureCount` | Outstanding scoped texture records | Both `null` |
| `pipelineCreationCount`, `shaderCreationCount` | Scoped creation counters retained by GPU generation | Both `null` |
| `surfaceEstimatedBytes`, `otherResourceBytes` | Always `null`: not attributed here | Always `null` |

Each retained number is a nonnegative safe integer; invalid or overflowing
arithmetic rejects instead of producing an exact-looking unsafe total. Buffer
and texture scopes reference the same frozen allocation records used by the
existing ledger. Private generation counters attribute pipeline creation and
shader-cache misses, not live native objects. No owner identity, mount token,
allocation handle, descriptor, shader code or native object is published.

`createGpuMountAllocationAccounting()` is a tracker-side accounting seam, not
an authority factory. It mints a powerless opaque token for a genuine standard
tracker. The broker binds it privately to its genuine mount lease and supplies
it to existing buffer, texture, shader and synchronous/asynchronous pipeline
accounting. Public `listAllocations()` retains its five scalar fields, while
`getUsage()`, app/global quota admission and surface reserves stay app-wide.
Direct legacy tracker writes without a scope affect those totals but are never
guessed into one mount. Opening an empty scope creates no legacy app entry.

Release revokes GPU admission without subtracting accepted allocations. An old
resource's tracked destroy removes only its own mount's record. Generation
retirement removes that generation's requested records and creation counters;
surface reservations survive as before. `forget(appId)` invalidates every old
scope epoch, including a scope captured before its first allocation. Its six
numeric fields become unavailable, not zero. A later same-app entry or a still-
live async pipeline completion cannot revive that discarded accounting history.
Native destroy failure and a host object refusing a destroy wrapper retain
their existing accounting semantics; neither is misreported as disposal proof.

The source supports the unmodified standard tracker, not arbitrary subclass or
replacement writer instrumentation. It inspects ten writer method descriptors
without invoking writer accessors. An observed tracker/writer replacement makes
the source permanently unavailable; restoring the prior object does not revive
it. Allocation metadata is prepared before method lookup, so a self-restoring
writer getter cannot conceal an observed unsupported writer. Missing or failed
optional telemetry setup leaves ordinary mount admission intact. Mount identity
is published before the new host getter can re-enter, and completion verifies
that the same lease remains current. These checks do not establish same-origin
backend isolation or detect arbitrary unobserved host swap-and-restore activity.

The separate surface source described here now covers manager acquisition,
resize, recovery and release. The next work is genuine Realm-owner/source joining
using the original teardown validator retained through owner release. Unsupported
resource families need reviewed sources before becoming available; they cannot
be filled from app totals. The ten-piece ledger, dependency16 and v1/v2/v3
runtime leases remain unchanged. Full telemetry and the visible city are still
unaccepted.
(Sources: `webgpu-os/kernel/GpuDeviceBroker.js`;
`webgpu-os/kernel/VRAMTracker.js`;
`webgpu-os/kernel/SurfaceManager.js`;
`webgpu-os/kernel/realm/RealmProcessOwnerIdentityAuthority.js`;
`tests/virtual-realm/m2-gpu-mount-allocation-source.test.js`.)

The mount-allocation browser gate passes **36/36 cases** using the real broker
and tracker with an explicitly instrumented JavaScript device transport. It
does not acquire a physical WebGPU device. The exact scoped Python group passes
**263/263**, including nineteen new source/confinement checks. The final focused
gate also verifies metadata validation before writer lookup and preserves the
legacy texture methods' independent dispatch through one private helper. An isolated
read-only HTTP mutation omits the mount token only in served broker bytes and
produces **21 expected failures and 15 passes**; repository source is unchanged.
Broker and tracker closures are exactly nine and seven modules respectively,
limited to the source modules and shared math. Entry106, B3-composition48 and
dependency16 remain unchanged. No broad all-app runner, full OS bundle or
documentation generator is included in this acceptance.
(Sources: `tests/virtual-realm/m2-gpu-mount-allocation-source.test.js`;
`tests/virtual-realm/test_m2db4h_gpu_mount_allocation_source.py`.)

The fresh adjacent regression sweep passes frame-source28, diagnostics32,
runtime30, Entry25, production composition11, factory11, attempt binding32,
operator transition18, original-open retirement14, lifecycle composition37,
and Desktop terminal transport17. Together with mount-source36 this is
**291/291 distinct browser cases**, with zero final failures, skips or console
errors. Mount-source36 and Desktop17 were rerun after the final legacy texture
dispatch correction; the exact 25-file Python group was also rerun at that
final source revision and passed all 263 checks. These accounting/transport
results do not establish native GPU disposal or physical-device acceptance.
(Sources: `tests/virtual-realm/m2-gpu-mount-allocation-source.test.js`;
`tests/virtual-realm/m2-desktop-terminal-factory.test.js`;
`tests/virtual-realm/test_m2db4h_gpu_mount_allocation_source.py`.)

The third bounded accounting source is
`captureGpuSurfaceAllocationTelemetrySource(surfaceView)` in `SurfaceManager`.
Its exact one-argument capture accepts only the original six-field kernel
surface view. A private native-pinned WeakMap rejects copied views, proxies,
matching panel/app labels, canvas/context objects and distinct Realm surface
receipts without inspecting caller properties. Capture grants no mount,
process-owner or Realm authority. The public surface interface stays unchanged.

The frozen observer exposes detachable, zero-argument `snapshot` and `close`.
Close releases only that observer and returns a stable frozen `{ closed: true }`;
it does not release the surface or sibling observers. Tracker identity and
reentrant close are checked before and after projection. Snapshot has exactly
five fields:

| Field | Retained reservation | Forgotten attribution |
| --- | --- | --- |
| `sourceName`, `version` | `gpuSurfaceAllocationAccounting`, `1` | Same discriminators |
| `tracking` | `retained` | `forgotten` |
| `surfaceEstimatedBytes` | Nonnegative safe-integer estimate for this original reservation | `null` |
| `surfaceCount` | `1` while reserved; `0` after its scoped removal | `null` |

`createGpuSurfaceAllocationAccounting(tracker, appId, panelId)` binds a powerless
scope to the existing numeric surface ledger through a private side index.
The same scope updates its reservation on resize and recovery; there is no
app-total subtraction or second quota budget. Ordinary app/global totals,
surface reserves and public allocation listings keep their existing shapes.
The four surface writer pins (`trackSurface`, `untrackSurface`, `forget`,
`_entry`) share descriptor validation but remain separate from the ten mount
writer pins. Instrumenting only a surface writer does not disable mount11.

Scoped removal compares the original scope before deleting the numeric slot.
A foreign scope or legacy unscoped overwrite/delete permanently forgets displaced
attribution; an old resize, release or rollback cannot reclaim that slot.
Removing a never-charged original scope ends it at retained zero without deleting
another reservation. Host `forget` invalidates its epoch permanently, including
across later same-ID reuse. Observed tracker/writer replacement makes observation
unavailable. Original-backend mutations retain their scoped identity even then;
an attributed operation never falls back to a keyed mutation on another backend.
Custom or subclass trackers retain legacy behavior but cannot certify this source.

Manager acquisition, attachment, resize and recovery recheck original ownership
around host callbacks. Acquisition preserves its original device/generation
pair; stale publication cannot replace an existing surface. Old cleanup and
unpublished-candidate rollback do not resize, remove or unconfigure a canvas
already acquired by another surface. Recovery checks the surface set during
commit, fences recursive rollback, and restores only still-owned candidates.
Existing allocation, quota-denial, resize-failure and release diagnostics remain.
Optional accounting setup failure stays contained; it does not block ordinary
legacy acquisition solely because telemetry is unavailable.

These measurements describe quota reservations, not configured-context liveness
or physical VRAM. Device invalidation and GPU-generation retirement deliberately
retain surface reservations. Native unconfigure failure, direct app context use,
zero accounting or a forgotten scope does not prove GPU completion or disposal.
The standard-tracker checks do not establish arbitrary same-origin host isolation
or detect an unobserved backend swap-and-restore.
The ownership fences are not universal atomicity against arbitrarily replaced
DOM/context setters, getters or methods; that same-origin instrumentation can
introduce callbacks inside native operations that ordinary browser objects do
not perform. Such instrumentation remains outside this source's authority claim.

Coverage is intentionally limited to `SurfaceManager` views. `CompatGpuBridge`
owns a different surface/recovery path and is not included. The Realm syscall
adapter retains the kernel view privately and returns a distinct Realm receipt;
that receipt cannot capture this source. Future trusted acquisition must join
these sources to the exact genuine Realm/mount and use the separately retained
teardown validator through owner release. Mount11 still reports surface bytes as null until that
join is reviewed. Missing-family coverage, complete telemetry/provider wiring,
M1C-to-first-frame integration and the visible city remain open. Both B4H ledgers
remain ten flat pieces; dependency16 and v1/v2/v3 leases are unchanged.
(Sources: `webgpu-os/kernel/SurfaceManager.js`;
`webgpu-os/kernel/VRAMTracker.js`; `webgpu-os/kernel/CompatGpuBridge.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`;
`tests/virtual-realm/m2-gpu-surface-allocation-source.test.js`.)

Surface acceptance passes **42/42 browser cases** against the real manager and
tracker with explicit JavaScript canvas transport and real DOM elements. Fresh
adjacent gates pass mount36, presentation-port60, syscall-adapter18,
owner-coupled-presentation15, frame28, runtime-composition30, M2A entry-contract25,
Desktop-terminal17 and the existing isolated kernel runtime-recovery19:
**290/290 distinct cases**, with zero final failures, skips or console errors.
No physical WebGPU device is acquired by the new gate.

The final exact 26-file Python group passes **283/283** in 51.74 seconds,
including twenty new surface source/confinement checks. The manager/tracker
closures are exactly eight/seven modules. Entry106, B3-composition48,
dependency16, mount11 and the six-field kernel surface view remain unchanged.
The prior mount source gate changes only its additive tracker export allowlist
and its check of the shared writer validator's still-frozen ten-method default.
No full OS bundle, broad all-app runner or shared documentation generator is
part of this bounded acceptance.

An isolated read-only HTTP mutation removes only the same-backend surface scope
from served manager metadata. It produces **31 expected failures and 11 passes**
in the same 42-case gate; repository source bytes remain unchanged. The helper
serves only its pinned twelve-file test closure and exits after the run.
This rejects absent attribution independently of the positive run, without
claiming whole-kernel, native-GPU or visible-city acceptance.
(Sources: `tests/virtual-realm/m2-gpu-surface-allocation-source.test.js`;
`tests/kernel/gpu-runtime-recovery.test.js`;
`tests/virtual-realm/test_m2db4h_gpu_surface_allocation_source.py`.)

Piece 9 now connects those prerequisites in the kernel-private
`RealmLifecycleAllocationAuthority`. Its synchronous exact three-option factory
accepts `{ operatorContext, generationStorageView, appId }`, captures the real
active operator and genuine matching protected generation view, and constructs
its own attempt controller without performing storage I/O. The exact frozen
six-field result is `{ attemptBinding, allocateGeneration,
assertGenerationCurrent, retireGeneration, observeRetirement, close }`. There
is no `portName`, `registerParticipant`, process owner, or provider registration.
This is a complete allocation/currentness/retirement owner, not the full
four-method `lifecyclePort@1`.

The source accepts the existing allocation four-field request and currentness
five-field request without changing Entry or its adapters. Mutable ordinary
records remain compatible: it snapshots only own enumerable data descriptors,
then checks the exact keys on the private frozen snapshot. Accessors, inherited
requirements, symbols, unknown keys, and undefined values are rejected without
reading caller fields. All identities must match the fixed app and real captured
operator/account generation. Caller labels never select another scope or create
a lifecycle generation. After caller reflection, state is rechecked before use.

`allocateGeneration` captures the identical bound construction root only at
Entry's existing allocation step. The first accepted request publishes its
pending state and Promise before starting any source I/O. Repeated requests for
the same live attempt share that Promise and confirmed result rather than
reserving additional generations. It calls the existing session authority to
reserve a fresh durable generation and fences construction, work, teardown,
operator, and view around issuance and again at the final Promise-delivery
boundary. A rejected accepted attempt cannot retry with the same roots. A later
attempt needs both actual prior teardown and genuine retirement of any issued
session. Separately constructed authorities may retain overlapping live
generations of the same account/app; the durable high-water mark is not a global
revocation switch. Currentness requires the issued generation and exact live work
root, and delegates to the genuine session, not a cached boolean.

The allocation result retains the exact existing two-field wire, but its
one-method retirement handle is an authentic owner-bound wrapper around the
private session handle. Direct `handle.retire({ reason, signal })` and
`retireGeneration({ retirementHandle, reason, signal })` execute the same
synchronous storage-free operation: retire the underlying generation, observe
its genuine terminal result while teardown is live, and retain that observation
privately. Copies, proxies, unbound calls, and foreign handles do not select a
session. `observeRetirement({ retirementHandle, signal })` requires the exact
issued wrapper and live teardown root. No supplied digest can become terminal
proof. Capturing the observation on both retirement paths prevents direct handle
use from bypassing the close-time evidence cache.

A late issued session rejected by construction fencing is retired privately
before the allocation rejects. If the teardown root has already ended and that
retirement cannot be completed, the session remains cleanup-required; neither
close nor a newly bound attempt can erase it. A factory failure before issuance
may leave an unissued durable gap, which is not a session or terminal proof.
`close()` refuses pending allocation, unretired issued authority, or a live bound
teardown root. After those conditions clear it returns the stable frozen
`{ closed: true }`. It never aborts caller roots, reopens old-account storage,
manufactures resource cleanup, or reconstructs previous-process evidence.
The existing binding is supplied through the approved v2 mount route; remaining
lifecycle methods are host-private until a genuine participant/process-owner
composition is built. No application import, frozen catalog, dependency key,
authority grant, camera, or first frame changes. (Source:
`webgpu-os/kernel/realm/RealmLifecycleAllocationAuthority.js`.)

Piece 9 also implements `RealmProcessOwnerIdentityAuthority`, an authentic
private identity prerequisite, not the full `processOwnerPort@1`. The exact
frozen factory input is `{ allocationAuthority }`; the result is exactly
`{ acquire, authenticate, close }`. It accepts only the actual allocation source
through a kernel-private WeakMap lookup, without calling supplied methods or
reading a look-alike source. Copies and proxies cannot authenticate it. The
allocation source's existing six fields and the application's sixteen dependency
keys are unchanged. Neither factory performs storage I/O or OS registration.

The separate allocation-module export
`captureRealmLifecycleAllocationOwnerSource(source)` returns a private
single-method `{ capture }` source. Its capture accepts the existing owner
request `{ appId, operatorIdentity, lifecycleGeneration, signal }`, using Entry's
exact **work** root, not its construction root. Every supplied label must match
the issued session. Pending, failed, stale, retired, unissued, or wrong-root
allocations cannot yield a binding. The stable frozen binding is exactly
`{ appId, operatorIdentity, operatorGeneration, lifecycleGeneration,
assertCurrent, observeRetirement }`. It contains no roots, controllers, session
handle, storage, writers, or method that can retire a generation.

The binding's `assertCurrent({ signal })` rechecks genuine scope and session
liveness using the exact work root. Construction completion alone does not
invalidate an active owner. Its zero-argument `observeRetirement()` returns only
the already cached genuine terminal observation, or null. It closes over the
original issued state, not the allocation source's next record. This observation
remains readable after operator switch, teardown, allocation-source close, or a
new generation, without reading old-account storage. A root abort, high-water
counter, or caller-supplied digest never fills the terminal cache. Retained
process-local observations do not restore authority after process loss.

The identity authority's synchronous `acquire` accepts the existing exact frozen
four-field owner request and issues exactly frozen `{ ownerId, release }`.
`ownerId` uses native cryptographic UUID generation without embedding account
labels. Only one identity may claim an issued binding across these authorities.
Live repeats on the issuing authority return the same handle. A weak private
claim set prevents issuing another identity after release without retaining
historical bindings strongly. Acquisition does not allocate another lifecycle
generation or use the legacy app-ID-keyed `ProcessTable`.

`authenticate` accepts exactly frozen `{ appId, ownerId, signal }`. It joins the
private active owner with its exact work root and genuine session currentness,
then returns frozen `{ ownerId, appId, operatorIdentity, operatorGeneration,
lifecycleGeneration }`. A matching owner ID alone is not proof. This result is
a point-in-time observation, not a transferable lease: future participant
registration must perform the actual private lookup at its authority boundary.

The authentic handle's `release({ reason })` accepts an exact frozen bounded
reason record and requires the original binding's genuine cached retirement.
It rejects copied/proxied/unbound receivers. Repeats return the same frozen
`{ ownerId, released: true }`, including after identity-source close or a newer
generation. If retirement is unavailable, ownership remains unresolved and
`close()` refuses it; closing never aborts roots or closes the allocation source.
These receipts prove only release of the identity prerequisite, not disposal of
children, participants, GPU resources, runtime pins, or durable recovery.

The retained cleanup continuation implements
`captureRealmProcessOwnerTelemetrySource(originalIdentityAuthority)` in the
same identity module. Its exact one-argument private lookup accepts only the
original authority, not its forwarding facade, a copied identity tuple, a proxy,
or matching labels. Native WeakMap methods are pinned at module initialization.
The result is exactly frozen `{ capture }`; it is not `resourceTelemetryPort@1`.

`capture()` accepts exactly one frozen
`{ appId, ownerId, lifecycleGeneration, signal }` request, matching Entry's
existing `beginOwner` call. It authenticates the genuine live owner, exact
lifecycle generation and original work root before retaining anything. Repeated
live capture returns the same frozen three-field binding:

| Field or operation | Guarantee | Explicit limit |
| --- | --- | --- |
| `identity` | Original frozen `{ ownerId, appId, operatorIdentity, operatorGeneration, lifecycleGeneration }` | Contains no selected Realm, selection epoch, bake, mount or GPU producer identity. |
| `assertCurrent()` | Zero-argument genuine currentness check with original-owner retention checked before and after host currentness callbacks; returns the same identity | Rejects work/operator invalidation, retirement, owner release and identity-source close. |
| `assertTeardown({ signal })` | Exact one-argument frozen request authenticated against the original live native teardown root; returns the same identity | Checks cleanup authority only; does not perform cleanup or certify retirement/disposal. |

The allocation module privately associates its original six-field owner binding
with `captureRealmLifecycleAllocationTeardownSource(originalOwnerBinding)`.
That exact one-argument lookup returns only frozen `{ assertTeardown }`. Its
validator consumes exactly frozen `{ signal }`, returns `undefined` on success,
and exposes no root, controller, writer, session or storage capability. It
captures the original root once; it never selects the allocation source's next
record or reconstructs authority from public labels.

Retained teardown validation needs neither successful retirement nor a live
operator/work root. Entry attempts every cleanup phase even if retirement fails.
The validator remains usable after identity release and identity-source close
while the original native teardown root is live. New captures and ordinary work
checks remain rejected in those states. Native teardown abort revokes retained
validation, including when an own `aborted` property lies or the caller presents
a fresh signal. Allocation-source close requires ended teardown, so it cannot
make retained cleanup live again. No retirement receipt is created or modified.

The checks are synchronous, storage-free and detachable. They report only fixed
`VR_M2DB4H_PROCESS_IDENTITY_*` or
`VR_M2DB4H_LIFECYCLE_ALLOCATION_*` rejection codes. Observation adds no timer,
subscription or logging callback; existing Entry diagnostics retain cleanup
failure/retry reporting. There is no observer resource to close. A retained
validator cannot authenticate after native teardown revocation; retaining its
object does not preserve live cleanup authority.
The allocation6, owner-binding6, identity3, owner-handle2, participant-source2,
participant-binding3, dependency16 and approved v1/v2/v3 leases are unchanged.
(Sources: `webgpu-os/kernel/realm/RealmLifecycleAllocationAuthority.js`;
`webgpu-os/kernel/realm/RealmProcessOwnerIdentityAuthority.js`;
`webgpu-os/apps/the-virtual-realm/VirtualRealmEntry.js`.)

The next source-joining work must resolve four distinct provenance boundaries:

1. `RealmGpuPresentationSyscallAdapter` retains an original kernel surface view
   but returns a distinct Realm receipt; only the retained original can capture
   the surface source. Its new weak-pair verifier authenticates historical
   receipt/view pairing when the trusted caller already holds both originals;
   it neither reveals the view nor proves owner attachment or currentness.
2. Guarded `Syscalls.gpu.registerFrameProducer` returns a five-method wrapper,
   not the original coordinator handle. The new private guarded-frame bridge
   preserves that original handle for observation without widening the wrapper.
   The direct coordinator capture still rejects the wrapper; trusted late
   attachment must use the separate bridge and authenticate Realm ownership.
3. Desktop's original GPU mount may span several sequential Realm process-owner
   epochs inside one mounted app. B3's released epoch does not establish that
   every retained mount allocation belongs to one new Realm owner. Neither
   app totals nor baseline subtraction can prove that attribution.
4. Entry begins telemetry before creating surfaces and frame producers. The
   future host must authenticate later source attachment; beginning telemetry
   cannot fabricate those not-yet-issued associations. Registry syscall-record
   snapshots also mean a bridge keyed only by the original record object does
   not automatically survive composition.

Resolve exclusive ownership scope or exact per-epoch attribution at trusted
dispatch before joining measurements, and independently bind selected-Realm and
activation provenance. Preserve unavailable resource families. This prerequisite
does not freeze an aggregate telemetry schema, install its port/provider, or
advance the physical M1C-to-city-frame gate. It remains inside flat piece 9.
(Sources: `webgpu-os/kernel/Syscalls.js`;
`webgpu-os/shell/Desktop.js`;
`webgpu-os/kernel/AppRuntimeCompositionRegistry.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`.)

The retained-binding gate passes **32/32 browser cases** over genuine operator,
branded storage-view, allocation and identity authorities with native attempt
signals. Its shared controllable backend supplies test transport, not additional
durability evidence. Fresh identity34, allocation32, participant40,
lifecycle-composition37, runtime-composition30 and Entry-contract25 gates bring
this continuation to **230/230 distinct browser cases**, with zero final
failures, skips or console errors.

The exact nine-file Python group passes **121/121** in 23.37 seconds, including
nineteen new source/confinement checks. Allocation49, identity50 and participant51
module closures remain unchanged; Entry106 and B3-composition48 still cannot
reach these private sources. Previous gate maintenance adds only the two
kernel-private exports and tightens extraction around the original frozen
binding/method bodies, without relaxing their fields or authority limits.
No broad runner, full OS bundle, shared discovery regeneration, physical GPU
or first-city-frame acceptance is included.
(Sources: `tests/virtual-realm/m2-process-owner-telemetry-binding.test.js`;
`tests/virtual-realm/test_m2db4h_process_owner_telemetry_binding.py`.)

An isolated read-only HTTP negative control inserts the old live-owner check
only into served telemetry teardown validation. The same gate produces
**10 expected failures and 22 passes**, including failed retry after owner
release; zero cases skip. The helper serves only its pinned 72-module test
closure and gate HTML, then exits successfully. Both production file hashes
remain unchanged. A final unmodified run again passes 32/32 without positive-run
console errors. Intentional mutation failures are not added to passing totals.

The guarded-frame continuation adds
`captureGuardedGpuFrameProducerTelemetrySource(wrapper)` in `Syscalls.js`.
It accepts exactly one original five-method wrapper issued by guarded
`gpu.registerFrameProducer`. Private WeakMap membership and lookup use native
methods captured at module initialization. Copies, proxies, revoked proxies,
matching labels, raw coordinator handles and caller-created forwarding wrappers
cannot select the association. No selector property or public `telemetry()`
method is inspected. There is no exported alias-registration operation.

Registration retains the exact coordinator return value immediately before
publishing the frozen wrapper. It creates no observer and captures no numeric
snapshot. The existing wrapper remains exactly
`{ update, reportGpuTiming, telemetry, unregister, destroy }`. Host process-table
lookup or `gpuConsumer` setters can reenter during consumer marking; a final
lifecycle fence now rejects stale publication and attempts original-handle
unregister within the existing rollback path. This does not certify successful
cleanup when a custom unregister fails.

Each trusted capture delegates to the existing
`captureGpuFrameProducerTelemetrySource(originalHandle)` and returns a fresh
frozen `{ snapshot, close }` observer. The existing eleven-field accounting
projection, zero-argument detachable observer methods and independent close
receipts are unchanged. Closing one observer cannot close another or unregister
the producer. There is no second counter ledger, copied projection or shared
observer whose close could disable siblings.

Historical observation deliberately does not reauthenticate current mount or
permission. It can retain original accounting after unregister, mount revocation,
same-label replacement, retired-cache eviction or coordinator destruction.
Final in-flight callback accounting belongs to that same original record.
Existing update admission and terminal unregister/destroy behavior are unchanged.
Neither retained observation nor a zero counter proves native GPU submission,
queue completion, resource disposal or a live producer.

Malformed capture arity or an unrecognized wrapper raises fixed
`GPU_GUARDED_FRAME_TELEMETRY_REQUEST_INVALID` or
`GPU_GUARDED_FRAME_TELEMETRY_SOURCE_REQUIRED`. A recognized wrapper whose custom
coordinator returned a non-genuine handle remains registration-compatible, but
observation fails the existing `GPU_FRAME_TELEMETRY_SOURCE_REQUIRED` check.
Original observer validation/closed errors are preserved. Observation adds no
logging callback, scheduling, subscription, permission request or resource work.

This bridge attests only the actual returned handle's provenance. A trusted
custom coordinator can return an older genuine handle; the bridge does not
claim a fresh registration or infer its owner/generation. Kernel construction
and import ownership remain trusted, not same-origin isolation. No selected
Realm, process-owner epoch, surface association or GPU mount becomes authenticated
by this link alone. The future provider still needs late attachment, selected-
Realm/activation binding, exact per-owner attribution across shared-mount epochs
and reviewed missing-family coverage. No application dependency, runtime lease,
M0-M1C catalog, aggregate telemetry wire or provider registration changes.
(Sources: `webgpu-os/kernel/Syscalls.js`;
`webgpu-os/kernel/GpuFrameCoordinator.js`;
`tests/virtual-realm/m2-guarded-frame-telemetry-source.test.js`.)

Guarded-frame acceptance passes **32/32 new browser cases**. The fresh regression
sweep also passes original frame-source 28/28, syscall-adapter 18/18,
owner-coupled presentation 15/15, production composition 11/11 and the existing
kernel GPU-device-authority gate 21/21: **125/125 distinct browser cases**,
with zero positive-run failures, skips or console errors. The exact seven-file
Python group passes **99/99** in 26.72 seconds, including seventeen new checks.
These are genuine kernel implementations over controlled scheduling, device and
lifecycle transport, not a physical GPU or real Desktop/Realm-owner measurement.
(Sources: `tests/virtual-realm/m2-guarded-frame-telemetry-source.test.js`;
`tests/virtual-realm/test_m2db4h_guarded_frame_telemetry_source.py`;
`tests/kernel/gpu-device-authority.test.js`.)

The source-gated import checks cover exactly 39 Syscalls modules, 42 new-browser
modules and 41 existing-device-authority modules, with zero skipped dependencies.
An explicit allowlist rejects excluded or unreviewed paths before source reads.
No broad application runner, full-OS bundle or global documentation/SPDX rebuild
was used for this continuation; First Shard was not scanned. Existing Entry106,
B3-48 and sixteen-key dependency boundaries remain unchanged.

Removing only the private wrapper-to-handle publication from an in-memory served
copy produces **22 expected failures and 10 passes**, with zero skips. The final
unmodified gate passes 32/32 again. Both isolated HTTP helpers exit normally;
the Syscalls, coordinator and broker files remain unchanged by the experiment.
The negative control demonstrates detection of the missing provenance link, not
complete resource accounting, teardown completion or acceptance of B4H.

The surface-receipt continuation adds
`assertRealmGpuPresentationSurfaceProvenance(receipt, kernelView)` to the existing
syscall adapter. It accepts exactly two objects already held by the trusted
caller and returns `undefined` only when they form an original adapter-issued
pair. A private `WeakMap<receipt, WeakSet<view>>` records that pairing after the
existing raw acquisition checks and before returning the scalar receipt. Native
map/set methods and the set constructor are captured at module initialization.
Copies, proxies, matching labels, canvases and wrong views cannot substitute for
either original. Neither argument is reflected upon or invoked by this check.

Both sides are weak. Keeping a former scalar receipt alive does not add a strong
reference to its kernel view, canvas, context or resize closure. The verifier
does not return a view, handle, observer, supplier callback or reusable binding.
There is no exported registration operation and no app port gains a method.
Its exact-arity, unknown-receipt and wrong-view failures are fixed frozen errors:
`VR_M2DB4H_SURFACE_PROVENANCE_REQUEST_INVALID`,
`VR_M2DB4H_SURFACE_PROVENANCE_SOURCE_REQUIRED` and
`VR_M2DB4H_SURFACE_PROVENANCE_SOURCE_MISMATCH`.

This check attests historical raw-adapter issuance, not exclusive ownership or
successful outer-broker acceptance. The broker returns the same scalar receipt
when accepted, but still owns abort/currentness validation and rollback. If a
trusted host retains a rejected original receipt, its historical pair can still
match after rollback. Release, device loss, capability retirement or later
same-label acquisition does not retarget that pair. If trusted transport returns
the same exact view to two adapter issuances, both original pairs can match.
No currentness, fresh allocation or disposal conclusion follows from success.

The trusted collector must independently use
`captureGpuSurfaceAllocationTelemetrySource(kernelView)` to authenticate genuine
manager accounting. A custom structurally accepted view can form an adapter pair
while failing that independent source check. Pair verification and accounting
support are separate: tracker replacement or accounting unavailability cannot
rewrite historical issuance, and historical issuance cannot manufacture a
supported measurement. No kernel import is added to the adapter or Entry.
(Sources: `webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationPortContract.js`;
`webgpu-os/kernel/SurfaceManager.js`.)

The surface-pair gate passes **28/28 new browser cases** over the genuine adapter,
contract broker, surface manager and accounting tracker, with explicitly
controlled capability/syscall/canvas-device transport. Fresh regressions pass
adapter 18/18, broker 60/60, owner-coupled presentation 15/15, production
composition 11/11, surface accounting 42/42 and guarded-frame provenance 32/32:
**206/206 distinct final browser cases**, with zero final failures, skips or
console errors. The exact seven-file Python group passes **86/86** in 25.03
seconds, including sixteen new checks. An initial resize-test expectation was
corrected to stay within the already-admitted pixel budget; production quotas
were not changed. No physical GPU, garbage-collector timing or owner measurement
is inferred from these tests.

Guarded import checks retain adapter14, broker13, Entry106 and B3-48, and establish
the new browser's exact25-module closure, with zero skipped dependencies. Unknown
or excluded paths reject before source reads. No broad OS bundle, application
runner or global discovery/SPDX generator was run, and First Shard was not
scanned. Source review verifies the weak edge structurally, not by forcing GC.
(Sources: `tests/virtual-realm/m2-surface-receipt-provenance.test.js`;
`tests/virtual-realm/test_m2db4h_surface_receipt_provenance.py`.)

A served-only removal of the private pair publication causes **22 expected
failures and 6 passes**, with zero skips. The unmodified gate then passes 28/28
again in a clean browser tab with zero console errors. The exact25-module-plus-
HTML helper exits successfully; all26 served file hashes remain unchanged on
disk. This control detects a missing pair association, not full attachment,
accounting completeness, resource disposal or garbage-collector behavior.

The lifecycle-composition telemetry continuation adds the host-private
`captureRealmLifecycleCompositionTelemetrySource(composition)` lookup in the
existing `RealmLifecyclePortComposition.js`. It accepts exactly the original
frozen six-field composition through a private, native-pinned WeakMap. Copies,
proxies, matching fields and the `ownerIdentity` forwarding facade reject without
caller-property inspection. The original facade remains ineligible for
`captureRealmProcessOwnerTelemetrySource()`. No raw identity authority is exposed.

The stable frozen `{ capture }` companion privately delegates to the genuine
identity source constructed by that composition. Its exact one-argument capture
consumes the existing frozen begin record
`{ appId, ownerId, lifecycleGeneration, signal }`. Each accepted capture first
authenticates the original owner and work root, then returns a cached frozen
`{ identity, assertCurrent, assertTeardown }` companion keyed by the exact genuine
binding, not by owner labels. `identity` is the original five-field identity
record. Source lookup, capture and teardown require one argument; currentness
requires none. Wrapper arity errors use the existing fixed frozen composition
`REQUEST_INVALID` error; unknown original sources use `SOURCE_REQUIRED`.
Underlying genuine validation errors retain their existing codes.

Capture, cache publication and currentness share the composition's existing
synchronous operation-depth fence. Reentrant close rejects `OPERATION_PENDING`
before setting closing state. No post-operation closure check can hide a newly
issued cleanup handle. All eight existing forwarded routes retain one-argument
request forwarding and their original result identity; asynchronous allocation
remains governed by its source's pending-allocation checks. Once closing begins,
new capture and currentness reject even if a child close fails.

Retained `assertTeardown({ signal })` bypasses that work fence and delegates to
the original native-root validator. It can validate during partial closing,
including after the identity source has closed while allocation close refuses
a still-live teardown root. Successful full composition close instead requires
that root already aborted: a later teardown check must reject. Stable source
lookup after close does not resurrect work or cleanup authority. No additional
storage I/O, subscriptions, diagnostic callback channel, source lease, public
field, app dependency or runtime lease is introduced.
(Sources: `webgpu-os/kernel/realm/RealmLifecyclePortComposition.js`;
`webgpu-os/kernel/realm/RealmProcessOwnerIdentityAuthority.js`;
`webgpu-os/kernel/realm/RealmLifecycleAllocationAuthority.js`.)

Companion acceptance passes **32/32 new browser cases**, including one explicit
protected-OPFS case. The final clean regression sweep passes existing lifecycle
composition 37/37, identity 34/34, retained telemetry binding 32/32, participant
40/40, production composition 11/11 and owner-coupled presentation 15/15:
**201/201 distinct browser cases**, with zero final failures, skips or console
errors. The exact eight-file Python group passes **104/104** in 39.37 seconds,
including sixteen new checks and all sixteen maintained composition checks.
Two initial browser expectations were corrected to preserve actual session
listener retirement and the genuine reentrant `NOT_CURRENT` error precedence;
no production lifecycle behavior was relaxed.

Pre-read allowlists verify composition52, Entry106, B3-48 and the new browser74,
with no skipped dependencies. The six regression browser closures are respectively
88, 72, 72, 87, 122 and 18 modules. An accidentally selected older broad test
entry was rejected at its unreviewed factory import before that import was read;
it was not run. No broad OS/app runner, full bundle, global discovery/SPDX
generator or First Shard scan was used. These are genuine authority/composition
tests with controlled transports, not real owner GPU measurements.

A served-only removal of the companion currentness operation fence yields
**4 expected failures and 28 passes**, with zero skips. Cases 20, 21, 22 and 26
detect the missing closing/currentness and reentrant-close protection. The
unmodified gate then passes 32/32 again as part of the clean 201-case sweep.
The mutation never changes production on disk. The private companion supplies
genuine-source access, not GPU ownership or complete telemetry.
(Sources: `tests/virtual-realm/m2-lifecycle-composition-telemetry-source.test.js`;
`tests/virtual-realm/test_m2db4h_lifecycle_composition_telemetry_source.py`;
`tests/virtual-realm/test_m2db4h_lifecycle_port_composition.py`.)

The GPU-epoch continuation hardens the existing
`RealmOwnerCoupledGpuPresentationPort.js` control boundary. Bind, release and
dispose now share a synchronous control-operation guard that starts before any
request or syscall descriptor reflection. Reentrant control calls reject
`VR_M2DB3_CONTROL_OPERATION_PENDING`, and app-port forwarding rejects while a
control transition is running. This prevents nested bind from overwriting a
newer epoch, publication after disposal, and an old release from clearing a
replacement selected during caller reflection. Failed operations restore the
guard in `finally`; the existing five-field controller remains unchanged.

Every forwarded operation increments its original epoch's pending count before
capability-request reflection and retains that reservation through adapter
settlement and result publication. Release therefore cannot null the original
adapter during validation, before any capability receipt exists. Existing broker
validation and rollback still own rejected or late cleanup-bearing candidates.
The controller captures retirement's original receipt from its own data
descriptor before dispatch, without invoking malformed accessors or rereading
caller-owned fields after successful retirement. No new post-result owner check
can hide the original candidate or replace its cleanup identity.

The additive private `captureRealmOwnerCoupledGpuEpochSource(port)` lookup accepts
exactly the original stable app-facing port through a native-pinned WeakMap;
neither the controller, copied port, proxy nor matching identifiers substitute.
It returns one stable frozen `{ capture }` source without adding a public port
method. Capture requires exactly frozen
`{ appId, ownerId, lifecycleGeneration }`, validates through existing B2/B3 rules
inside the control guard, and selects the original current epoch. Repeated
captures of that epoch return the same frozen
`{ identity, assertCurrent, assertResult }` companion. Its immutable identity
contains those three scalar fields; it is not a genuine lifecycle-owner proof.

Zero-argument `assertCurrent()` returns that original identity while the
controller still holds the same epoch, then rejects after release, rebind or
dispose. `assertResult(method, result)` accepts exactly an existing presentation
method name and its exact original successfully returned object. It returns
`undefined`, never the object, a raw source or a callable authority. Each epoch
owns nine fixed weak result sets, one for each existing presentation operation.
Native weak-set methods and the constructor are captured at module evaluation.
Recording occurs only after real adapter/broker acceptance, the original-epoch
check and existing active-receipt bookkeeping; rejection and rollback do not
publish successful membership. Lookup and result checking inspect no caller
properties. Unknown methods, copied/proxied results and results never accepted
by this epoch reject. Membership is non-exclusive: if trusted transport returns
the same original object and separate epochs independently accept it, that object
can belong to both histories. Neither membership nor a matching receipt digest
proves exclusive ownership. The fixed frozen private errors are
`VR_M2DB4H_GPU_EPOCH_PROVENANCE_REQUEST_INVALID`, `SOURCE_REQUIRED`,
`METHOD_INVALID`, `RESULT_REQUIRED` and `NOT_CURRENT` under that same prefix.

This source deliberately retains **historical acceptance**, including acceptance
before source capture and after later epoch release. It does not report native
allocation, callback execution, successful GPU submission, exclusive resources,
physical cleanup or authorization at dispatch. Stable app-port methods continue
to route new calls to the latest bound epoch; they are not retained old-epoch
work capabilities. Retained device methods, scheduling callbacks, producer
callbacks and lifecycle invalidation remain governed by their existing adapters,
not by these weak result sets. No GPU syscall, live callback, aggregate telemetry
wire or genuine-owner source is added to this controller.

The scan therefore rejects a retrospective genuine-owner join. A result could
predate capture of the genuine owner binding, or be accepted after that owner's
work root is invalidated while the label-matching GPU epoch remains bound. A
later equality check cannot reconstruct authorization at acceptance. The next
genuine join must install its original owner binding before the first dispatch,
and enforce ordinary-work checks in the affected routes and retained callbacks.
Late results still require original cleanup ownership even when those checks
deny publication. This temporal requirement stays in piece 9; no new nested
milestone, dependency, lease or look-alike joined-owner provider is introduced.
(Sources: `webgpu-os/kernel/realm/RealmOwnerCoupledGpuPresentationPort.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationPortContract.js`.)

The GPU-epoch slice's final isolated acceptance sweep passes **200/200 distinct
browser cases**: 36 new epoch-source, 15 unchanged owner-coupled controller,
11 production composition, 18 syscall adapter, 60 presentation broker, 28 surface
provenance and 32 lifecycle-companion cases. There are zero final failures, skips
or console errors. The exact six-file Python group passes **64/64** in 19.79
seconds, including eighteen new static/import/shape checks. The controller's
15-module, B3's 48-module and Entry's 106-module production closures are unchanged;
the new browser gate has an exact pre-read 19-module closure. These are controlled
transport and instrumented JavaScript tests, not physical GPU measurements.

Two separately served, memory-only negative controls prove test sensitivity.
Removing only successful-result weak membership produces **14 expected failures
and 22 passes**; removing only the control-entry idle check produces **5 expected
failures and 31 passes** (cases 24, 25, 26, 27 and 36). Each runs all 36 cases with
zero skips. Both exclusive localhost helpers exit 0 after explicit finish,
serve and rehash exactly twenty approved files, reject no paths and confirm zero
disk changes. The final production SHA-256 remains
`0ee4976e33d072456bd7855b7015a388da4a99793ab752c6ec131a31ac7c89a2`.
An initial 35/36 run exposed only a new test helper omitting the existing encoder
descriptor argument; the helper now supplies explicit frozen descriptors without
relaxing the production contract or case count. Fixed errors and existing scalar
snapshots provide diagnostics without inserting logger callbacks into acceptance.
No full OS bundle, broad app runner or shared discovery generator was run for
this slice, and First Shard was not scanned.
(Sources: `tests/virtual-realm/m2-gpu-presentation-epoch-source.test.js`;
`tests/virtual-realm/m2-gpu-presentation-epoch-source.main.js`;
`tests/virtual-realm/test_m2db4h_gpu_presentation_epoch_source.py`.)

The next integration stays inside flat piece 9. Its private dispatch join must
satisfy these independent requirements; the companion alone implements none of
the dispatch or measurement association:

1. Capture the genuine composition-derived owner binding after authentic owner
   acquisition and install it before the first dispatch. B3 already holds the
   original acquisition signal, owner and generation at epoch bind; waiting for
   Entry's later telemetry begin is not required. Late surface/producer attachment
   must preserve that original binding. Scalar labels and historical accepted
   result membership cannot retroactively prove genuine-owner authorization.
2. Bind each dispatch route, delayed callback and completion to its immutable
   original owner/dispatch epoch. B3 captures one GPU syscall facade and reuses
   it across owner restarts. A mutable current-owner cell behind retained methods
   would attribute old activity to a new owner; a method snapshot alone does not
   solve this temporal mismatch.
3. Reassert ordinary-work currentness after caller-request reflection,
   immediately before raw side effects and after asynchronous completion.
   The controller's request-reflection/pending-registration interval is now
   fenced, but genuine owner checks across raw effects and retained callbacks
   remain unimplemented. Do not turn a past provenance pair into a current
   attachment merely because its identifiers match.
4. Preserve exact cleanup-bearing candidates when the post-dispatch check fails.
   A newly issued capability, surface, producer or subscription cannot disappear
   behind a late throw. Keep it reachable by existing rollback or an explicit
   retained cleanup owner until exact terminal evidence settles it. Never clean
   a replacement resource selected by matching labels.
5. Separate ordinary dispatch from original terminal-resource authority and
   lifecycle callback delivery. Most low-level GPU calls carry neither Entry's
   work signal nor its teardown signal. Entry disposes GPU presentation before
   calling `resourceTelemetryPort.closeOwner()`; requiring that later teardown
   request before existing release/unregister/unsubscribe routes would deadlock
   the current cleanup order.
6. Keep cleanup authorization distinct from cleanup outcome. B2 memoizes failed
   cleanup operations and does not redispatch them. A retained validator can
   authorize a telemetry retry after owner release, but cannot prove or cause a
   second GPU destruction attempt. Observer closure is not resource disposal.
7. Independently establish original manager/frame provenance, exact per-resource
   ownership across restarts, selected-Realm/activation provenance and reviewed
   missing-family coverage. Whole-mount totals or baseline subtraction cannot
   establish owner attribution when epochs share that mount.

The approved attempt binding and v3 host channel are not attachment channels.
This private observation companion adds no seventeenth dependency, lease field,
full process-owner method or new milestone. Actual dispatch joining, complete
telemetry and visible-city presentation remain unimplemented.
(Sources: `webgpu-os/apps/the-virtual-realm/VirtualRealmEntry.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`webgpu-os/kernel/realm/RealmOwnerCoupledGpuPresentationPort.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationPortContract.js`;
`webgpu-os/kernel/realm/RealmProcessOwnerIdentityAuthority.js`.)

#### Pre-dispatch integration review: terminal GPU contract decision

**Status: separate versioned terminal GPU design approved by the subsequent
continue instruction; the inert v1 contract validators and original buffer/texture
issuer registry are implemented. The authenticated terminal destruction channel,
private delivery installation and dispatch enforcement remain unimplemented.**
The historical epoch/source slice remains accepted only
for its stated observation and reentry scope. This work stays inside flat piece 9.

There is a concrete compatibility conflict, not merely a missing currentness
check. `VirtualRealmEntry.stop()` and `_cleanup()` abort ordinary work before
`_disposeGpuPresentation()`. The presenter's `#destroyGpuGeneration()` then calls
ordinary `scheduleJob` with a fresh `AbortController().signal`. Its callback
creates an encoder, invokes `RealmStaticGpuResourceOwner.disposeSynchronously()`
through retained device-facade destruction callbacks, finishes and submits an
empty command buffer. Surface release and capability retirement also use fresh
local signals. These are not the original lifecycle teardown root.

Applying genuine owner `assertCurrent()` to every existing route would therefore
deny legitimate cleanup after work invalidation. Exempting a caller-supplied
operation ID ending in `:teardown`, accepting any live signal, or allowing a
general scheduling callback after invalidation would grant ordinary execution
through the cleanup exception. None is an acceptable implementation.
(Sources: `webgpu-os/apps/the-virtual-realm/VirtualRealmEntry.js` `stop`, `_cleanup`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuPresenter.js`
`#destroyGpuGeneration`, `#cleanupAuthorizedGeneration`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuResourceOwner.js`
`disposeSynchronously`.)

The approved design is a **separate, versioned destruction-only channel**,
bound to the original genuine owner, original lifecycle/device generation and
original live teardown root. Its v1 wire validators now exist; this does not
construct a usable channel or supply its genuine authority.
It must accept only resources whose exact original ownership was established
before publication, retain their original cleanup operation, and report exact
terminal evidence. It must expose no arbitrary `execute` callback, allocator,
buffer/texture writes, encoder, rendering or queue-submission authority. Any
required scheduling stays inside the reviewed broker implementation. Resource
labels, receipt digests and historical weak membership alone cannot enroll a
resource or prove exclusive ownership. Exact request/result fields and the
private delivery wire are frozen by the inert contract described here. The
host-private delivery installation still requires the original genuine sources.

Public accepted-resource cleanup and private acquisition rollback are distinct
cohorts. Before dispatch, reserve the original acquisition/cleanup owner; retain
any actual late candidate under it before a post-call check can throw. This
includes unpublished receipts, surfaces and registration handles that are never
accepted publicly. It does not let callers enroll arbitrary objects through the
terminal channel. Capture destruction operations from the reviewed original
issuer/kernel authority, never from caller-supplied `destroy` or cleanup
callbacks. A differently named arbitrary callback is still execution authority.

The same terminal design must preserve original producer disposal, surface
release, subscription removal and capability retirement independently of
ordinary-work currentness. It must not wait for `resourceTelemetryPort.closeOwner`:
Entry calls that after presentation disposal. Device loss still distinguishes
abandoned handles from successfully destroyed resources. Current resource-owner
release loops pop failed entries and memoize their receipt; broker cleanup also
memoizes failure. This review grants no retry or successful-destruction claim.
Any later retry policy must retain unresolved exact handles and distinguish
permission to retry from evidence that a retry occurred.

The implementation impact is bounded but crosses both the host and presenter:

| Existing source | Required integration under the approved contract |
| --- | --- |
| `RealmLifecyclePortComposition.js` and `RealmProcessOwnerIdentityAuthority.js` | Reuse genuine private lookup and original-root validation; do not accept a shape-compatible companion as authority or turn observation into owner acquisition. |
| `RealmM2RuntimeComposition.js` | Install the original composition host-privately before acquisition starts; require the exact composition lifecycle port used by B3, then bind the genuine owner before epoch publication. |
| `RealmOwnerCoupledGpuPresentationPort.js` | Retain one immutable genuine binding per opted-in epoch; keep historical result acceptance distinct from work authorization and terminal cleanup. |
| `RealmGpuPresentationSyscallAdapter.js` | Enforce ordinary checks at raw-effect and retained callback entry; preserve exact late candidates and original terminal operations. A frame callback must be checked before current-texture/view acquisition. |
| `RealmGpuPresentationPortContract.js` | Coordinate broker acceptance/rollback, callback scopes, retained device methods and nested encoder/pass capabilities with the opt-in checks and separate terminal channel. |
| `RealmStaticGpuPresenter.js` | Use authenticated destruction-only cleanup instead of an ordinary job with a fresh signal; retain the original facade/resource association across stop and recovery. |
| `RealmStaticGpuResourceOwner.js` | Preserve original-resource LIFO ownership and truthful terminal evidence; do not silently convert abandoned or failed releases into successful cleanup. |
| `VirtualRealmEntry.js` | Deliver the original teardown root to the approved private cleanup binding before presentation teardown, preserving the existing teardown order and dependency record. |

The table names existing files, not newly available interfaces. The CPU-only
`runtime/RealmEngineAdapter.js` is not the GPU disposal implementation and must
not receive these presenter changes. The static presenter currently captures
some destruction callbacks against a local facade, while uploaded-buffer
callbacks read `this.#facade` later; the new ownership proof must not select a
replacement facade through that mutable cell.
(Sources: `webgpu-os/kernel/realm/RealmLifecyclePortComposition.js`;
`webgpu-os/kernel/realm/RealmProcessOwnerIdentityAuthority.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`webgpu-os/kernel/realm/RealmOwnerCoupledGpuPresentationPort.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationPortContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmEngineAdapter.js`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuPresenter.js`.)

The build order within piece 9 is:

1. Implemented: freeze and validate the separate terminal-channel v1 wire and
   host-private delivery record; preserve dependency16 and attempt/v3 channels.
2. Reserve B3 acquisition/installation before reflective validation; snapshot
   original acquire4 data once. Reject late or competing installation.
3. Authenticate the original lifecycle composition and exact lifecycle-port
   reference. After genuine owner acquisition, capture begin4 with the original
   work signal; match app, owner, lifecycle generation and requested operator.
4. Recheck B3 closing/disposed/reservation state after genuine currentness calls,
   before epoch publication. Retain cleanup handles if acquisition fails.
5. Establish original-resource terminal ownership and wire presenter destruction;
   test post-work-abort teardown before enabling ordinary-work denial.
6. Add genuine checks after caller reflection, immediately before raw effects,
   at delayed callback execution and before result publication. Cover device
   methods and nested encoder/pass capabilities, not only top-level syscalls.
7. Keep late capability/surface/producer/subscription candidates reachable by
   exact rollback; preserve lifecycle invalidation cleanup even if app delivery
   is denied. Invalidation inside a raw call cannot undo an effect already made.
8. Run genuine-source hostile, callback, cleanup and legacy regression gates;
   re-certify any expanded import closure and update the same flat ledger.

An additive host-private installer can preserve B3 options17, controller5,
bind4, release3, composition6 and existing app wires. It must derive authority
from original privately registered sources, not caller-supplied check functions.
Changing any frozen shape instead requires an explicit versioned decision.
The already approved attempt binding and v3 lifecycle channel are not reused
as GPU cleanup channels. A genuine full process-owner provider, including its
activation-authorized children, remains separately missing; its two-field
identity prerequisite is not a replacement six-method handle.

Required integration gate evidence includes real composition-issued owners, original
work/teardown roots, cross-composition and cross-epoch rejection, reentrant
invalidation, delayed transfer/job/frame callbacks, nested retained capability
checks, late-result rollback, original-only destruction after work abort, and
denial of allocation/writes/render/submit through cleanup. Reuse the genuine
lifecycle test fixture and controlled adapter callback transport; instrumented
JavaScript counters are not physical GPU evidence. Existing closure counts and
the prior 200/200 browser / 64/64 Python results remain historical receipts,
not validation of unimplemented channel operations. The earlier implementation
review changed documentation only; the subsequent contract build is separate.
(Sources: `tests/virtual-realm/m2-lifecycle-composition-telemetry-source.test.js`;
`tests/virtual-realm/RealmProtectedHeadTestFixtures.js`;
`tests/virtual-realm/m2-gpu-presentation-syscall-adapter.test.js`;
`tests/virtual-realm/m2-owner-coupled-gpu-presentation.test.js`.)

#### Terminal cleanup v1 inert contract

`RealmGpuTerminalCleanupContract.js` implements five synchronous validators over
the existing `RealmRuntimeValidationPrimitives.js` leaf. It imports no broker,
owner service, renderer, kernel source, registry or provider. It creates no
channel and calls no supplied operation. The new private wire does not change
the existing nine presentation methods or sixteen application dependencies.

| Wire | Exact fields and rules |
| --- | --- |
| Identity4 | `appId`, `ownerId`, `lifecycleGeneration`, `deviceGeneration`. App is exactly `os.the-virtual-realm`; owner is a bounded canonical identifier; lifecycle is positive canonical uint64 text; device generation is a positive safe integer. |
| Port3 | `portName: 'realmGpuTerminalCleanup'`, `version: 1`, `destroyOwnedResources`. The sole method must be callable, but is never invoked by validation. No allocation, scheduling, enrollment, retry or caller-selected abandonment method exists. |
| Delivery5 | `port` plus Identity4. The original port reference is retained, not reconstructed or registered as genuine. This record belongs to a future host-private delivery path, not dependency17 or the attempt/v3 channel. |
| Request5 | Identity4 plus `signal`. Validation requires an explicit expected Identity4 and a live native AbortSignal; no raw resource, destructor, `execute`, reason or operation-label field is accepted. |
| Receipt11 | `receiptKind: 'realm-gpu-terminal-cleanup'`, `version: 1`, Identity4, `status`, `ownedResourceCount`, `destroyedResourceCount`, `abandonedResourceCount`, `unresolvedResourceCount`. An explicit expected Identity4 is required. |

All records must be exact frozen plain records with own enumerable data fields;
unknown, symbolic, inherited, accessor or mutable fields reject. All five
validators enforce exact argument counts: identity/port/delivery take one;
request/receipt take two. Identity, delivery, request and receipt produce frozen
descriptor-captured snapshots. The port validator returns the original port
reference. No validator reads supplied record fields through ordinary `get`
access after capture, but record inspection may run Proxy reflection traps;
these validators are not a reentrancy fence or hostile-realm isolation boundary.

Native signal branding uses an import-pinned native `aborted` getter, not a
look-alike object's properties. A shadowed `aborted` field cannot forge liveness.
Even a structurally valid native signal can be the wrong root: the future
original binding must independently authenticate it. Matching expected scalar
labels, a copied valid receipt and a callable port similarly prove no authority
or historical destruction.

Each count is a nonnegative safe integer, excluding negative zero. BigInt
arithmetic enforces exact conservation without rounded addition:
`owned = destroyed + abandoned + unresolved`. Status follows those counts:

- `destroyed`: no abandoned or unresolved resources, including an empty cohort.
- `abandoned`: no unresolved resources and at least one abandoned resource;
  destruction may have completed for other resources before device loss.
- `cleanup-pending`: at least one unresolved resource, including unattempted
  resources or failed destruction that remains unresolved.

These are declared aggregate outcomes for one issuer-enrolled cohort, not byte
counts, physical GPU reclamation or a retry policy. A valid shape cannot verify
that a destruction occurred. Only the future authentic original issuer may
produce trustworthy terminal receipts; callers cannot enroll resources or choose
abandonment through this contract. Successful destruction must not be inferred
from the mount accounting source: legacy accounting can be removed before an
original destroy operation throws.

Fixed frozen errors use `VR_M2DB4H_GPU_TERMINAL_` with `REQUEST_INVALID`,
`IDENTITY_INVALID`, `PORT_INVALID`, `SIGNAL_REQUIRED`, `SIGNAL_ABORTED`,
`IDENTITY_MISMATCH` or `RECEIPT_INVALID`. They do not echo caller values. This inert
leaf uses errors rather than logger callbacks or side effects for diagnostics.
(Sources: `webgpu-os/apps/the-virtual-realm/runtime/RealmGpuTerminalCleanupContract.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmRuntimeValidationPrimitives.js`;
`webgpu-os/kernel/GpuDeviceBroker.js` `_installTrackedDestroy`, `_retireResourceRequest`.)

The contract-only slice did not implement an original-issuer/resource index.
The subsequent [original-resource issuer registry](#original-resource-issuer-registry)
implements that prerequisite in the real GPU broker, independently of accounting
and writable resource properties. Genuine per-Realm ownership must still be
established before effects; a shared mount/facade alone is not a Realm epoch.

Accepted evidence for this inert contract slice:

- Browser gate: exactly **36/36 passed**, zero failures, skips or blocked cases,
  and zero console errors. Cases include hostile reflection, accessors, scalar
  coercion, shadowed native signal properties, abort during reflection, exact
  expected identities, conservation boundaries and forbidden authority fields.
- Scoped Python group: **66/66 passed**, including the new contract's 18 checks,
  historical GPU epoch source 18, lifecycle companion 16, and B3/B2 port/adapter
  checks 14. These are static/source checks, not physical GPU observations.
- Guarded pre-read import closures: production exactly **2** modules; browser
  exactly **5**. Entry remains **106** and B3 composition **48**, with no new
  contract import in either. The five new source/test files pass scoped SPDX,
  whitespace, final-newline and conflict-marker checks.
- Independent read-only source/test audit found no blocker in the inert scope.
  This acceptance covers validation, not a genuine root/issuer/resource binding,
  teardown execution, restart recovery, physical memory release or first frame.
- Memory-only negative control: removing just the conservation rejection produced
  **35 passed / 1 failed / 0 skipped**, with only case 30 failing as expected.
  Its exclusive loopback helper served the five approved modules plus HTML,
  received explicit completion and exited 0; all six disk SHA-256 hashes stayed
  unchanged. The unmodified gate then passed **36/36** again with zero console
  errors. No mutation was written to the source tree.

The exact Python command is:

```powershell
python -m pytest -q tests/virtual-realm/test_m2db4h_gpu_terminal_cleanup_contract.py tests/virtual-realm/test_m2db4h_gpu_presentation_epoch_source.py tests/virtual-realm/test_m2db4h_lifecycle_composition_telemetry_source.py tests/virtual-realm/test_m2db3_runtime_production_composition.py tests/virtual-realm/test_m2db2_gpu_presentation_port.py tests/virtual-realm/test_m2db2_gpu_presentation_syscall_adapter.py
```

Source pin (SHA-256):
`EE8F5BADFEA69231F74C34BFB8BF4596901DE3E45173DB450DD0C73FC80E97DF`.
Browser receipt: `#browser-receipt` in
`tests/virtual-realm/m2-gpu-terminal-cleanup-contract.test.html`, suite
`virtual-realm-m2-gpu-terminal-cleanup-contract`. No full bundle, general OS/app
runner, excluded First Shard source, shared discovery regeneration or global
license pass was used.

#### Original-resource issuer registry

`GpuDeviceBroker.js` now privately retains the original issuer and destruction
operation for each buffer or texture returned by its configured device. The
registry is an issuance and rollback prerequisite inside flat piece 9, not the
approved terminal channel. It does not enroll a resource into a Realm lifecycle,
authorize destruction after work invalidation, or change a presentation method,
application dependency, attempt binding or existing lifecycle wire.

`captureGpuOriginalResourceOwnershipSource(ownerAuthority, facade)` requires
exactly the original mount authority and original facade reference. It returns
a frozen two-method source: `snapshot(resource)` and `close()`. Their exact
argument counts are one and zero. Closing is idempotent and returns the same
frozen `{ closed: true }` receipt; it closes only that observer. Snapshot and
capture use private identity lookups without reflecting on caller selectors.
Historical lookup remains available after release, remount, device loss, tracker
replacement or forgotten accounting, but grants no current GPU authority.

Each snapshot is a new frozen seven-field record:

| Field | Meaning |
| --- | --- |
| `appId` | Original issuer's app identifier, not a selected Realm or operator. |
| `generation` | Original broker-published GPU generation. |
| `ownerEpoch` | Original mount/release epoch. |
| `brokerEpoch` | Original facade's broker invalidation epoch. |
| `resourceKind` | Exactly `buffer` or `texture`; other families are not enrolled. |
| `publicationStatus` | `pending`, `accepted` or `rejected` at this broker's return boundary, not outer app acceptance. |
| `destructionStatus` | `capture-pending`, `unavailable`, `not-observed`, `in-progress`, `returned` or `failed`. |

`returned` is sticky evidence that an observed invocation of the retained
original operation returned normally. It is not physical GPU reclamation,
Promise settlement, successful Realm teardown or a terminal Receipt11. A later
throwing repeat cannot erase a prior normal return. Invocation depth preserves
the existing repeated and nested direct-call behavior without reporting an
unfinished outer call as complete solely because an inner call threw.
After any normal return, `returned` also remains visible during later or nested
calls; it is not a statement that no destruction invocation is currently running.
Unwrapped direct resource calls remain unobserved: nonextensible objects and
resources created without accounting handles keep their legacy methods.

The source is kernel-internal and reveals no raw resource, issuer object,
original destructor, writable registry, enrollment method or execution method.
Its fixed frozen `GPU_ORIGINAL_RESOURCE_` errors use `REQUEST_INVALID`,
`SOURCE_REQUIRED`, `CLOSED` and `RESOURCE_REQUIRED`; issuance also uses
`RESOURCE_INVALID` and `RESOURCE_DUPLICATE`. Legacy raw allocation/destructor
failures keep their existing propagation behavior. This does not establish
hostile-realm isolation; future full-provider acceptance still requires that
separate boundary.

Issuance follows these ordered rules:

1. Immediately after the raw create call returns, reserve the exact object in a
   module-private weak index before reading its `destroy` property or running a
   post-call currentness check. Metadata comes from the immutable private facade
   binding, not mutable request fields. The index is shared across broker instances.
2. Reject any duplicate, including the same issuer or another resource family,
   before adopting or charging it. The duplicate request cannot overwrite or
   destroy the first issuance. Rejected-resource identities are not reusable.
3. Capture the original destruction operation once, independently of trackers
   and host-property wrapping. Cancellation during that getter records retirement
   intent and waits for capture to finish. Getter failure or a noncallable value
   reports `unavailable`; the tracked legacy installer still rejects a captured
   getter error, while the no-handle path preserves its previous acceptance.
4. Keep normal accounting-once-before-call semantics when a legacy wrapper is
   installed. Wrapped calls invoke the retained operation with its original
   receiver; replacing `resource.destroy` later cannot change private rollback.
   Accounting removal, observer closure and generation retirement never fabricate
   an observed successful call.
5. Roll back only the original request's private issuance. A late return after
   cancellation is captured before rejection. Rollback does not recursively invoke
   an already-running destroy or retry a failed attempt. Failed or unavailable
   unpublished candidates remain in a private per-broker retention set reachable
   through original issuer state. Retained observers, facades or resources can
   keep that state alive; no release/loss/observer-close drain or garbage-collection
   lifetime bound is promised. There is no new retry, abandonment or restart-
   reconciliation service.

The private set constructor, weak-map operations, set mutation operations,
original-call invocation and private-record freeze operation are import-pinned.
This prevents the reviewed post-import replacement attacks from exposing the
private rollback records or original issuer through those operations. It is not
a blanket claim that ambient JavaScript intrinsics or the existing broker are
isolated from hostile code in the same realm.
(Source: `webgpu-os/kernel/GpuDeviceBroker.js`
`retainOriginalResource`, `retireOriginalResource`, `invokeOriginalResourceDestroy`,
`captureGpuOriginalResourceOwnershipSource`, `_installTrackedDestroy`,
`_retireResourceRequest`, `_buildFacade`.)

The next integration must establish genuine per-Realm lifecycle ownership
**before allocation**, join that binding to this original issuer/resource record,
and authenticate the original teardown root. Do not retrofit ownership using
matching labels or historical receipts. Then install the destruction-only
terminal channel and prove stop/loss/rollback behavior before enabling ordinary
work-currentness denial. Existing presenter cleanup remains in use until that
replacement is usable. M1C production admission and the full process-owner
provider remain separate unfinished work in the same ten-piece ledger.

Registry verification uses the actual broker and tracker with controlled
JavaScript device/resource transport, not a physical WebGPU device:

- New registry browser gate: **36/36 passed**, including duplicate and late
  candidates, capture/getter/setter reentry, tracker-independent identity,
  unwrapped resources, thrown `undefined`, sticky normal return, nested calls,
  and post-import private-collection/freeze replacement attacks.
- Existing browser regressions: mount accounting **36/36**, guarded frame
  **32/32**, frozen terminal contract **36/36**. The four distinct gates total
  **140/140**, zero failures/skips/blocked cases or console errors.
- Independent scoped Python group: **74/74 passed** (registry20, mount19,
  guarded-frame17, terminal18). Entry106, B3 composition48 and dependency16 stay
  unchanged and do not import the new source. The earlier contract's 66-case
  receipt remains historical; it is not added to this new 74-case count.
- Guarded pre-read import closures: broker9, registry browser13, mount browser12,
  guarded-frame browser42 and terminal browser5. No broad app runner, full bundle,
  shared discovery/SPDX generator or First Shard traversal was used.
- Two memory-only negative controls verify gate sensitivity. Removing duplicate
  rejection produced **30 passed / 6 failed / 0 skipped**, specifically cases
  18–22 and 34. Using an ambient constructor for the private rollback set produced
  **35 passed / 1 failed / 0 skipped**, specifically the private-state leak check
  in case 36. Each variant served only the approved 13 modules plus HTML.
  Explicit completion stopped the helper with exit 0; all 14 disk hashes stayed
  unchanged. The original gate then passed **36/36** again with zero console errors.
- Independent source/test review found and closed the constructor interception
  leak before acceptance. The private freeze operation is also pinned. Final
  review found no production blocker and corrected the retention-lifetime
  wording: issuer references, not just the broker object, can retain unresolved
  candidates. No garbage-collection or cleanup-completion claim follows.

The exact scoped Python command is:

```powershell
python -m pytest -q tests/virtual-realm/test_m2db4h_gpu_original_resource_registry.py tests/virtual-realm/test_m2db4h_gpu_mount_allocation_source.py tests/virtual-realm/test_m2db4h_guarded_frame_telemetry_source.py tests/virtual-realm/test_m2db4h_gpu_terminal_cleanup_contract.py
```

Broker SHA-256:
`8D1F592478152D6FDCE90B504B3AE57ED1E9879D03CB7ECFAF20400946799EE7`.
The new browser receipt is `#browser-receipt` in
`tests/virtual-realm/m2-gpu-original-resource-registry.test.html`, suite
`virtual-realm-m2-gpu-original-resource-registry`. The old mount test exports only
its two existing transport helpers for reuse; its 36 cases remain unchanged.
The old mount Python gate changes only the additive export pin and the original
destruction call-target pin. No production source except `GpuDeviceBroker.js`
changes in this slice.

#### B3 pre-epoch lifecycle installation

The opt-in `installRealmM2RuntimeLifecycleComposition(originalB3, originalLifecycle)`
host function connects the original B3 runtime composition to the original
six-field lifecycle composition before its first process-owner acquisition
attempt. It accepts exactly two arguments and uses private original-object
lookup for both. A copied record, forwarding facade, proxy or matching label
cannot install a source. The lifecycle port must be the exact reference already
held in B3's dependency record. Installation performs no allocation, owner
acquisition, storage operation or GPU call.

This is a pre-epoch authentication prerequisite in flat piece 9. It does not
enroll buffers or textures, install the terminal channel or deny ordinary GPU
work. The full host provider must opt in; no boot registration or application
wire silently enables it. Uninstalled B3 compositions retain their legacy
authority behavior, with the shared early reservation and descriptor-snapshot
hardening. The source port now receives a fresh snapshot, not the caller's original
request object. B3 options17, output2, dependency16, GPU controller5,
bind4, release3, presentation9, lifecycle composition6 and the approved attempt
and v1/v2/v3 channels keep their exact shapes.

The private installer reserves its synchronous operation before source lookup
or diagnostics. It returns a frozen `{ installed: true }` receipt. Identical
installation is idempotent only before acquisition starts. Acquisition, close
and recursive installation cannot enter during installation. Any admitted
acquisition attempt, including invalid input, permanently forbids late
installation. This prevents retrospectively attaching a genuine lifecycle to
an epoch that was already opened under unrelated authority.

Acquisition uses the following sequence:

1. Reserve pending acquisition and its settlement promise before inspecting the
   caller's request. Reflective reentry cannot acquire a competing owner, install
   a source late or make close wait on an obsolete promise.
2. Validate the existing frozen acquire4 record and capture its four own data
   descriptors into one new frozen record. Only that snapshot is forwarded to
   the configured full process-owner port and used for later identity checks.
3. Retain the returned source handle immediately, then construct the existing
   six-field process-owner facade. The separate genuine identity authority's
   two-field handle is not adapted into a full process owner.
4. For an installed composition, capture the genuine begin4 binding using the
   returned owner ID and original request's app, lifecycle generation and work
   signal. Reassert genuine currentness and match the original identity's app,
   owner, lifecycle generation and operator to that snapshot.
5. Recheck B3 closure before binding the GPU epoch. B3 has already captured its
   syscall functions into a fresh frozen local record. The local bind record and
   adapter construction do not call supplied operations between the final genuine
   check and epoch publication. This relies on the existing trusted-intrinsics
   construction model, not isolation from hostile global prototype mutation.
6. Retain the genuine companion on the private acquisition/active-owner record.
   A rejected capture, identity mismatch or reentrant close uses the existing
   cleanup-bearing rollback record. Failed source release remains available to
   explicit composition-close retry; no handle is discarded as successful cleanup.

The configured full provider and its six-field handle remain a trusted structural
boundary. The genuine lifecycle source authenticates the returned owner ID's
association with the original work root. It does not authenticate the provenance
of that full handle, its child operations or its release implementation. Those
remain part of the missing genuine full-provider acceptance.

The companion preserves its original teardown validator, but this slice does
not expose or invoke it for GPU destruction. Work invalidation after a successful
acquisition does not revoke existing GPU forwarding yet. Do not infer effect-time
authorization from this one acquisition check. Per-operation ownership must still
reach the original issuer before each raw allocation; a shared facade cannot be
permanently labeled with one Realm owner or used to adopt older resources.

New fixed diagnostics use `VR_M2DB4H_RUNTIME_LIFECYCLE_` with `REQUEST_INVALID`,
`SOURCE_REQUIRED`, `PORT_MISMATCH`, `INSTALLATION_PENDING`, `ACQUISITION_STARTED`,
`ALREADY_INSTALLED`, `CLOSED` or `IDENTITY_MISMATCH`. Genuine source failures keep
their original error codes and existing rollback failures retain aggregate errors.
Successful first installation emits `virtual-realm.m2db4h.lifecycle.installed`
under the installation fence; existing owner-bound/released logs remain in use.
(Source: `webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`
`installRealmM2RuntimeLifecycleComposition`, `createOwnerCoupledProcessPort`.)

The direct genuine-source import intentionally changes B3's exact closure from
48 to 88 modules. Entry remains 106 and still excludes this host-private source.
Earlier 48-module B3 receipts in this document describe their historical slices;
they are not a claim about the current B3 graph. The issuer registry and inert
terminal contract are not imported into B3. No full bundle or global discovery
generator is used because First Shard remains outside the permitted scan.

Accepted verification for this slice:

| Browser gate | Passed cases | Guarded module closure |
| --- | --- | --- |
| New runtime lifecycle binding | 32/32 | 180 |
| Preserved B3 production composition | 11/11 | 159 |
| Genuine lifecycle composition companion | 32/32 | 74 |
| Original GPU epoch provenance | 36/36 | 19 |
| Original buffer/texture issuer registry | 36/36 | 13 |
| Frozen terminal cleanup contract | 36/36 | 5 |

These six gates total **183/183 browser cases**, with zero failures, skips,
blocked cases or console errors. The new gate uses actual lifecycle, operator,
allocation and identity authorities with the existing controlled full-provider
test boundary. It is not physical GPU execution or a genuine full-provider test.
The preserved lifecycle gate includes its existing protected-OPFS case.

The final exact 22-file Python group passed **305/305** in 92.87 seconds, exit0:
the new gate's18 checks plus287 preserved checks. Maintenance of21 existing
Python gate files only updates the intentional B388/import/export boundary and
truthful source pins. Entry exclusion, exact allowlists, forbidden execution
checks and earlier test cases remain. The two reused browser test files add only
helper exports; their original32 and11 cases are unchanged. No broad test
discovery, app runner or bundle was needed.

Two memory-only negative controls verify sensitivity without editing source:

- Removing the exact lifecycle-port reference check gives31 passed/1 failed,
  specifically case6.
- Removing the genuine capture/currentness/identity-check block gives23 passed/
  9 failed, specifically cases20–28. The unexpectedly admitted owners also trip
  the existing owner-active cleanup guard. This is negative evidence, not a
  claim that those intentionally broken acquisitions completed cleanup.

The exclusive loopback helper served only the180 approved modules plus the HTML
document. Explicit completion stopped it with exit0 and confirmed all181 disk
SHA-256 hashes unchanged; its listening port is closed. The unmodified new gate
then passed32/32 again with zero console errors. Independent production/test/doc
review found no production blocker and corrected full-handle provenance and
legacy request-identity wording before acceptance.

Production B3 SHA-256:
`7559A00F7D28CED2AE30F1D49F33392E0039905B6B4850C721725BDD7D5A8B46`.
New browser test SHA-256:
`35D053B1AEBD2497B7061A17B22FB39C489366A97F2C9B83ED14DE2FEDCC9A0C`.
New Python gate SHA-256:
`61E80B16FB1219732E077974DB21BDA8B527639F876B61CDC492752E0233BC32`.

The new browser receipt is `#browser-receipt` in
`tests/virtual-realm/m2-runtime-lifecycle-binding.test.html`, suite
`virtual-realm-m2-runtime-lifecycle-binding`. Run the new scoped static gate with:

```powershell
python -m pytest -q tests/virtual-realm/test_m2db4h_runtime_lifecycle_binding.py
```

This command runs the new18 checks, not the full305-case regression receipt.
The exact22-file regression command is:

```powershell
python -m pytest -q tests/virtual-realm/test_m2db4h_runtime_lifecycle_binding.py tests/virtual-realm/test_m2db3_runtime_production_composition.py tests/virtual-realm/test_m2db4h_frame_producer_telemetry_source.py tests/virtual-realm/test_m2db4h_gpu_original_resource_registry.py tests/virtual-realm/test_m2db4h_gpu_mount_allocation_source.py tests/virtual-realm/test_m2db4h_gpu_presentation_epoch_source.py tests/virtual-realm/test_m2db4h_gpu_terminal_cleanup_contract.py tests/virtual-realm/test_m2db4h_lifecycle_generation_head_storage.py tests/virtual-realm/test_m2db4h_lifecycle_session_authority.py tests/virtual-realm/test_m2db4h_lifecycle_allocation_authority.py tests/virtual-realm/test_m2db4h_lifecycle_composition_telemetry_source.py tests/virtual-realm/test_m2db4h_local_operator_snapshot_source.py tests/virtual-realm/test_m2db4h_lifecycle_participant_authority.py tests/virtual-realm/test_m2db4h_process_owner_identity_authority.py tests/virtual-realm/test_m2db4h_local_operator_policy_head_storage.py tests/virtual-realm/test_m2db4h_process_owner_telemetry_binding.py tests/virtual-realm/test_m2db4h_runtime_attempt_binding.py tests/virtual-realm/test_m2db4h_runtime_diagnostics_source.py tests/virtual-realm/test_m2db4h_local_selection_head_storage.py tests/virtual-realm/test_m2db4h_lifecycle_port_composition.py tests/virtual-realm/test_m2db4h_runtime_host_lifecycle.py tests/virtual-realm/test_m2db4h_surface_receipt_provenance.py
```

All imports were checked against reviewed allowlists before browser execution. No excluded
First Shard source or directory was opened or traversed.

The following prospective allocation slice connects this pre-epoch identity to
explicit private resource cohorts. The subsequent
[authenticated terminal endpoint](#authenticated-cohort-terminal-destruction)
adds destruction-only execution; standard-adapter integration and private
delivery into the presenter still require completion.
Only after usable terminal cleanup replaces the presenter's ordinary-job cleanup
may ordinary work denial be enabled. Production M1C admission, genuine
activation-child authority and full-provider registration remain unfinished;
the two ten-piece roadmaps stay flat.

#### Prospective original GPU allocation cohorts

The Virtual Realm now has explicit owner-bound buffer and texture creation
routes. A cohort is the private set of original resources issued through one
particular route. Cohorts record ownership at creation, not by attaching a Realm
label to an entire shared GPU facade or by adopting a resource afterward.
This is a piece-9 prerequisite, not standard renderer integration or a live
terminal cleanup channel.

Three existing authority layers remain separate:

| Layer | Source and output | What it establishes |
| --- | --- | --- |
| Generic original GPU issuer | `createGpuOriginalResourceAllocationCohort(originalMount, originalFacade, admit)` returns frozen identity/createBuffer/createTexture/snapshot/close | Exact original mount/facade issuance and disjoint resource membership. Its required synchronous hook only restricts creation; it conveys no Realm provenance. |
| Original B3 owner | `captureRealmM2RuntimeGpuOwnerSource(originalB3)` returns a frozen capture-only source | One completed, installed B3 acquisition's original genuine owner, currentness check and retained original-root teardown validator. |
| Realm allocation route | `createRealmGpuAllocationCohort(originalB3, originalMount, originalFacade)` returns frozen createBuffer/createTexture/close | Internally derived genuine-owner checks joined prospectively to allocations through that route. No caller-provided guard, generic cohort or resource list can substitute. |

The generic broker captures its original allocation closures privately. Ordinary
facade methods reuse the same buffer/texture implementation with no cohort.
Owned calls bind their request to a private cohort before descriptor inspection.
When the raw method returns, the issuer reserves original object identity and
cohort membership before reading `destroy`, checking acceptance or publishing
the resource. Duplicate identity is rejected before any second attribution,
charge or rollback candidate can replace the first issuance.

Each owned request runs the full broker check, including external kernel
currentness getters, before the synchronous owner restriction. A final
broker-owned checkpoint then rechecks the request, device publication, original
mount lease and recovery admission without invoking another kernel getter.
This ordering prevents a getter from aborting Realm work after the final owner
check but before raw allocation. Revocation during that owner check still
rejects through the final broker checkpoint. It relies on trusted broker
records, methods and intrinsics; it is not isolation from malicious direct
kernel mutation that bypasses broker publication.

Admission reentry into the same cohort is fenced. Descriptor, raw-method,
destructor, accounting and wrapper callbacks are followed by the existing
acceptance checkpoints. Invalidation before allocation denies the raw call;
invalidation after a returned resource retains its original rejected issuance
and uses captured-operation rollback without requiring renewed work authority.

There is no ambient current-cohort variable. Ordinary allocations before,
between or recursively inside owned calls remain ordinary. Two genuine owners
can use the same original mount/facade at different lifecycle epochs without
relabelling earlier resources. Two cohorts with equal scalar identity also
remain separate original memberships. A future cleanup consumer must authenticate
the exact original cohort, not merely compare its identity tuple.

The B3 capture source rejects acquisition-in-progress, uninstalled, released,
releasing, closing and obsolete owners. Genuine checks run under an observation
fence and are followed by another check of the original active record. The
cached companion belongs to that one record. Its teardown method deliberately
retains the original lifecycle validator rather than using the latest owner's
work signal or requiring the old owner to remain current. This grants root
validation only, not destruction authority.

`captureRealmGpuAllocationCohortSource(originalCohort)` uses private original-object
lookup. Copies, proxies, generic cohorts and matching labels do not authenticate.
The frozen source contains `identity`, `snapshot(resource)` and
`assertTeardown({ signal })`. Identity is the existing terminal identity4:
app, genuine owner, lifecycle generation and original device generation. The
resource snapshot is a new flat nine-field observation:

```javascript
{
    appId, ownerId, lifecycleGeneration, deviceGeneration,
    ownerEpoch, brokerEpoch, resourceKind, publicationStatus, destructionStatus
}
```

The original generic snapshot7 and all existing app wires remain unchanged.
No snapshot exposes a resource, original destructor, root signal, mutable record,
enrollment method or scheduling callback. Pending and rejected candidates remain
observable through their original cohort, including unavailable or failed
destructor capture and failed rollback. Creation close returns a cached frozen
`{ closed: true }` receipt, denies later creation and does not destroy anything.
Historical membership and original-root teardown validation survive that close.

The initial allocation-only slice retained all cohort issuances, not only
accepted resources, without a drain. The following terminal slice now drains
each observed normal original-destroy return once while preserving weak historical
membership. Unresolved entries retain no guaranteed lifetime bound. Observed
synchronous destructor return still does not prove physical GPU reclamation,
asynchronous completion or full-owner terminal cleanup.

The trusted host explicitly supplies an authentic same-app mount/facade pair.
The route checks the original issuer's app against the genuine B3 owner. It does
not independently prove that the configured full provider uses that mount, or
authenticate a selected Realm, activation child or full process-owner handle.
Those joins remain part of provider acceptance.

Most importantly, these routes are **prospective and unwired**. B3 source capture
requires completed acquisition, so calling this factory afterward cannot prove
that no earlier adapter dispatch occurred. The next integration must capture and
install immutable routes before adapter publication. Standard presentation9,
dependency16, B3 options17/output2, the attempt binding and the approved v1/v2/v3
channels remain unchanged. Ordinary renderer work and ordinary cleanup retain
their current behavior. Do not enable ordinary-work denial until authenticated
terminal destruction and private delivery are usable.

Sources: `webgpu-os/kernel/GpuDeviceBroker.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`webgpu-os/kernel/realm/RealmGpuAllocationCohort.js`.

The new combined browser gate and seven preserved gates pass **259/259** cases:

| Browser gate | Passed cases | Guarded module closure |
| --- | --- | --- |
| Original allocation cohort | 40/40 | 190 |
| B3 runtime lifecycle binding | 32/32 | 180 |
| B3 production composition | 11/11 | 159 |
| Genuine lifecycle composition companion | 32/32 | 74 |
| Original GPU epoch provenance | 36/36 | 19 |
| Original buffer/texture issuer registry | 36/36 | 13 |
| Exact GPU mount allocation source | 36/36 | 12 |
| Frozen terminal cleanup contract | 36/36 | 5 |

All eight browser receipts have zero failures, skips or console errors. The
new40 includes two genuine lifecycle epochs on one unchanged mount/facade,
ordinary and sibling recursive allocations, original-only source authentication,
pre-raw denial, post-raw rollback, retained failed/unavailable candidates and
original-root teardown after B3 release/closure. Case26 distinguishes the final
callback-free checkpoint from the rejected post-admission kernel-getter ordering.
These are real broker/lifecycle/identity sources over instrumented JavaScript
resources and a controlled full-owner service boundary, not physical GPU or
genuine full-provider evidence. The preserved lifecycle gate includes protected
OPFS; the new cohort fixture uses its controlled storage boundary.

The exact six-file Python group passes **100/100** in35.76 seconds, exit0:
newcohort20, mount19, registry20, lifecycle-binding18, B3production5 and
terminal-contract18. The existing environment emits a `requests` dependency
compatibility warning; it causes no failures. Run that group with:

```powershell
python -B -m pytest -q tests/virtual-realm/test_m2db4h_gpu_allocation_cohort.py tests/virtual-realm/test_m2db4h_gpu_mount_allocation_source.py tests/virtual-realm/test_m2db4h_gpu_original_resource_registry.py tests/virtual-realm/test_m2db4h_runtime_lifecycle_binding.py tests/virtual-realm/test_m2db3_runtime_production_composition.py tests/virtual-realm/test_m2db4h_gpu_terminal_cleanup_contract.py
```

The final **23-file Python regression passes325/325** in119.42 seconds, exit0.
Its exact file set is the22-file command in [B3 pre-epoch lifecycle installation](#b3-pre-epoch-lifecycle-installation)
plus `tests/virtual-realm/test_m2db4h_gpu_allocation_cohort.py`. The100-case focused
group is a subset, not an additional100 cases. Independent review found and fixed
the post-admission kernel-getter ordering before acceptance, then found no
remaining blocker in the production, test and documentation scope. Scoped
documentation checks validate metadata, balanced fences and all104 Markdown file
links across the three edited plan pages. Both flat ten-piece ledgers retain
identical piece9 rows.

At the allocation-cohort gate, source closures were broker9, B388 and Entry106.
The separate Realm cohort entry joined them in a96-module closure. These are
historical boundaries. Its190-module browser allowlist was checked before reading each dependency;
unknown or excluded paths fail before opening. No First Shard source or directory
is opened or traversed. No full bundle, broad runner or global documentation/
discovery generator is used. Three existing Python gates receive narrow source/
export pins; two existing browser gates add helper exports without changing
their original32 and36 cases. Fixed errors and read-only status projections
provide diagnostics without adding reentrant logging to the allocation hot path.

Accepted production SHA-256 pins:

| Source | SHA-256 |
| --- | --- |
| `GpuDeviceBroker.js` | `8D0A63A63CBBE32FF721A3B64A41724FBED4F051D87AA49BC20166D00E0017DE` |
| `RealmM2RuntimeComposition.js` | `A346BB341F31EBA01B4359F94F0DA44DCC9C2EC1C25D37E184873B514A31B2C4` |
| `RealmGpuAllocationCohort.js` | `0438305F4A08FED689E4901684765BD495EBE24C700545C7B8A5D184C98BDD2E` |

New browser test SHA-256:
`3CFD1D5E0CBEF6B9626BFDF56895DF7527F2A4BAC892253B63611309C08435CA`.
New Python gate SHA-256:
`0E4B259150C62B4AE53969D063D55EA6B0B1E89A8F6EF804B092DCFF11521E02`.
The browser receipt is `#browser-receipt` in
`tests/virtual-realm/m2-gpu-allocation-cohort.test.html`, suite
`virtual-realm-m2-gpu-allocation-cohort`.

#### Authenticated cohort terminal destruction

The Virtual Realm now has a separate, callable destruction-only endpoint for
each original allocation cohort. It uses the accepted terminal v1 wire and the
cohort's original genuine teardown validator. It does not depend on an active
work signal, a current mount or an ordinary scheduling callback. The endpoint is
host-private and remains unwired into Entry, the standard adapter and presenter.
It accepts only buffers and textures originally issued through that exact cohort.

`captureRealmGpuAllocationCohortTerminalDelivery(originalRealmCohort)` returns one
cached frozen Delivery5 containing the original Port3 and its identity4. Private
original-object lookup rejects generic cohorts, copied objects, proxies, observer
sources and identity lookalikes. The unchanged cohort output3 and observation
source3 gain no methods. Only the separate delivery port grants destruction.

The sole port method is synchronous `destroyOwnedResources(request5)`. Its request
is the existing exact frozen identity4 plus `signal`. It reserves an operation
fence before reflective validation, snapshots the request, and derives a local
`{ signal }` request for the original owner's retained teardown validator. Every
call, including empty and repeated calls, must authenticate that original live
native root. A copied live signal, work or construction signal, different owner
tuple or caller-supplied callback cannot authorize it. No cached receipt bypasses
the root check on a later call.

The generic broker primitive is
`destroyGpuOriginalResourceAllocationCohort(originalGenericCohort, authorize)`.
Its original-cohort map is private. The required synchronous function restricts
that existing generic capability; it supplies no Realm provenance, receives no
arguments or receiver authority, and cannot select resources. The Realm endpoint
never exposes the generic cohort or accepts a caller-provided restriction. It
supplies its own original-root validator and wraps the returned count4 in the
unchanged validated Receipt11.

The terminal algorithm has these bounded stages:

1. Reserve same-cohort terminal execution before invoking authorization. Creation
   and recursive terminal calls cannot enter through that reservation.
2. Authenticate the original root, then permanently seal further cohort creation.
   Invalid requests or denied initial authorization do not seal creation.
3. Reject with `GPU_COHORT_CLEANUP_ALLOCATION_PENDING` if any explicit cohort
   creation is still on the stack. The creation remains sealed, but no aggregate
   receipt is returned. Its raw method could still return an unknown resource;
   counting that as an empty, completely destroyed cohort would be false.
4. Snapshot at most 256 retained candidates using pinned Set iteration and a
   pinned null-prototype table. An inherited array-index setter must never see
   a private issuance. Visit each snapshot entry once using the captured count.
   Do not rotate a live iterator or repeatedly scan
   an unavailable first entry without a bound.
5. Reauthenticate before each candidate. Skip already returned, still capturing,
   currently executing or unavailable original operations. Release the original
   accounting closure if present, then reauthenticate and reread issuance state
   immediately before invoking the captured original destructor. An intervening
   original attempt prevents a duplicate terminal attempt for that candidate.
6. Reauthenticate after the destructor. Original errors remain unresolved; an
   authorization error stops the pass. Completed observations remain recorded
   even when a later root check prevents publication of a receipt.
7. Move visited unresolved candidates to the retained Set's tail. Later explicit,
   independently authorized calls reach other resources instead of starving
   behind the same failure. No timer, task, Promise, automatic retry or queue
   submission is introduced.
8. Reauthenticate before projecting the aggregate and again before the Realm
   endpoint publishes its validated Receipt11. Clear operation reservations on
   success or error without reopening sealed creation.

Allocation depth is reserved before the explicit creation route's first host
check and released in `finally`. This covers descriptor inspection, raw method
execution, destructor capture and accounting callbacks. A terminal request from
one of those callbacks seals creation and returns no misleading receipt. When
the raw allocation unwinds, existing captured-operation rollback retains the
exact returned candidate. A later authorized terminal call then sees its actual
destroyed or unresolved state. Rollback remains distinct from terminal execution;
it does not require renewed work authority.

Internal cumulative owned/destroyed counts use BigInt. A conservative creation
reservation prevents the lifetime total plus active candidate reservations from
exceeding the safe-integer wire limit before raw allocation. Counts never
saturate, reset on close or silently discard candidates. The frozen count4
projects only when `owned = destroyed + unresolved` holds exactly. Abandonment
is always 0 in this implementation. Mount release, recovery, device replacement,
an unavailable destructor or forgotten accounting is not proof of abandonment.

Every observed normal call to the retained original destructor settles its
cohort membership once, including ordinary wrapped destruction and rollback
before any terminal call. Settlement increments the cumulative destroyed count
and removes the issuance from both cohort retention and any unresolved rollback
Set. A later wrapped call preserves existing original-call behavior without
counting that resource twice. Historical snapshot7/snapshot9 still authenticate
the original resource even after strong retention is drained.

The returned status is `destroyed` when no resources remain unresolved, including
an empty cohort, or `cleanup-pending` when another authorized pass is needed or
an operation remains unavailable. The wire still supports `abandoned`, but this
executor does not claim that outcome without an independent authentic loss
source. An observed synchronous destructor return is not Promise settlement,
physical GPU reclamation, renderer quiescence or full-owner cleanup. The 256
bound is on executor candidate visits, not on arbitrary behavior inside trusted
host callbacks or original resource operations.

Fixed broker errors use `GPU_COHORT_CLEANUP_` with `REQUEST_INVALID`,
`SOURCE_REQUIRED`, `OPERATION_PENDING`, `ALLOCATION_PENDING` or `COUNT_INVALID`.
The allocation route adds `TERMINAL_PENDING` and `CAPACITY_EXCEEDED` under its
existing `GPU_ALLOCATION_COHORT_` family. The Realm lookup/operation fence uses
`VR_M2DB4H_GPU_COHORT_TERMINAL_` with `REQUEST_INVALID`, `SOURCE_REQUIRED` or
`OPERATION_PENDING`. Original contract and teardown errors retain their codes.
Errors and historical projections provide diagnostics without adding logging
callbacks between authorization and destruction.

At this terminal endpoint's acceptance, standard integration still required a
cycle-free pre-bind source path: the Realm cohort module imported B3, and its current-owner capture rejected
acquisition-in-progress. Importing that module back into B3 would create a cycle
and would not establish ownership before adapter publication. Authenticate the
exact facade returned by the configured syscall source against the selected
original mount; matching app/device labels are insufficient. Deliver this
endpoint privately to the renderer and replace its ordinary-job destruction
before enabling ordinary-work denial. Preserve surface release, producer and
subscription disposal, capability retirement and late-result rollback as well.

The presenter handoff has additional acceptance requirements inside piece 9:

- Bind the exact original cohort delivery to the actual presenter generation,
  not merely an equal identity tuple. Establish access to the original teardown
  root before startup can fail; waiting for Entry's final stop is too late.
- Always inspect that cohort during terminal cleanup, even if the presenter's
  local lease count is zero. Rejected, unpublished allocations can still require
  cleanup without ever having entered the local resource owner.
- Retire local bookkeeping only from appropriate terminal evidence. Calling
  `disposeSynchronously()` after aggregate destruction repeats original release
  callbacks; calling `abandon()` mislabels successful destruction. Neither is an
  acceptable adapter for the new aggregate Receipt11.
- Keep cumulative cohort counts distinct from current presenter lease counts.
  Successful resize releases are already historical destruction observations.
  Preserve existing legacy LIFO release behavior; separately establish and test
  the terminal mode's ordering instead of silently substituting cohort iteration.
- Retain the exact delivery, teardown root, unresolved state and completed cleanup
  steps after `cleanup-pending` or failure. The current stop/dispose path clears
  references and memoizes completion too early for explicit terminal continuation.
  A new mode must not publish successful disposal or permit restart over unresolved
  ownership. Concurrent cleanup requests must share the current operation without
  making a failed operation the permanent final result.
- Preserve producer, GPU-resource, surface, subscription and capability cleanup
  order, with retryable remaining steps. Device-loss handle abandonment in the
  legacy presenter is not evidence for terminal `abandonedResourceCount`.
- Bind release operations to their original generation, not mutable
  `this.#facade`. Producer, surface, subscription and capability cleanup are not
  covered by the buffer/texture cohort and must remain usable after work stops.

These are implementation requirements, not implemented presenter behavior.
(Sources: `webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuPresenter.js`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuResourceOwner.js`.)

Only the broker and separate Realm cohort module changed production behavior in
that terminal slice. Its historical boundaries were broker9, B388, Entry106 and Realm cohort96;
the frozen terminal contract, dependency16, presentation9, B3options17/output2,
controller5, bind4/release3 and approved attempt/v1/v2/v3 channels are unchanged.
No full provider, selected-Realm/activation join, M1C production opener or first
submitted city frame is accepted by this endpoint.

Sources: `webgpu-os/kernel/GpuDeviceBroker.js`;
`webgpu-os/kernel/realm/RealmGpuAllocationCohort.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuTerminalCleanupContract.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuPresenter.js`.

The accepted execution evidence is scoped to this endpoint:

- Browser: **299/299** across nine gates, zero failures, skips, blocked cases
  or final-run console errors. New terminal execution40; preserved cohort40,
  runtime binding32, B3 production11, lifecycle companion32, epoch36, issuer36,
  mount36 and terminal contract36. Resources are instrumented JavaScript objects;
  the configured full-owner service is controlled, not a new production provider.
- Python: **349/349** across the previous exact 23-file regression group plus
  `tests/virtual-realm/test_m2db4h_gpu_cohort_terminal_cleanup.py`. Its 24 new
  checks and the focused seven-file **124/124** group are included in 349, not
  additional checks. They pin ownership, reentry, original-root checks, fair
  bounded traversal, count conservation and the unchanged public boundaries.
- Exact guarded browser closures are191/190/180/159/74/19/13/12/5. The source
  closures remain broker9, B388, Entry106 and Realm cohort96. Unknown or excluded
  imports reject before source reads. No First Shard traversal, broad runner,
  full bundle or shared discovery generation was performed by this slice.
- Independent audit found and fixed inherited-array-setter exposure of private
  candidate records. Case40 now tests the null-prototype snapshot with no tracker.
  The first browser run passed36 and failed4 because test cleanup tried to retire
  lifecycle authority after aborting its teardown root. Cases31/34/35/36 now retire
  and release the fixture before intentionally aborting that root; all original
  denial and evidence assertions remain. The final clean-tab run passed40/40.

The browser receipt is `#browser-receipt` in
`tests/virtual-realm/m2-gpu-cohort-terminal-cleanup.test.html`, suite
`virtual-realm-m2-gpu-cohort-terminal-cleanup`. To run just the new Python gate:

```powershell
python -B -m pytest -q tests/virtual-realm/test_m2db4h_gpu_cohort_terminal_cleanup.py
```

Historical terminal-slice implementation SHA-256 pins:

| File | SHA-256 |
| --- | --- |
| `GpuDeviceBroker.js` | `B23E2D4FDF3341323CCADC20FEECC9F2E4ED683500631BE6F936AEB5BE2A8A8B` |
| `RealmGpuAllocationCohort.js` | `0CCA08281A767374D791C1E8A593CB86666B31B6EFFC152F032D15A0DABBEFE9` |
| `RealmM2RuntimeComposition.js` (unchanged) | `A346BB341F31EBA01B4359F94F0DA44DCC9C2EC1C25D37E184873B514A31B2C4` |
| New browser test | `9A76F817004319803268B5C78B4C192EE2165C08B2CFF99D005634232F1BE27D` |
| New Python gate | `3D30966240F330F2C945F95779383D16DCF6A5356EF03F30CCE5090246C2450B` |

#### Cycle-free pre-bind GPU allocation association

Piece 9 now includes the cycle-free ownership prerequisite. An original B3
composition can opt into an exact original broker mount/facade pair before its
first acquisition attempt. Acquisition prepares a genuine owner-bound allocation
cohort before binding the GPU epoch; the original B3 capture APIs require a
completed acquisition to expose the primary cohort. The later stable-port
lookup can discover a paused source earlier, without permitting allocation.
At this slice's acceptance, it did not route standard renderer
allocations into the cohort or deliver terminal cleanup to the presenter. The
later adapter-routing section below supplies only the former. It remains one continuation within
the existing flat ten-piece plan, not a new milestone or provider acceptance.

The implementation separates these existing responsibilities:

| Module | Responsibility in this continuation | Still outside its authority |
| --- | --- | --- |
| `GpuDeviceBroker.js` | Authenticate the original mount/facade pair through private issuer membership; return frozen Source2 with historical Identity4 and guarded `assertCurrent()` | Realm lifecycle, selected Realm, full-provider origin, resource enrollment or teardown |
| `RealmLifecyclePortComposition.js` | Read-only exact-original companion authentication through a private weak registry | Caller registration, copied companion acceptance or new lifecycle wire |
| `RealmGpuAllocationCohortCore.js` | Construct the genuine-owner cohort and its separate private restriction controls without importing B3 | Standard-adapter route installation, full-provider authority or ordinary-work denial |
| `RealmM2RuntimeComposition.js` | Install the original association, prepare and retain the primary cohort before bind, compare actual configured `getDevice()` results, and retire private controls with the original owner | Presenter terminal transport, selected-Realm/activation joining or atomic effect-time dispatch |
| `RealmGpuAllocationCohort.js` | Preserve the existing completed-B3 factory and original source/delivery exports by delegating to B3 and the core | A second cohort implementation or B3-to-wrapper import |

`captureGpuOriginalFacadeBindingSource(originalMount, originalFacade)` requires
exactly two arguments. Its original-object lookup performs no caller property
reflection. The frozen source has exactly `identity` and `assertCurrent`; the
identity retains `appId`, `generation`, `ownerEpoch` and `brokerEpoch` from the
original issuer. Capture validates currentness immediately. Each exact-zero-arg
check reserves a local observation fence before invoking the retained broker
guard, releases it in `finally`, and returns the same historical identity.
Copied or proxy facades, matching labels and a mount from another pair cannot
authenticate. No resource tracker, allocation or terminal authority is acquired.

The core requires the exact genuine lifecycle companion, original mount and
original facade. There is no public registry writer or caller-supplied admission
callback. Its frozen result2 contains `cohort` and `control`. Cohort3 remains
`createBuffer`, `createTexture`, `close`; the private Control4 is `pause`, `resume`,
`close`, `isObserving`. These controls only restrict their own cohort and cannot
replace genuine currentness. A shared original-companion observation fence
rejects sibling-cohort reentry; per-core observation state also preserves B3's
existing source-capture fence. Both unwind without leaving admission stuck.
The exact-one-argument `assertRealmGpuAllocationOwnerCurrent(originalCompanion)`
authenticates the companion and owns that shared reservation. B3 observations,
initial acquisition, final pre-bind checks and configured device checks use the
same helper as cohort admission. This also rejects the reverse B3-observation to
cohort-allocation path; a one-direction-only fence would regress old behavior.
It accepts no callback and adds no registration or wire authority.
Explicit public close retains the prior closed error; private retirement retains
the prior owner-not-current error and never destroys a resource by itself.

`installRealmM2RuntimeGpuAllocationBinding(originalB3, originalMount,
originalFacade)` is a separate exact-three-argument host call. It requires the
existing genuine lifecycle installation first, reserves before broker callbacks,
and refuses installation after even a malformed first acquisition attempt.
An identical original pair is idempotent only before acquisition begins; an
authentic alternative pair cannot replace it. The installation receipt remains
the frozen one-field `{ installed: true }`. Installation makes no configured
`getDevice` call and allocates no GPU resources.

During opted-in acquisition, B3 invokes its already captured configured
`getDevice` method and requires reference equality with the installed original
facade. It revalidates the original broker source and genuine owner after the
callback, then constructs a resource-empty cohort before GPU epoch binding.
The bound syscall snapshot replaces only `getDevice` with the associated probe;
later device acquisition repeats that exact-reference check. Shared probe
reservation rejects callback reentry and always resets in `finally`. Source
namespace mutation cannot replace the previously captured method. Legacy B3
acquisition without installation keeps its prior lookup timing and routes.

`captureRealmM2RuntimeGpuAllocationCohort(originalB3)` requires exactly one
original composition and a completed current acquisition. It returns the cached
primary cohort, never creates one or exposes its control. Provider callbacks,
request reflection and owner-bound diagnostics cannot capture it early. The old
factory can still construct disjoint cohorts after completed acquisition, with
or without the new installation; these never replace the primary cohort.

Release pauses private controls before checking pending work. A failure before
epoch retirement resumes them; successful epoch retirement closes them
irreversibly before full-owner release. Later source-release failure remains
retryable and cannot reopen allocation. Rejected acquisition closes unpublished
controls before rollback. Irreversible retirement drains B3's private control
set and primary reference, so a caller-held old owner handle does not retain all
its historical cohorts. Caller-retained cohorts, observation sources and genuine
terminal deliveries remain usable for historical evidence and authorized cleanup.
No resources can escape the new pre-bind primary path before publication, so
failed pre-bind acquisition does not need an invented teardown root.

At this slice's acceptance, the exact association was a momentary observation at the wrapped lookup boundary,
not an atomic joint lifecycle/GPU check or final renderer publication guarantee.
The standard adapter inspected mutable facade metadata after this return.
The integration review therefore required coverage after authentic `__isGpuFacade` or
`__generation` validation aborts the original work root while a distinct live request
signal is supplied. That path requires provenance-aware final publication and
effect-time denial; checking only the request signal is insufficient. Do not
enable ordinary-work denial before original terminal delivery and retry-safe
presenter cleanup are connected. The presenter requirements above remain open.

The source closures are now broker9, core60, B396 and compatibility wrapper97;
Entry remains106 and does not import the new core. B3 never imports the wrapper,
and the core imports neither B3 nor the wrapper. Earlier B388/cohort96 receipts
remain historical. Dependency16, presentation9, B3 options17/output2,
controller5, bind4/release3, terminal Request5/Receipt11 and approved attempt and
v1/v2/v3 host channels are unchanged. No first frame, production M1C opener,
full process-owner provider or physical GPU reclamation is accepted here.

The new browser gate passes **40/40** and all nine preserved gates pass
**299/299**, giving **339/339**, with no failures, skips, blocked cases or
final-run console errors. It covers configured facade replacement, work and
operator invalidation, close reentry, original-object forgery, pre-publication
capture fencing, sibling observation reentry, recoverable release, historical
terminal cleanup and unchanged legacy routing. The initial 39/40 result exposed
an incorrect test expectation after B3 close; the corrected case requires the
actual disposed epoch state and successful source-owner rollback.

Final review also identified the reverse B3-observation to cohort-allocation
reentry path. The shared authenticated helper closes it. Case29 now tests both
primary capture and B3 owner-source capture, while cases36/38 test helper arity,
original provenance, recursive rejection and recovery after a thrown check.
The complete339-case browser group was rerun after that correction and passed.

The final 25-file Python group passes **373/373** in 132.06 seconds after the
bidirectional guard correction: the previous
24-file terminal regression group contributes349 and the new pre-bind gate24.
The focused five-file106/106 run is included, not additional. Legacy changes
update reviewed import/export and moved-source pins while preserving case counts.

Exact guarded browser closures are193/192/191/187/166/74/19/13/12/5 for
pre-bind, terminal execution, cohort, B3 lifecycle binding, B3 production,
lifecycle companion, epoch, registry, mount and terminal contract respectively.
Unknown/excluded imports reject before source reads. These tests use actual
broker/lifecycle authorities with instrumented JavaScript resources and controlled
full-owner services, not native GPU execution or a new production provider.
No First Shard scan, broad runner, full bundle or global documentation generator
is required or was performed for this continuation.

The browser page is
`tests/virtual-realm/m2-gpu-prebind-allocation-binding.test.html`; inspect
`#browser-receipt` for suite `virtual-realm-m2-gpu-prebind-allocation-binding`.
Run the separate static gate with:

```powershell
python -B -m pytest -q tests/virtual-realm/test_m2db4h_gpu_prebind_allocation_binding.py
```

Sources: `webgpu-os/kernel/GpuDeviceBroker.js`;
`webgpu-os/kernel/realm/RealmLifecyclePortComposition.js`;
`webgpu-os/kernel/realm/RealmGpuAllocationCohortCore.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`webgpu-os/kernel/realm/RealmGpuAllocationCohort.js`;
`tests/virtual-realm/m2-gpu-prebind-allocation-binding.test.js`;
`tests/virtual-realm/test_m2db4h_gpu_prebind_allocation_binding.py`.

#### Standard adapter cohort allocation routing

Piece 9 now connects standard buffer/texture creation to the exact original
cohort selected by the existing opt-in B3 pre-bind installation. This is an
allocation-routing slice, not full presenter integration or all-effect work
denial. Ordinary jobs, transfers, other device methods and destruction retain
their existing behavior. In particular, presenter cleanup has not lost its
existing ordinary-job route before its replacement is ready.

The core adds a cached exact-original WorkSource6, obtained with the exact-one-
argument `captureRealmGpuAllocationCohortWorkSource(originalCohort)`. Its fields
are `identity`, `assertCurrent`, `assertFacade`, `allocation`, `observation` and
`terminalDelivery`. The last three retain the existing original Cohort3,
historical Source3 and Delivery5; no public registry writer, replacement cohort,
caller admission function or raw facade is exposed by this lookup.

`assertCurrent()` takes no arguments. `assertFacade(originalFacade)` takes one
and compares the original reference before observing currentness. Both return
the existing Identity4. Checks combine genuine owner/work-root admission,
private pause/retirement/closure restrictions and the original broker's exact
mount/facade proof. The broker proof is captured lazily so legacy cohort
construction does not gain new broker callbacks. A source-local reservation
rejects nested work-source checks and releases in `finally`; checks after
callbacks prevent a local terminal seal or retirement from being missed.
This is a momentary observation, not an atomic grant across independently
callback-bearing owner and broker authorities. The existing shared companion
admission fence is not a global lock around the entire broker observation.

Successful genuine terminal-root authorization seals this separate work proof,
including a valid empty cleanup and a valid in-flight `ALLOCATION_PENDING`
rejection. Malformed requests or teardown roots denied before any successful
authorization do not newly seal it. A later authorization failure never reopens
a seal already established by that call or an earlier one. Historical
observation and the original terminal endpoint remain retained
for evidence and authorized explicit retry after work becomes unavailable.
Existing Cohort3, Source3, Control4 and Delivery5 shapes remain unchanged.

The adapter adds two host-side functions:

| Function | Exact original association and result |
| --- | --- |
| `createRealmGpuOwnedAllocationSyscalls(gpuSyscalls, originalCohort)` | Exact2. Authenticates the original cohort before descriptor reflection, reuses the existing syscall validator to capture a fresh frozen exact10 namespace, then checks original currentness before privately associating that namespace with WorkSource6. |
| `captureRealmGpuOwnedAllocationSource(originalAdapterPort)` | Exact1. Returns the selected cached WorkSource6 for an authentic owned adapter, or `null` for an authentic legacy adapter. Unknown, copied, proxy or revoked-proxy ports reject without selector reflection. |

The adapter captures the namespace's private association before its ordinary
validator clones the syscall record. Copying the namespace therefore loses
the association and cannot fabricate ownership evidence. The source lookup
recognizes the exact adapter port, not the stable owner-controller port or a
presenter. Same-identity sibling cohorts remain distinct: their resources and
terminal endpoints cannot substitute for those selected by the adapter.

The owned adapter checks app/owner binding, requested lifecycle generation and
the returned device generation. A rejected original capability receipt follows
the existing retirement path. For `createBuffer` and `createTexture` only, raw
facade methods call the selected original cohort routes without consulting
replaceable ordinary allocator methods. The existing outer broker still owns
callback scopes and opaque-argument validation. Rejected raw allocations remain
in original-cohort evidence, including unpublished resources whose immediate
rollback failed, so the retained terminal endpoint can retry destruction.

Raw device acquisition checks the exact original facade after metadata reads
and rechecks its active receipt before retaining a facade. The raw cached path
also revalidates if reached. The browser gate injects original-work cancellation
during metadata validation while using a separate live request signal. It does
not prove the outer broker's independent cached-facade or post-`await`
publication boundaries: those can bypass this raw path and remain deferred.
No general facade-publication or all-effect currentness guarantee is claimed.

B3 uses the factory only in its existing installed pre-bind branch, before
`bindEpoch`. After the factory's final callback-bearing proof, B3 performs only
a callback-free acquisition-open check before binding. Legacy acquisition stays
unowned. Dependency16, syscall10, presentation9, B3 options17/output2,
controller5, bind4/release3, terminal Request5/Receipt11 and the existing attempt
and v1/v2/v3 host channels are unchanged. Core remains60 modules, B396,
wrapper97 and Entry106; adapter64 and owner-controller65 are newly expanded
guarded closures. B3 still does not import its compatibility wrapper.

At the allocation-routing slice's acceptance, the next work was an original-only association through the stable
presentation port into the exact presenter generation, followed by private
terminal-root delivery and retry-safe cleanup. It must reject an empty sibling
cohort despite equal scalar identities and prevent multiple presenters from
claiming one cohort's cleanup. Failed cleanup must retain exact resources and
late capability/surface/producer/subscription results; Entry must not discard a
presenter that still owns unresolved cleanup. Startup settlement and cleanup
must not await each other. Only after this replacement works can ordinary-work
denial cover retained callbacks, nested capabilities and final publication.
Recovery to a new device facade also needs a separate reviewed association;
the installed original pair is not silently replaceable.

This slice does not accept full-provider mount provenance, selected-Realm or
activation ownership, production M1C admission, a visible city frame, native
GPU destruction or physical memory reclamation. Browser resource witnesses and
controlled full-owner services are not hardware or production-provider evidence.
No First Shard scan, broad runner, full bundle or shared discovery regeneration
is part of this scoped verification.

The focused browser gate is
`tests/virtual-realm/m2-gpu-owned-adapter-allocation.test.html`; its exact32-case
receipt is published in `#browser-receipt` as
`virtual-realm-m2-gpu-owned-adapter-allocation`. The corresponding static gate is
`tests/virtual-realm/test_m2db4h_gpu_owned_adapter_allocation.py`.

Final browser verification passes **431/431** across fourteen gates: the prior
ten gates339, the new owned-allocation gate32, legacy adapter18, owner-controller15
and presenter27. There are no final-run failures, skips, blocked cases or console
errors. The new gate proves original membership for both resource families,
same-mount isolation, metadata-time cancellation, retained rejected resources,
terminal sealing and ordinary-job destruction after work abort without double
destruction. It uses actual lifecycle/broker/adapter authorities with controlled
capability/full-owner services and instrumented JavaScript device resources.

Final Python verification passes **406/406** across exactly28 files in146.72
seconds, with no failures or skips: prior25 files373, the two additional legacy
adapter/port files9, and the new owned-adapter gate24. Focused86 is included,
not additional. Count-preserving updates pin the additive exports, exact
source-section boundaries, terminal-state declaration and reviewed closures;
the first full run's three stale historical pins were corrected before this
final complete rerun. The nine changed Python files and eight production/browser
files pass scoped SPDX, whitespace, final-newline and conflict-marker checks.
The three plan files pass112 local-link checks and retain two identical piece-9
rows within their unchanged flat ten-piece ledgers. Shared discovery generators
are deliberately deferred under the excluded-world/concurrent-work boundary.

Run the new focused source gate with:

```powershell
python -B -m pytest -q tests/virtual-realm/test_m2db4h_gpu_owned_adapter_allocation.py
```

The legacy adapter initially passed17/18: its source-policy case still banned
every kernel import. That check now admits exactly the reviewed Core import and
continues to reject hidden device/context/frame acquisition; the final18 pass.
Two new-gate fixture expectations were corrected before its first execution
(the existing `currentHook` signature and outer-broker zero-argument diagnostic).
Independent review found no production blocker within this bounded routing
scope. The new factory-observation/B3-close window is order-pinned in Python,
but is not separately claimed as a directly injected browser scenario.

Guarded source closures are broker9/Core60/adapter64/controller65/B396/wrapper97/
Entry106. Browser closures are owned194; pre-bind193; terminal192; cohort191;
lifecycle-binding187; B3-production166; lifecycle-companion74; epoch69;
registry13; mount12; terminal-contract5; adapter67; owner-controller68; presenter37.
Unknown, external and excluded imports reject before file reads. Prior epoch19
and adapter/controller closure receipts remain historical, not current pins.

Sources: `webgpu-os/kernel/realm/RealmGpuAllocationCohortCore.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`;
`tests/virtual-realm/m2-gpu-owned-adapter-allocation.test.js`.

#### Stable presentation-port allocation association

Piece 9 now links an exact original stable presentation port and its original
epoch telemetry token to the allocation source actually selected by that epoch's
adapter. This completes the stable-port association prerequisite without binding
a presenter, changing cleanup behavior, or granting exclusive ownership of a
cohort. It is available before capability admission, so failed startup admission
does not make the selected cleanup source undiscoverable.

`captureRealmOwnerCoupledGpuAllocationSource(originalStablePort,
originalEpochTelemetry)` takes exactly two arguments. Both selectors must be
the original objects. A private outer WeakMap authenticates the stable port;
its private inner WeakMap authenticates that port's original epoch token.
Lookup returns the selected cached WorkSource6, or explicit `null` for an
authentic legacy epoch. Unknown ports and unpaired epochs reject; copies, proxies,
revoked proxies, matching scalar identities and tokens from another controller
cannot select a source. Lookup performs no selector reflection and never
consults the current epoch, calls a currentness check, or enrolls a caller object.

The function is non-mutating, but its result is capability-bearing: WorkSource6
contains the existing allocation routes and original terminal delivery. This
is a host-private trusted-module interface, not pure telemetry, dependency17,
an application sandbox, or proof of a presenter's exclusive cleanup claim.
The existing epoch telemetry source remains unchanged and grants only its
previous observation/forwarding evidence. Do not conflate the two interfaces.

The intended host-side sequence reuses existing mechanisms:

1. Capture the original epoch token using the original stable port's existing
   `captureRealmOwnerCoupledGpuEpochSource(port).capture(identity3)` operation.
   That selection requires the current matching epoch under the existing
   controller fence. Retain the returned token before startup effects.
2. Pass the exact stable port and token to the new allocation-source lookup.
   Retain that source instead of reconstructing a cohort from scalar labels.
3. For an accepted capability receipt, use the same token's existing
   `assertResult('requestCapabilityReceipt', receipt)` operation to verify
   historical forwarding. This is not exclusive ownership or work authorization.
4. Continue to use the source's separate original work and teardown checks for
   those operations. Historical lookup remains available after work abort,
   terminal sealing, epoch release, disposal or a later epoch; it does not
   reopen allocation or bypass the original teardown root.

At bind time the controller captures the source from its actual original
adapter. It matches app, owner and lifecycle identity before registering the
epoch or changing the highest generation/current epoch. Lifecycle text comes
from the already validated BigInt primitive, avoiding a later caller property
read or a `BigInt.prototype.toString` callback. Rejected owned binding does not
advance the generation or prevent a later valid bind. No work-currentness
callback is added after B3's final pre-bind proof. Legacy `null` is preserved,
not reinterpreted as an owned source or silently replaced by another cohort.

Both weak lookup operations and the nested WeakMap constructor are captured
at module initialization. Epoch registration occurs once before publication;
retirement does not overwrite its selected source. Retaining scalar receipts
alone does not create a new strong history index. No global receipt-to-source
map exists: an original receipt can legitimately appear in more than one
controller's historical forwarding evidence. Exact port/epoch pairing prevents
one such controller from overwriting another's selected cohort.

Separate controllers can intentionally select the same genuine cohort. The
lookup accurately returns that same source; it does not consume or exclusively
claim it. The next presenter binding must prevent competing cleanup claims and
connect the exact presenter generation to this original source and its accepted
receipt. A same-identity empty sibling cannot replace the selected cohort, but
selecting the correct cohort alone does not establish renderer ownership.

The lookup also revealed a startup publication gap. During B3's synchronous
`owner.bound` logger callback, the original stable epoch was already discoverable
but acquisition had not completed. The regression reproduced **23/24** passing
cases: its first case observed two premature raw allocations, one buffer and
one texture, instead of zero. Assertions run after the logger returns so its
error isolation cannot swallow the witness.

`RealmM2RuntimeComposition.js` now uses the existing private controls to pause
the primary cohort after syscall-namespace factory proof and before the final
callback-free pre-bind check. It resumes only after `owner.bound` returns,
immediately before the callback-free return/finally tail clears `acquirePending`.
Rejection still closes and drains paused controls. Explicitly closed, retired
or terminal-sealed cohorts cannot reopen. Early historical lookup can return a
paused capability-bearing source; its work checks and both allocation routes
stay closed until acquisition completes. The original B3 capture APIs continue
to require completed acquisition. This distinction is intentional.

Production changes are limited to `RealmOwnerCoupledGpuPresentationPort.js`
and that private B3 publication fence. Existing Controller5, presentation9, epoch Source1/Token3/Identity3,
B3 options17/output2, dependency16, adapter syscall10, cohort/source/control and
terminal/attempt/v1/v2/v3 wires remain unchanged. Existing forwarding, receipt
retirement and successful-result publication in the controller are not modified.
Fixed frozen errors use `VR_M2DB4H_GPU_STABLE_ALLOCATION_` with
`REQUEST_INVALID`, `SOURCE_REQUIRED`, `EPOCH_REQUIRED` and `IDENTITY_MISMATCH`;
they do not reflect or echo supplied selectors.

Private presenter terminal-root delivery, retry-safe retention of failed/late
handles, full ordinary-work denial, outer-broker final publication checks and
device-recovery association remain open. This slice accepts no full-provider
mount provenance, selected-Realm/activation join, production M1C opener, visible
city frame, native GPU reclamation or First Shard access. The existing flat
ten-piece plan is preserved; no milestone is added or promoted.

Final verification after the B3 fix passes **455/455** browser cases across
fifteen gates, with zero failures, skips, blocked cases or final-run console
errors. This includes the new stable-source24, preserved owned-adapter32,
pre-bind40, terminal40, cohort40, lifecycle-binding32, B3 production11, epoch36,
resource-registry36, mount36, terminal-contract36, adapter18, controller15,
presenter27 and lifecycle-companion32. The new gate also proves normal allocation
after completed acquisition and that an early authentic terminal seal cannot
be reopened. Controlled JavaScript device resources are used; this is not a
physical-GPU or newly integrated presenter-cleanup acceptance.

The final exact29-file Python group passes **426/426** in143.87 seconds, with
zero failures or skips: the prior406 checks plus the new20. The existing epoch
gate retains all18 checks with count-preserving source pins. The new browser
entry closes over exactly195 pre-read-allowlisted modules; the preserved fourteen
browser closures and production broker9/core60/adapter64/controller65/B396/
wrapper97/Entry106 closures remain verified. No First Shard or unknown import
was read. No shared bundle, broad discovery or documentation-index generator ran.

The durable gates are `tests/virtual-realm/m2-gpu-stable-allocation-source.test.html`
(receipt suite `virtual-realm-m2-gpu-stable-allocation-source`) and
`tests/virtual-realm/test_m2db4h_gpu_stable_allocation_source.py`.

Sources: `webgpu-os/kernel/realm/RealmOwnerCoupledGpuPresentationPort.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`;
`webgpu-os/kernel/realm/RealmGpuAllocationCohortCore.js`.

#### Original presenter-generation provenance

Piece 9 now supplies the missing presenter side of the ownership proof.
`captureRealmStaticGpuPresenterGenerationSource(originalPresenter)` observes
the actual local generation of an original `RealmStaticGpuPresenter`. This is
a provenance prerequisite, not the prospective host binding or exclusive
cleanup claim. A lookup performed after startup cannot prevent another
presenter from already allocating through the same stable port.

The interface is separate from all existing presenter methods and app wires:

| Interface | Exact operation | Result and boundary |
| --- | --- | --- |
| Original lookup | One original presenter argument | Cached frozen Source1. Copies, inherited look-alikes, proxies and revoked proxies reject without selector reflection. |
| Source1 | `capture()` with zero arguments | The current original Token4. Idle, aborted, invalidated, stopped or disposed generations reject; no numeric selector can reconstruct a token. |
| Token4 identity | Frozen `presenterId` and positive local `generation` | Local presenter identity only, not a lifecycle owner, Realm, mount or cohort identity. |
| Token4 | `assertCurrent()` with zero arguments | The same Identity2 if the exact generation and resource owner remain current and the internal start signal is natively live. |
| Token4 | `assertPresentationPort(originalPort)` | The same Identity2 only for the exact validated constructor port. Historical evidence; no port is returned. |
| Token4 | `assertResult('requestCapabilityReceipt', originalReceipt)` | Returns `undefined` only for a successfully adopted original object/function receipt in this generation's weak membership. Historical evidence; no receipt is returned. |

The original presenter is registered only after successful constructor
initialization. Each local generation gets its token before startup diagnostics
or compilation can call out. Capturing the source does not start the presenter;
capturing its token does not wait for a capability receipt. The token can exist
for a startup that later fails compilation or admission, with no receipt members.

Currentness uses the exact private active generation and owner, the native
`AbortSignal.aborted` getter and the pinned original resource-owner assertion.
Allocation rollback can invalidate the owner before the outer awaited startup
catch clears its generation; the token must already reject in that interval.
Receipt membership is recorded only after the existing presenter currentness
check and receipt assignment, with a separate pinned, callback-free currentness
gate. Shadowing a signal property or replacing the legacy owner method cannot
cause stale receipt adoption to be certified. Skipping stale evidence does not
repair or silently redefine legacy startup, late-result cleanup or teardown.

Original-map operations, the receipt WeakSet constructor and operations, native
signal getter, resource-owner assertion and evidence freezing are captured at
module initialization. The source selects one current evidence record. A caller
that retains an old token can still check its exact original port and adopted
receipt after stop, failure, disposal or restart. A later generation cannot
replace that token's receipt history. This is weak receipt membership, not a
strong global receipt registry or a guarantee of garbage-collection timing.
Detached token methods remain bound to their original private evidence; copying
a method does not create another generation or grant new issuer membership.

Fixed frozen errors use `VR_M2DB4H_GPU_PRESENTER_PROVENANCE_` with
`REQUEST_INVALID`, `SOURCE_REQUIRED`, `NOT_CURRENT`, `PORT_REQUIRED`,
`METHOD_INVALID` and `RESULT_REQUIRED`. They do not reflect or echo selectors.
Legacy scalar capability results retain their existing behavior but never become
original receipt evidence. Existing diagnostics are reused; no logger or observer
callback is added to receipt enrollment.

Only `webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuPresenter.js`
changes in production. Its existing resource-owner import also supplies the
pinned original assertion; no new import path or kernel dependency is added.
Public presenter methods, start9, presentation9, dependency16, controller/epoch,
allocation/terminal and approved v1/v2/v3 wires remain unchanged. No GPU route,
teardown root, original resource handle or writer is returned by this source.

The next integration must install an issuer-authenticated pre-start host binding
and reserve the actual selected cohort before capability admission. It must join
this exact presenter generation and port to the existing original epoch, selected
WorkSource6 and accepted receipt proofs, rejecting empty siblings and competing
claims. Neither a post-start lookup nor a caller-supplied guard is that binding.
Do not release claims merely because `stop()` returned `disposed: true`: existing
cleanup can lose failed handles. Original terminal-root delivery and retry-safe
retention must precede ordinary-work denial. Full-provider mount provenance,
production M1C admission, device recovery and a visible city remain unaccepted.
The same ten-piece plan is preserved, with no new milestone or authority channel.

The new browser gate passes **32/32** with zero failures, skips, blocked cases
or console errors. Its initial run passed28/32: three cases exposed stale
provenance under native-abort shadowing, owner-method stop reentry and permanent
disposal with a replaced public stop method. The shared pinned-current predicate
fixes those three evidence defects. The fourth failure was a test setup error:
the actual-adapter case lacked a parent for its persistent canvas. Attaching that
canvas fixes the fixture without weakening its expected controlled-surface error.

The owned integration case combines a real presenter, lifecycle/B3 authorities,
broker, stable port, selected cohort and accepted receipt. It intentionally stops
at controlled surface construction with zero GPU resources; it is not a full
rendering fixture. Other cases use the established strict JavaScript GPU rig.
The hostile shadowed-abort case can still reach legacy `ready` while the new
source rejects currentness and receipt evidence. This is a tested limitation,
not a claim that legacy work admission or all cleanup paths are now hardened.

Durable browser entry: `tests/virtual-realm/m2-gpu-presenter-generation-source.test.html`,
receipt suite `virtual-realm-m2-gpu-presenter-generation-source`. Its exactly197
modules are checked against a pre-read allowlist. The presenter production
closure remains31, the existing presenter browser closure37 and Entry106.
No First Shard or unknown import was read; no broad bundle or shared discovery
generator ran. Source checks live in
`tests/virtual-realm/test_m2db4h_gpu_presenter_generation_source.py`.

Final fixed-source browser verification passes **487/487** across sixteen gates:
the new32 plus all prior455. There are zero failures, skips, blocked cases or
final-run console errors. All fifteen preserved browser import closures were
independently rechecked before execution. The unchanged presenter27 is included
in that total, not additional acceptance of terminal or exclusive ownership.
Scoped documentation validation passes118 file-local links, nine same-page
links and all72 fragment references targeting the three plan documents. Both
piece9 rows remain identical within ten flat pieces.

The final exact30-file Python regression passes **446/446** in157.75 seconds,
with zero failures or skips: prior426 plus new20. No prior static or browser
fixture files needed modification. Legacy module walks were guarded in memory
against the exact reviewed path union before reads; each gate's exact closure
assertions remained enabled. The new source gate pins frozen interfaces,
constructor enrollment, pre-diagnostic token issuance, private/native currentness,
callback-free receipt membership and unchanged public/cleanup boundaries.

Source: `webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuPresenter.js`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuResourceOwner.js`.

#### Strict presenter startup and fresh-cohort exclusivity proposal

**Status: bounded protected-startup slice implemented and verified.** The user
approved both the opt-in v4 host carrier/fresh-cohort policy and the narrow
original-issuer dependency. This piece 9 implementation now reserves the actual
selected protected cohort before presenter startup diagnostics and enforces the
winning presenter/route/receipt at buffer and texture allocation. Full B4H,
production M1C admission and a visible city remain unaccepted. The subsequent
private-terminal section below records the separate cleanup continuation.
The unchanged ten-piece ledger still owns the remaining requirements.

##### Implementation preflight and dependency amendment

The dependency amendment is approved and implemented. The presenter imports
original-only validation and startup operations from the existing
`RealmOwnerCoupledGpuPresentationPort.js` issuer. The controller and protected
core import original presenter evidence. This creates a deliberate ES-module
cycle instead of trusting a supplied validator or public enrollment callback.
No imported startup operation runs during module evaluation. All five cycle
edges use namespace imports and call-time property lookup: the canonical bundler
snapshots named imports, which would otherwise retain unfinished exports.
The existing cyclic baseline adds only the two possible reviewed cycle member
sets; the stricter test guard pins the complete four-member, five-edge component.
Unrelated cycles and unknown imports remain rejected. Native-browser and scoped
canonical-bundle import-order evidence is recorded below after verification.

Moving an issuer behind a different filename would not have removed its trust
dependencies. The accepted change explicitly grows the presenter/Entry import
closures. It does not expose a kernel root, install a full authority provider,
or establish same-origin isolation. The earlier 31-module presenter and
106-module Entry measurements remain historical, not current closure claims.
(Sources: `bundler/cyclic_baseline.json`; `bundler/emitter.py`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuPresenter.js`;
`webgpu-os/kernel/realm/RealmOwnerCoupledGpuPresentationPort.js`;
`webgpu-os/kernel/realm/RealmGpuAllocationCohortCore.js`.)

##### Exact host carrier and original startup binding

| Interface | Implemented contract | Boundary |
| --- | --- | --- |
| V4 runtime lease | Exact frozen `leaseVersion, dependencies, attemptBinding, hostLifecycle, presenterStartupBinding, close` | Separate opt-in version; v1/v2/v3 outputs and dependency16 remain unchanged. |
| Startup binding | Exact frozen `{ portName: 'realmGpuPresenterStartupBinding', version: 1 }` | Opaque issuer member with no methods, callbacks, routes or teardown roots. |
| Controller binding factory | `createRealmGpuPresenterStartupBinding(originalController)` | Exact-one original-controller lookup; cached original binding. It may precede epoch creation but cannot reserve without a current protected epoch. |
| Binding validator | `validateRealmGpuPresenterStartupBinding(originalBinding)` | Exact-one original-only observational lookup returning the same object. Copies, proxies, matching labels and caller callbacks cannot enroll. Historical membership is not current work authority. |
| B3 protected installer | `installRealmM2RuntimeProtectedGpuAllocationBinding(composition, mount, facade)` | Exact-three genuine pre-acquisition installation; returns only the opaque binding for v4 transport. |
| Entry handoff | Third optional constructor/factory argument | Private storage; passed to the presenter's optional `startupBinding` constructor option, never dependency17 or public status. |
| Presenter constructor proof | `assertRealmStaticGpuPresenterStartupBinding(presenter, binding)` | Exact original constructor association. A host cannot retrofit an unbound legacy presenter after its started diagnostic. |
| Original request proof | `captureRealmStaticGpuPresenterRequestSource(originalRequest)` | Frozen `{ token, assertCurrent }` for the internally created request; no public enrollment, caller request copy or raw receipt. |

Registry authentication happens before creating an owned lifecycle wrapper.
Invalid leases retain existing raw-close quarantine and retry ownership.
Desktop now retains lifecycle transport for v3/v4 and attempt binding for
v2/v3/v4, forwarding the exact original startup object in its own separate
`virtualRealmRuntimePresenterStartupBinding` context field. The factory rejects
inherited, accessor, non-enumerable and explicitly undefined injection. Existing
attempt-binding validation is reused through one private descriptor reader;
no duplicate authority check or callback authorizer is introduced.
(Sources: `webgpu-os/kernel/AppRuntimeCompositionRegistry.js`;
`webgpu-os/shell/Desktop.js`; `webgpu-os/apps/the-virtual-realm/factory.js`;
`webgpu-os/apps/the-virtual-realm/VirtualRealmEntry.js`.)

##### Reservation before startup and receipt adoption

The presenter issues its authentic local generation token, then calls the
original host startup issuer inside the same catch/finally boundary that settles
startup and unlinks its signal. The issuer verifies the exact constructor binding,
constructor port, original presenter/token and current controller epoch. It
selects the child route already associated with that epoch's actual adapter;
callers cannot supply a same-label sibling source.

The controller records its attempt before genuine owner checks can reenter stop.
The protected core reserves source-global ownership before owner callbacks.
Only after successful reservation does the presenter emit its started diagnostic
and begin upload compilation. Entry's earlier CPU scene/draw-packet compilation
is unchanged. A rejected reservation settles startup and performs existing cleanup.

Immediately before capability dispatch, the presenter registers its internally
created original request against its token. The controller verifies the request
against its exact attempt/epoch/adapter route and marks the core claim dispatched
before invoking the adapter. After successful original forwarding, it records the
exact receipt in both epoch history and the protected route. This is forwarding
evidence, not adoption. The presenter independently records successful receipt
adoption under native/private currentness checks.

No protected allocation can run before that exact receipt has been adopted.
Source1, Token4, start9, the existing presentation port, snapshot fields and
all sixteen app dependencies retain their shapes. Protected startup adds native
currentness checks without silently redefining the legacy non-opted startup path.
(Sources: `webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuPresenter.js`;
`webgpu-os/kernel/realm/RealmOwnerCoupledGpuPresentationPort.js`.)

##### Fresh protected cohorts and effect-time allocation

`createRealmGpuProtectedAllocationCohortCore(companion, mount, facade)` is a
separate exact-three factory using the existing genuine owner and broker cohort.
Its result2, Cohort3 and WorkSource6 shapes remain unchanged. The legacy factory
continues to issue legacy cohorts. B3 selects protected primary creation only
after genuine lifecycle capture and exact configured-device validation; existing
pause/bind/owner-bound/resume acquisition fences remain intact.

Protection is fixed at fresh issuance. Neither legacy-to-protected promotion nor
protected-to-legacy downgrade is permitted by the B3 installer. Repeated identical
installation before the first acquisition remains valid. Every later primary
cohort from that opted-in composition is freshly protected. The compatibility
sibling factory continues to create a distinct legacy source; it cannot substitute
for the epoch's selected protected source.

Each actual adapter receives one original private child route. Its Control5 has
`reserve(presenter)`, `dispatch(presenter, request)`,
`accept(presenter, request, receipt)`, `allocation`, and `cancel(presenter)`.
The allocation object has two private methods taking exactly the original receipt
and descriptor. The public facade still receives only the descriptor. Passing
the facade's actual receipt prevents a cached facade from another receipt on the
same adapter from borrowing the winner's route.

Protected bare Cohort3 create methods always reject. Other child routes reject
unless they hold the same source-global winning claim. Each allocation checks
the exact route, receipt, original presenter currentness and adopted-receipt
membership before entering a private operation fence. The existing generic
broker repeats admission around owner, descriptor, native-return and accounting
callbacks. Nested routes reject; a bare route cannot inherit an ambient
authorization flag. Source currentness/facade observation remains usable during
B3 preparation without granting allocation.

Native calls are not atomic. If creation returns after cancellation or retirement,
existing original-resource enrollment, rejected-publication rollback and
unresolved retention keep the candidate with its original cohort. No broker
implementation change or sibling transfer is required.
(Sources: `webgpu-os/kernel/realm/RealmGpuAllocationCohortCore.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`;
`webgpu-os/kernel/realm/RealmM2RuntimeComposition.js`;
`webgpu-os/kernel/GpuDeviceBroker.js`.)

##### Failure ownership, diagnostics and remaining boundaries

The private core distinguishes unclaimed, reserved, admission-dispatched,
accepted, adopted and closed phases. Only an unused reserved claim can return
to unclaimed. Cancellation during a reservation callback waits for the original
transition to finish before clearing it. Once capability dispatch begins,
rejection, late receipt, stop, disposal, abort and failed cleanup cannot transfer
ownership to another presenter. A late accepted receipt may remain historical;
it cannot reopen a closed route.

Ending the exact startup attempt is idempotent. The presenter also prevents a
denied host cancellation from replacing the original startup error or skipping
ordinary cleanup. Such denial emits the fixed
`virtual-realm.m2db4h.reservation.cleanup-pending` event. Successful reservation
and adoption have bounded diagnostic events with local generation only; no route,
root, resource or caller selector is logged.

At the protected-startup gate, ordinary destruction/jobs remained available and
the legacy presenter/resource owner could discard failed cleanup handles. Those
legacy receipts are still not evidence of terminal emptiness. The later private
terminal continuation below replaces that cleanup only for the root-bound
protected presenter. Successful original terminal cleanup permanently seals the
cohort; later startup requires fresh issuance, never reopening.

The terminal continuation below delivers the authentic cleanup capability,
retains failed and late handles, and replaces ordinary-job destruction. General
ordinary-work denial remains separate. Outer-broker cached/after-await work
publication checks beyond cleanup retention, full-provider mount provenance,
selected-Realm/activation ownership, recovery, production M1C and the actual
first submitted city frame remain separate unaccepted work.
(Sources: `webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuPresenter.js`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuResourceOwner.js`;
`webgpu-os/kernel/realm/RealmGpuAllocationCohortCore.js`.)

The existing eight implementation steps stayed within flat piece 9: exact carrier,
fresh issuance, startup reservation, request/receipt association, protected
allocation, failure retention, independent verification, and plan/memory evidence.
No nested milestone, full-provider registration or broader GPU-effect authority
was added.

Verification on the final namespace-import source passes **204/204 distinct
behavioral browser cases**: protected startup40, presenter provenance32, stable
source24, owned adapter32, pre-bind40 and legacy host36. Two fresh native ESM
import-order checks also pass. The unmodified canonical builder and emitter then
run all40 protected cases in each initial require order, adding80 repeated case
executions, not80 new cases. Total: **286 successful case executions**, zero
skips, denied HTTP requests or unexpected browser errors.

The source browser closure contains199 modules; each scoped canonical bundle
contains198, excluding the top-level-await test main and using the actual test
module/harness. Each bundle produces exactly one explicitly asserted diagnostic
for the builder's unconditional probe of the out-of-scope `VirtualGPU.js` module.
No substitute implementation is supplied and that source is never scanned.
This is scoped canonical-bundle evidence, not a full OS release build or physical
GPU certificate. It verifies the repair for the cycle failure reported by the
concurrent Speech task without running a broad build that could scan First Shard.

The new Python architecture gate passes **26/26**. It verifies exact80 source
closures, namespace-only cycle edges, original-only proofs, effect-time receipt
binding, fresh issuance and v4 transport. Canonical cycle enforcement accepts
both reviewed entry orders with the explicit baseline and rejects an empty
baseline. The final broader source regression passes494/494 across32 explicitly
selected files in133.11 seconds; the earlier five-file100 is included, not
additional. With the new26, current Python verification is **520/520** across33
files. Historical generic walkers now use a declared172-source pre-read
allowlist; dedicated graphs retain their exact manifests and strict cycle check.
Source checks are architectural evidence, not substitutes for the browser runs.
Independent Presenter/Controller/Core/Adapter/B3 review found no actionable
defect within this allocation-protection scope.

The reentrant native-texture case explicitly retains a rejected original
candidate and retries original receipt retirement from the host after the
operation settles. It does not claim that ordinary presenter stop completes
cleanup. Factory/Desktop transport remains exact-source verified; actual Entry
construction and v4 Registry lifecycle/identity behavior execute in the browser.

Reproduce the browser evidence with
`python -B tests/virtual-realm/run_protected_startup_browser.py generation stable owned prebind host protected presenter-first controller-first bundle-presenter-first bundle-controller-first`.
Run the new source gate with
`python -B -m pytest --confcutdir=tests/virtual-realm -q tests/virtual-realm/test_m2db4h_gpu_protected_startup.py`.
The runner writes a per-case JSON receipt with SHA-256 for every served byte
sequence. Final receipt for this run:
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-b5rfqu1s.json`.
(Sources: `tests/virtual-realm/m2-gpu-protected-presenter-startup.test.js`;
`tests/virtual-realm/run_protected_startup_browser.py`;
`tests/virtual-realm/test_m2db4h_gpu_protected_startup.py`;
`tests/virtual-realm/RealmPresenterStartupGraphGuard.py`.)

#### Private presenter terminal cleanup and retry ownership

This bounded continuation remains within flat piece9. Entry passes its exact
existing `lifecycle.teardownSignal` privately beside the original startup binding.
The presenter captures cleanup after successful reservation and before diagnostics,
compilation or capability dispatch. Nothing is appended to the v4 lease6,
dependency16, start9, Source1, Token4, presenter methods or public status records.
The raw root, original cohort and terminal wire endpoint are not returned.

The original controller's exact-four-argument
`captureRealmGpuPresenterTerminalCleanup(binding, presenter, token, teardownSignal)`
looks up the historical attempt and its retained actual adapter. It does not
consult the controller's current epoch, caller labels, a supplied cohort or an
adopted-receipt list. Keeping the adapter on that attempt matters because epoch
release clears the mutable epoch adapter slot. Invocation requires that exact
attempt to have ended. The result is a private frozen one-method capability,
`destroyOwnedResources()`, taking exactly zero arguments.

The adapter forwards through its already-selected original child route to
`captureRealmGpuProtectedTerminalCleanup`. Core retains each original token's
reservation record with monotonic dispatched/released facts. Every capture,
preflight and terminal delivery authenticates the original teardown root and
historical claim. An old unused reservation returns only `not-dispatched`, not a
manufactured empty-cohort receipt; it cannot drain or seal a successor on the same
adapter. A dispatched reservation must remain the irreversible selected source
claim on every retry, even after current work or receipt adoption is unavailable.
The original-only `isRealmGpuProtectedTerminalCleanupDispatched` preflight also
checks the root and claim; it is not a scalar authorization shortcut.

Protected cleanup has one dependency order:

1. End the original attempt and revoke local work; share the in-flight stop.
2. Settle startup while retaining every late returned handle before stale checks.
3. Stop the published producer, then drain retained unpublished rollback handles.
4. Use the original cohort's bounded terminal destruction and require zero
   unresolved and zero abandoned resources; do not issue an ordinary GPU job.
5. Release the published surface, unsubscribe, and retire the original receipt.
6. Only after success let Entry continue lifecycle, telemetry, participant and
   process-owner teardown; its exact teardown root stays live until aggregate success.

Producer, surface, subscription and receipt references survive rejection. Native
buffer/texture candidates remain in the original cohort even when no local lease
or public handle was returned. Protected allocation rollback no longer discards
the local owner through ordinary synchronous disposal. An incomplete terminal
receipt or failed phase rejects; `whenSettled()` retains that failure and an
explicit later `stop()` or `dispose()` retries. Permanent dispose intent prevents
new startup but never suppresses required cleanup retries. Duplicate and reentrant
stops share published promises; startup does not await the stop that awaits it.
After genuine resource completion the private evidence closure releases its local
resource-owner reference, so historical Token4 proof need not retain destroyed
GPU handles. Receipt provenance itself remains weak and historical.

The protected adapter uses a separate retry-policy broker factory, preserving
the public presentation wire and legacy broker policy. Failed producer disposal,
individual unsubscription, surface release and receipt retirement no longer cache
an unretryable rejection. Completed phases are not repeated. Private original-only
broker and adapter retention also covers rejected publication and rollback:
unpublished receipt, surface, producer and subscription candidates are retained
until observed cleanup succeeds. Their terminal drain revalidates the original
Core preflight around raw effects and asynchronous continuation. Rejected receipt
retirement in that terminal drain follows resource proof, never a guessed empty
local owner. Published handles remain the presenter's ordered cleanup responsibility.
The original-broker cleanup-source lookup is host-private and is not independently
root-authorized. The original adapter installs and enforces the Core preflight
for terminal delivery; the stable application port exposes neither that broker
source nor the original adapter. This is not isolation against arbitrary
same-origin module imports or hostile replacement of trusted construction code.

Device loss is not abandonment evidence. This path preserves the original
destruction-only delivery rather than invoking the legacy `abandon()` behavior.
Terminal resource counts describe observed original destructor completion, not
physical GPU reclamation or proof of full renderer quiescence. At that terminal
gate, ordinary-work denial, nested effect fencing and cached/late work publication
remained open; the following continuation adds bounded standard-route checks.
Full-provider mount
and backend isolation, selected-Realm/activation ownership, genuine telemetry,
recovery, production M1C and a first submitted city frame remain open.

Entry stops its reverse cleanup immediately if protected GPU disposal rejects;
it keeps the same presenter and upstream owner instead of treating the rejection
as a report-only failure. Its protected cleanup pass skips the second GPU-dispose
call in static-candidate disposal. A presentation error and a cleanup error are
preserved together in an `AggregateError`, including frozen original issuer
errors; the legacy error path is unchanged. Protected Entry publishes its stop
and cleanup promises before abort listeners and lifecycle logging can reenter,
while still revoking construction/work synchronously before `stop()` returns.
Fixed terminal diagnostic events
record generation, phase counts and bounded error codes, never private roots,
routes, raw handles or content.
Protected public status and failure diagnostics do not inspect an arbitrary
native error's `code` property. They use fixed runtime/cleanup codes while the
original failure remains available to `stop()` and `whenSettled()` callers.

##### Terminal continuation verification

Final Chrome151 verification passes **458/458 executions** across14 exact gates:
**288 distinct behavioral cases** (prior startup/provenance/adapter/host204,
existing cohort-terminal40, and new44), two fresh native ESM import-order checks,
and168 repeated cases across four canonical bundles. The new44 comprise37
presenter cases and seven Entry teardown cases. There are zero skips, denied
requests or unexpected browser errors. Each scoped canonical bundle accounts
for exactly one asserted missing-`VirtualGPU.js` probe from the unchanged builder;
no substitute module, First Shard read or full OS build was used.

The new gate's exact source closure is199 modules; its canonical bundle contains198,
excluding the top-level-await main. These counts happen to equal the earlier
protected-startup gate but describe different exact inventories. The reviewed
four-member/five-edge authority component and all public wire sizes are unchanged.
The final served232-route receipt is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-0_bz3o3y.json`,
SHA-256 `8f37981a754b87e0656ad79bf5211c69b0fc254d1f09f7325eca0f92212fdd8c`.
All six current production modules were independently matched against the
receipt's normalized served-byte hashes.

The seven Entry cases start actual Entry-owned lifecycle roots and a genuine B3
owner, then attach an actual protected presenter using the existing canonical
draw-plan fixture. They verify reverse teardown and retry, including synchronous
abort-listener and lifecycle-logger reentry. Service and native GPU boundaries
are controlled test implementations. This is not a full admission/ECS recipe
pipeline, full-provider boot, physical GPU reclamation or visible-city proof.
No manual host GPU retirement is used to turn a failed presenter cleanup into
a passing result. Wrong roots/selectors, old unused claims, extra original native
candidates, unpublished rollback failures, every published cleanup handle,
concurrent stop/dispose, device loss and hostile `error.code` getters are covered.

The final exact35-file Python sweep passes **562/562** in109.88 seconds, including
the new24 terminal source checks and18 Entry checks. Historical static pins were
updated only for intentional private exports, original terminal delivery and
protected Entry ordering; exact pre-read inventories and observable/public
authority exclusions remain enforced. These are structural checks, not native
GPU execution evidence. Independent Core/Adapter/Broker, Presenter/Controller,
Entry and documentation reviews found no remaining bounded-scope blocker.

Reproduce the complete browser sweep with
`python -B tests/virtual-realm/run_protected_startup_browser.py generation stable owned prebind host protected cohort-terminal terminal presenter-first controller-first bundle-presenter-first bundle-controller-first bundle-terminal-presenter-first bundle-terminal-controller-first`.
The two new structural gates are
`tests/virtual-realm/test_m2db4h_gpu_presenter_terminal_cleanup.py` and
`tests/virtual-realm/test_m2db4h_gpu_presenter_terminal_cleanup_entry.py`; the
exact full Python selection is recorded in session memory. Source/header,
final-newline, whitespace and conflict checks pass across24 changed code/test
files. Both plan ledgers retain ten flat pieces and identical piece9 rows. Curated Markdown
validation is scoped; shared discovery/SPDX generators remain deferred to avoid
excluded-source traversal and concurrent-write collisions.

Sources: `webgpu-os/kernel/realm/RealmGpuAllocationCohortCore.js`;
`webgpu-os/kernel/realm/RealmOwnerCoupledGpuPresentationPort.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationPortContract.js`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuPresenter.js`;
`webgpu-os/apps/the-virtual-realm/VirtualRealmEntry.js`.

#### Root-enrolled ordinary-work fencing

This continuation stays inside flat piece9 and preserves the independent
terminal channel. It does not turn a shared GPU mount into an exclusively owned
Realm backend. Its protection is a momentary original-work check at reviewed
presentation boundaries, not revocation of every operation inside a native GPU
call or memory access through a previously returned resource.

Enrollment requires both the actual original Presenter's constructor-retained
teardown root and its matching pre-dispatch terminal capture. The private
`isRealmStaticGpuPresenterTerminalBinding(presenter, token, root)` authenticates
the exact original generation and constructor choice without returning the root.
Core fixes the claim's `strictWork` policy at dispatch. Merely calling a host
terminal-capture helper for a rootless Presenter, or capturing after dispatch,
cannot retrofit this policy. A released unused predecessor cannot transfer it
to a successor. Source1, Token4, Control5, WorkSource6, start9, dependency16,
the v4 lease6 and public presenter/port/status records remain unchanged.

Core's exact-two-argument
`captureRealmGpuProtectedWorkSource(originalRoute, originalReceipt)` first
authenticates the irreversible original dispatched claim. A genuinely
non-enrolled claim returns `null` as an immutable policy observation, not proof
of the supplied receipt. This preserves binding-only cleanup jobs and their
previous cached/reissued-receipt behavior. An enrolled claim additionally
requires the exact accepted and Presenter-adopted receipt and returns a cached
private frozen1 `assertCurrent()` taking zero arguments. Every assertion checks
the retained claim, route, token, receipt, owner/mount currentness and unsealed
work before and after genuine observations. Reentrant observations reject;
the observation reservation is not held across caller effects or awaits.
Starting work must be permitted after adoption because startup itself builds
shaders and uploads resources; this proof is not a separate frame-readiness grant.

The Adapter captures proof lazily after adoption and independently checks its
original source around facade/queue/encoder method resolution, ordinary calls,
scheduled callback entry and return, cached facade delivery and awaited results.
Frame work also checks its captured producer/surface identities and local
retirement flags around current-texture/view acquisition and callback delivery.
The original-only `assertRealmGpuAdapterOrdinaryWork(adapter, receipt)` is used
by the Controller for its final awaited facade/job/transfer return. It cannot
select a copied adapter or caller-authored guard. The Controller captures its
actual receipt before awaiting and performs no late caller-request reflection.

The separate `createRealmGpuWorkRestrictedPresentationBroker(rawPort, binding,
restriction)` applies an additional host-authored restriction to Broker caches,
callback scopes, nested command-encoder/pass getters and calls, submission and
post-await publication. The restriction is not an authenticator for arbitrary
ports: actual Adapter effects independently use Core proof. Explicit `false`
preserves genuine non-enrolled policy. There is no new import edge or callback
registration authority. After genuine proof, final Broker checks inspect private
state only, avoiding a receipt getter that could revoke work after the check.
Caller callbacks are captured before the final proof and then invoked with their
original receiver. Existing synchronous and one-shot callback rules remain.

Producer disposal, surface release, unsubscription, receipt retirement, lifecycle
loss delivery and original terminal destruction do not require current work.
Late surface/producer/subscription candidates are retained before new stale
checks, and failed cleanup remains retryable. The Controller does not reject
newly published cleanup-bearing handles after forwarding; their recipient must
retain them before rejecting staleness, as the protected Presenter already does.
Native buffer/texture results remain enrolled in the original cohort even when
work revokes inside creation and no result is published. Existing fixed issuer
errors and Presenter failure/cleanup diagnostics remain the observability path;
no logging callback is inserted into a proof's callback-free final check.

##### Ordinary continuation verification

The final Chrome151 run passes **551/551 executions** across17 exact accepted
gates:319 non-bundle behavioral cases, two fresh native ESM import-order checks,
and230 repeated cases across six canonical bundles. The new ordinary31 cases
pass directly and in both canonical import orders. There are zero skips, denied
requests or unexpected browser errors. Each bundle accounts for exactly one
asserted missing-`VirtualGPU.js` probe from the unchanged canonical builder;
no excluded module is supplied or read. Ordinary source closure201 and bundle200
are exact reviewed inventories, not a whole-OS build.

Accepted receipt:
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-7sao2tn9.json`,
SHA-256 `5ea9dd64816df97774ccf6b68e07124060825c567b356dcaba068c1f0267f241`.
It records243 served routes with aggregate
`7349a8506159a18d83bc0629d78f5c0c61f94b73c53d88eefa6b0b1ec24e1ad6`.
All five current production files and the strengthened ordinary test bytes match
its normalized served hashes. GPU/native service boundaries are instrumented;
this does not prove a physical submitted city frame or physical reclamation.

The final exact37-file Python sweep passes **587/587** in245.78 seconds: the
previous562 checks, five existing port-contract checks and20 new ordinary-work
structural checks. Source pins now require the intentional original-only exports,
unchanged public shapes, retained late candidates, captured operations and the
Controller's exact three-method final work fence. No tests were removed or
combined to obtain that result.

An upstream shared-schema refactor added exactly three separately reviewed paths:
`engine/core/schema/JsonSchemaValidator.js`, `StrictJsonValue.js` and
`JsonSchemaProfile.generated.js`. The generated profile imports only the already
reviewed strict-value module. Pre-read inventories name these paths explicitly;
they do not allow an entire schema directory. The authority closure is now83,
Entry155, B3114 and wrapper115, retaining the exact four-member/five-edge
authority component. This task changed none of those shared schema sources.

The accepted ordinary suite has31 cases; two additional native-effect witnesses
remain a separate strict failing suite. Five nested-denial cases compare the
propagated sentinel identity outside the rejected callback, so an inner assertion
failure cannot masquerade as expected operation rejection. Prior terminal cases
still test both existing listener handles by stopping during the second listener
registration; a new ordinary case separately proves that stopping during the
first registration prevents the second while cleaning the first exactly once.

Source/header, final-newline, whitespace and conflict checks pass across51 exact
code/test files. Curated documentation is checked locally; shared discovery and
SPDX generators remain deferred. The ledgers keep ten flat pieces and identical
piece9 rows. These checks do not promote the two open native-effect probes.

Reproduce accepted browser evidence with
`python -B tests/virtual-realm/run_protected_startup_browser.py generation stable owned prebind host protected cohort-terminal terminal ordinary presenter-first controller-first bundle-presenter-first bundle-controller-first bundle-terminal-presenter-first bundle-terminal-controller-first bundle-ordinary-presenter-first bundle-ordinary-controller-first`.
The new structural gate is
`tests/virtual-realm/test_m2db4h_gpu_presenter_ordinary_work.py`; the exact37-file
selection and safe no-discovery flags are recorded in session memory.

##### Open kernel-native effect boundary

**Historical pre-implementation checkpoint.** The two method-getter assertions
now pass in the [approved native work-view implementation](#original-cohort-native-work-view-implementation).
The separately recorded descriptor-conversion assertion remains unaccepted.
The following receipt preserves the original failure, not current acceptance.

At this checkpoint, two hostile browser probes remained **unaccepted**. They replace the
underlying native shader-method or queue-write method getter, stop the Presenter
during that lookup, and observe one native call before the outer work check
rejects the result. The already-entered `GpuDeviceBroker` wrapper rechecks its
own mount authority but does not yet carry the original Realm generation proof.
Those probes are not counted as passing ordinary-work acceptance and must remain
reproducible. Rejecting a return value does not undo an already-issued GPU effect.

Reproduce these open assertions separately with
`python -B tests/virtual-realm/run_protected_startup_browser.py native-gap`.
The historical strict result was **0/2 passing**, with zero denied requests:
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-kjqgq8kh.json`,
SHA-256 `4147707a4b25a4b7ed95a4dc06dacc3ae91afdc22071d84ef11ac60e8b216e41`.
That historical run exited unsuccessfully. It was not included in the551
accepted executions, and no assertion was waived. The same native-gap command
now passes both original assertions; descriptor-gap is the separate failing gate.

The next bounded slice must bind the original Realm proof inside that exact
kernel effect boundary without a caller-authorizer shortcut, a global policy on
all users of a shared facade, or any work check on destruction-only cleanup.
It must cover cache returns, native member/descriptor reflection, queue and
command operations, reentrant revocation and late ownership, while preserving
legacy/rootless behavior. Any new original-issuer capability or import-cycle
amendment needs explicit review before implementation.

Raw buffer/texture child methods, mapped-memory writes, a separately authenticated
frame-ready phase, physical GPU quiescence, full-provider mount/backend isolation,
activation-selected ownership, genuine resource telemetry, recovery and the
production M1C-to-first-submitted-city-frame route remain separate open gates.
No First Shard source, full OS build, shared documentation generation or
RealmForge/Compute/Speech production change is part of this slice.

##### Original-cohort native work-view proposal

**2026-09-12 status: approved by the user's CONTINUE response to the explicit
private-capability question, then implemented for method/cache/command boundaries.**
This retained blueprint records the decision and its wider acceptance limits.
See [implementation evidence](#original-cohort-native-work-view-implementation)
for current results and the separate failing descriptor gate. It stays inside
existing flat piece 9, not a new milestone or a replacement for M1C-to-visible-city
integration. The proposal-time measurements that follow are historical.

The fresh browser run preserves the distinction between accepted outer checks
and failing inner effects: ordinary **31/31**, native-gap **0/2**, zero skips and
zero denied requests. Both failing assertions expect zero native calls and
observe one. The existing ordinary-work structural Python gate passes **20/20**.
These are instrumented service/native boundaries, not physical GPU evidence.
The fresh receipt is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-h4b_kion.json`,
SHA-256 `6d7672a58de6743823c808d04c114f3bf17640ea19fcd7a8d2b8d6be571e4b09`.
Its served-source aggregate is
`46a1614d0d34175e25acef1bb7f1e28c79d0f87c3a5ead9b2c82ea1862d21596`.
The earlier551 browser and587 Python results remain historical full-sweep
evidence; this continuation does not claim to have rerun either full sweep.

The source diagnosis is specific: `_buildFacade()` closes its inner `guard`
over broker/mount/restoration state. The Adapter's original Realm proof runs
outside that closure. A native method getter can therefore retire the Presenter
after the outer check, while the inner guard still sees a live shared mount.
The existing original buffer/texture cohort already carries a private admission
restriction into `_assertResourceRequest()`. Reuse that original association
for a separate ordinary-work view; do not install a new arbitrary authorizer.
(Sources: `webgpu-os/kernel/GpuDeviceBroker.js`, `_buildFacade()` and
`_assertResourceRequest()`; `webgpu-os/kernel/realm/RealmGpuAllocationCohortCore.js`,
`createAllocationCohort()`; `webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`,
`createRawPort()`.)

The two exports approved by this proposal are **additive private capabilities**:

| Proposed boundary | Exact input and result | Required authority rule |
| --- | --- | --- |
| `GpuDeviceBroker.js` export `createGpuOriginalCohortWorkView(originalCohort)` | One original generic cohort; frozen WorkView8 containing Queue3 | Authenticate the original cohort by private identity before reflection. Use its retained issuer and retained admission operation. Accept no callback, supplied facade, labels, registration writer or authority replacement. Generic admission remains an additional restriction, not proof of Realm origin. |
| `RealmGpuAllocationCohortCore.js` export `captureRealmGpuProtectedNativeWorkView(route, receipt, actualFacade)` | Three arguments; the cached view of that irreversible root-enrolled claim, or genuine legacy-policy `null` | Authenticate the original route and dispatched claim first. For an enrolled claim, require exact adopted receipt and exact retained original facade, then revalidate before publication. Do not return the generic cohort, raw mount, device, root or proof supplier. |

WorkView8 contains exactly `createSampler`, `createShaderModule`,
`createBindGroupLayout`, `createPipelineLayout`, `createBindGroup`,
`createRenderPipeline`, `createCommandEncoder`, and `queue`. Queue3 contains
exactly `writeBuffer`, `writeTexture`, and `submit`. These are the synchronous
ordinary routes already selected by the Realm presentation adapter. The view
does not add `createBuffer`, `createTexture`, `destroyResource`, `runOneShot`,
event listeners, a device-loss promise, asynchronous pipeline methods or
device-level compute methods. Buffer/texture creation keeps its exact
receipt-bound allocation route. Existing nested compute operations, if reached
through the command encoder, retain their current compute-capability gate;
they do not gain a new grant. (Sources: `RealmGpuPresentationPortContract.js`,
`REALM_GPU_DEVICE_FACADE_METHOD_IDS`; `RealmGpuPresentationSyscallAdapter.js`,
`createRawDeviceFacade()`, `createRawTransferContext()`, `createRawJobContext()`;
`GpuDeviceBroker.js`, `wrapCommandEncoder()`.)

The Adapter must retain the original `active.device` for existing exact-facade
checks and cleanup compatibility. It retains the ordinary-work view separately
and selects it only for the enrolled claim's listed work routes. Rootless and
legacy callers keep their existing path, including the immutable policy opt-out
before supplied-receipt authentication. A caller cannot retrofit enrollment by
capturing cleanup later. Never replace the actual-facade identity proof with
the derived view or a copied metadata record.

The proposed inner checkpoint follows the existing allocation precedent:

1. Reserve a short cohort observation after checking original cohort liveness.
2. Check the original mount, including external kernel observations, then invoke
   the cohort's original retained admission operation.
3. Recheck broker-owned device/owner/restoration state without external getters.
4. Recheck private cohort closure/seal state, then enter the captured operation.

No external kernel getter, diagnostic callback, descriptor read or coercion may
follow the final Realm admission before the intended native call. Factor the
broker-only state check from resource-request membership; do not fabricate a
live allocation request merely to reuse the helper. End every observation fence
before entering a native operation or waiting. Keep restrictions in per-view
closures, never an ambient shared "current Realm" slot. A rejected reentrant
observation must not clear another observation's reservation.

Core admission must check the original dispatched, unreleased, source-global
claim and its adopted receipt before and after owner observation **only after
the strict claim has authenticated its adopted receipt and original facade**.
The implementation latches that binding at native-view capture, not dispatch:
dispatch itself observes owner work before an adopted receipt exists. Use retained private claim/token state and the
existing direct protected-allocation check. Calling `captureRealmGpuProtectedWorkSource()`
or `state.assertWork()` from admission would recurse through the same work
observation. Do not change legacy admission, promote an old cohort, transfer a
dispatched claim, or reopen a terminal seal.

Reuse the native operation implementation with an explicit view-bound check.
Do not call `_buildFacade()` again: it also creates loss records, listeners,
caches and owner publication state. Do not mutate the original facade's guard,
cache or listener ownership. A restricted view must not become another entry in
the original-facade issuer registry. Use view-local cache identity and final
cache-hit checks. Nested command/pass wrappers and finished-command-buffer
provenance must retain the same view restriction; an outer wrapper alone does
not close an already-entered inner operation. Preserve the existing one-shot,
single-finish, single-submit and escaped-callback protections.

**Descriptor conversion is a separate acceptance boundary, not solved by the
two method-getter fixes.** The current shader implementation reads `desc.code`
but passes the original descriptor to the native call. Native argument
conversion can execute another getter or coercion inside that call, after the
last outer check. The complete reviewed-native-boundary gate therefore also
requires bounded, schema-directed snapshots of supported descriptor fields,
numeric/string conversions and iterables before final admission, preserving
opaque GPU references. No generic deep clone, resource proxy or silent
narrowing of existing accepted descriptors is authorized by this proposal.
An implementation that closes only method lookup/cache checkpoints must be
reported as that bounded result; descriptor conversion remains unaccepted until
its independent tests pass. Raw opaque-resource child methods and mapped-memory
writes remain later gates even after descriptor admission is verified.

The dependency-ordered build contains eight flat pieces. Each is a bounded
implementation/review unit within piece 9, not another nested roadmap:

1. **[MODIFY] Broker checkpoint reuse:** separate callback-free mount state from
   allocation-request membership; preserve all existing allocation behavior.
2. **[NEW] Original-cohort view:** add exact-one private issuance, WorkView8/Queue3,
   lazy operation selection, view-local caches and no additional owner lifecycle.
3. **[MODIFY] Native work boundaries:** carry the retained check through native
   lookup, return, cache and nested commands. Complete or explicitly retain the
   independent descriptor-conversion gate; do not claim it from getter tests.
4. **[MODIFY] Core claim binding:** extend only strict admission and add exact-three
   private capture, with original facade, receipt and irreversible-claim checks.
5. **[MODIFY] Adapter routing:** keep original device identity, cache its separate
   view and route only listed ordinary operations through it; preserve cleanup.
6. **[MODIFY] Browser evidence:** add positive twins and hostile cases from the
   matrix, retain both strict native-gap assertions and original regression gates.
7. **[MODIFY] Structural/bundle evidence:** freeze exact new exports and shapes;
   rerun both initial import orders and reviewed allowlisted canonical closures.
8. **[MODIFY] Plan and memory:** record actual acceptance, hashes, remaining gaps
   and rollback boundary without advancing full B4H or the visible-city gate.

| Acceptance family | Required evidence, beyond a thrown error |
| --- | --- |
| Original provenance | Broker rejects copied/proxied/non-original cohorts before reflection. Core rejects foreign/sibling routes and wrong enrolled receipts/facades. Neither new export accepts a supplied restriction or registration writer. An existing genuine generic cohort may already retain a caller-authored admission restriction; that never proves Realm origin. |
| Native creation | Current positive twin reaches the native method exactly once. Getter-triggered stop/work abort reaches the getter but performs zero native calls. Revocation during an already-started native call suppresses publication; it is not represented as an undone effect. |
| Caches and reflection | Current misses/hits preserve the intended view-local identity. Revocation from broker-controlled key/member/metadata reads prevents stale hit publication and native miss effects. Test descriptor conversion inside the native call independently. |
| Queue and commands | Test native writeBuffer/writeTexture/submit, encoder creation/begin/copy/clear/finish and reached pass methods. Stale captured callables perform zero effects. Finished buffers cannot acquire a successor view's proof. Keep exact-sentinel rejection checks. |
| Same-mount isolation | A genuine ordinary/rootless sibling on the same original mount continues before/after rooted stop, in both construction orders. Two rooted views cannot borrow each other's receipt or currentness. Nested A-to-B-to-A and throwing paths preserve each restriction without ambient context. |
| Publication and teardown | Delayed work cannot publish under a successor. Late allocation candidates remain original-cohort-owned. Stop, failed cleanup and explicit retry still drain the same handles without duplicate destruction or ordinary-work admission during terminal cleanup. |
| Compatibility and imports | Frozen v1/v2/v3, v4 lease6, dependency16, start9, Source1, Token4, Core3, Control5 and WorkSource6 remain unchanged. Preserve the exact four-member/five-edge authority cycle; no reverse Broker-to-Realm import is needed. |

Use existing fixed issuer errors and Presenter diagnostics for rejected work.
Do not add logging inside callback-free proof tails or log capabilities, code,
resource handles or identity-bearing private records. Count effects in the test
harness. New source exports require explicit structural expectations, not an
unrestricted allowance or a changed test denominator.

Approval covers the two additive host-private capabilities and the listed
view-bound routing, not a new application dependency or broad GPU authority.
Rollback disables the new view route and reverses only this slice's reviewed
changes; it does not reset the repository, erase concurrent changes, weaken
the two native assertions or revert independent terminal cleanup. Approval was
received before implementation; the wider open gates retain their own acceptance.

Full-provider mount/backend isolation, genuine resource telemetry, activation-
selected ownership, recovery, physical GPU execution/quiescence and the real
M1C-to-first-submitted-city-frame route remain open. RealmForge's accepted inert
artifacts remain inputs to that later integration; this proposal neither edits
RealmForge nor claims a walkable city, first-person traversal or local Operations
View. First Shard remains excluded from source scans, builds and generators.

##### Original-cohort native work-view implementation

**2026-09-12 accepted bounded result: 734/734 browser executions across20 gates
and605/605 Python checks across38 exact files.** The original two native-method
getter failures now pass, without weakening their zero-effect assertions. A
separate descriptor-conversion probe failed **0/1** at that checkpoint and was
not counted as accepted. These are instrumented native/service boundaries, not physical GPU
execution or complete GPU-effect isolation.

Those counts and the descriptor failure describe the native-view checkpoint.
The later [protected shader implementation](#protected-shader-descriptor-profile-implementation)
records the separately approved conversion change and its own evidence.

The implementation changes only three production modules:

- `webgpu-os/kernel/GpuDeviceBroker.js` authenticates an original generic cohort
  in exact-one `createGpuOriginalCohortWorkView()`. Its private retained factory
  issues WorkView8/Queue3 without rebuilding the mount facade or changing its
  guard, shader cache, loss/listener ownership or original-facade registry.
  Generic retained admission is an additional restriction, never Realm identity.
- `webgpu-os/kernel/realm/RealmGpuAllocationCohortCore.js` adds exact-three
  `captureRealmGpuProtectedNativeWorkView(route, receipt, actualFacade)`.
  Original route/claim checks precede receipt/facade checks; genuine rootless
  policy still returns `null`. A genuine strict claim latches its exact adopted
  receipt after original-facade authentication and before view creation. Failure
  retains that latch; only the same claim/receipt can retry. Direct private
  admission checks run before/after owner observation without recursing through
  work-source capture. Latching at dispatch would reject valid startup before
  adoption, so no strict binding is inferred merely from `strictWork`.
- `webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`
  retains original `active.device` for identity/allocation/cleanup and caches the
  derived view separately. Only the enrolled claim's six ordinary creation
  methods, encoder and queue work select it. Loss/retirement clears the view;
  the independent terminal channel still drains original owned handles.

Shared native-operation helpers accept an explicit view check. That check holds
only a short per-cohort observation reservation, checks original mount state,
invokes retained admission, then checks callback-free broker/cohort state. It
releases its reservation before native effects or waits. A rejected reentrant
check cannot clear another check's reservation. Native member lookup and cache
publication recheck the original claim. Revocation inside an already-entered
native call rejects publication; the implementation does not claim to undo it.

Shader caches have independent view identity. Nested command/pass callables,
object aliases and self-returned pass aliases retain the same view restriction.
Pass end and encoder finish are one-way; ended aliases cannot restart work.
Finished command buffers retain private view provenance. Submit preflights all
members before changing any status, rejects foreign/duplicate/submitted buffers,
and restores only pending buffers if failure occurs before the native call.
Existing compute gates remain restrictions. No arbitrary opaque-resource graph
compatibility, buffer/texture child membrane or mapped-memory protection is added.

The final browser matrix retains all original regression cases and expands
ordinary31 to90 with positive twins, lookup-triggered revocation, already-entered
return rejection, independent cache identity, same-mount rootless siblings,
command/pass aliases, cross-view submit and reentrant observation. Ordinary90
and the original native2 run in source form and both canonical import orders.
The20 accepted gates have zero skips, denied requests or unexpected browser
errors. Eight canonical builds report exactly one expected absent-VirtualGPU
diagnostic each; that excluded source is not supplied or read.

Reproduce the accepted browser selection:

```powershell
python -B tests/virtual-realm/run_protected_startup_browser.py generation stable owned prebind host protected cohort-terminal terminal ordinary native-gap presenter-first controller-first bundle-presenter-first bundle-controller-first bundle-terminal-presenter-first bundle-terminal-controller-first bundle-ordinary-presenter-first bundle-ordinary-controller-first bundle-native-gap-presenter-first bundle-native-gap-controller-first
```

Accepted receipt:
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-ku7vxp3d.json`;
SHA-256 `1a911aaea3c86ba538fe3804cc65834fe306c1dfb95f6f35d8436d25b03321d9`.
The249 served routes have aggregate
`8f40fabe1e599f3399d74864937d79a4868e09da57f924ee625877b9a6eb2c31`.
Final normalized production SHA-256 values match the served receipt:

| Module | SHA-256 |
| --- | --- |
| Broker | `0faeb80e0896121bf0263801483ba57b66e458162f9e8e638286c4a9cd9d3f29` |
| Core | `55eaff2b2f20be5b49419d56cda4a6048f719d8b84753e2723dd72f4bcae855f` |
| Adapter | `34e8fa98d3fb291faee81ec7e96ba8922a8ad0d77e75bbc12fa1ea56927c3e6f` |

The new structural gate is
`tests/virtual-realm/test_m2db4h_gpu_native_work_view.py` (**18/18**).
Six existing structural gates received exact additive-export/private-factory
expectations and browser counts, not relaxed authority assertions. The full
reviewed38-file Python selection passes605/605. Frozen v1/v2/v3, v4 lease6,
dependency16, start9, Source1, Token4, Core3, Control5 and WorkSource6 are unchanged.
No import edge was added: authority source83, its exact four-member/five-edge
cycle, Entry155, B3114 and wrapper115 remain the reviewed closures.

Reproduce the independent open conversion witness:

```powershell
python -B tests/virtual-realm/run_protected_startup_browser.py descriptor-gap
```

This command intentionally exits unsuccessfully: shader descriptor `code` is
read twice, the second read stops the Presenter inside the native operation,
and one effect occurs where zero is required. The separate receipt is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-kzlxubuk.json`;
SHA-256 `22064c5067acdab68d56a80eced204dbba68334c1c4f5bb1efb813aae53bb5d9`.
It uses the same final production bytes. A future bounded inert snapshot may
correctly read the caller's getter once and perform a still-current effect;
acceptance must include that positive case and zero effects after actual
revocation, not force repeated caller getters or merely suppress valid work.

**Next acceptance boundary:** schema-directed native argument conversion and
separate native-return/thenable conversion. The current promise-settlement guard
does not certify arbitrary thenable assimilation. Keep opaque GPU leaves intact;
do not introduce a generic deep clone or silently narrow accepted descriptors.
The trust scope remains retained kernel/broker internals and intrinsics, not
isolation from hostile same-origin replacement of globals. View-local shader
cache lifetime is not universal zeroization or physical resource reclamation.

Raw resource children/mapped memory, authenticated frame readiness, physical GPU
execution/quiescence, full-provider mount/backend isolation, selected-Realm and
activation ownership, genuine telemetry, recovery and the production
M1C-to-first-submitted-city-frame route remain unaccepted. First Shard was not
scanned. Full OS/API/docs/SPDX discovery generators were not run; verification
used exact reviewed source/test allowlists and scoped documentation checks.
RealmForge and other parallel production work remain unchanged by this slice.

##### Shader descriptor conversion profile proposal

**2026-09-12 approved blueprint.** The user approved this bounded protected-shader
profile, its exact limits, standard-only handling and complete conversion on cache
hits. The [implementation record](#protected-shader-descriptor-profile-implementation)
is separate from the proposal-time analysis retained here. The complete unit is
the protected shader descriptor, not all WebGPU argument conversion. It stays in flat
piece9 and preserves the original device, public wires and terminal cleanup.
It adds no world milestone and does not advance M1C-to-visible-city acceptance.

The proposal-time source defect was specific: `createTrackedShaderModule()` read
`desc.code` for its cache and forwarded the original descriptor. A native method
could read another accessor after final admission. Copying only `code` leaves
label conversion, compilation hints and their nested conversions live. The
existing buffer/texture request helpers cannot be applied unchanged: they rely
on active allocation-request membership and impose different string/iteration
rules. Do not fabricate a resource request for ordinary work.
(Source: `webgpu-os/kernel/GpuDeviceBroker.js`, `_requestString()`,
`_snapshotStringIterable()`, `createTrackedShaderModule()` and `createWorkView()`.)

The proposed standard profile converts inherited label before code, then
compilation hints, with each read converted before the next member. Empty strings
are valid conversion results; missing required values and Symbols are not.
USVString conversion replaces lone surrogates. Hint layout is optional and accepts
a genuine pipeline layout or the auto-layout enum. These rules come from the
[official WebGPU interface definitions](https://gpuweb.github.io/gpuweb/webgpu.idl)
and [WebIDL conversion algorithms](https://webidl.spec.whatwg.org/#es-dictionary).

**Approved limits.** No existing shader-text or hint-count
quota was found in the reviewed authority83 source set. Shader accounting counts
objects; buffer/texture and queue quotas are not shader-input limits. Therefore
the following values are new host policy, not inferred device limits or existing
WebGPU guarantees. They apply only to the separate protected work view:

| Input | Approved maximum | Enforcement |
| --- | --- | --- |
| Converted shader code | 1,048,576 UTF-16 code units | Reject before native lookup or cache publication; never truncate. |
| Converted label | 4,096 UTF-16 code units | Reject excess length; preserve Unicode conversion for accepted values. |
| Each converted hint entry point | 4,096 UTF-16 code units | No identifier rewriting or truncation. |
| Compilation hints | 4,096 entries | Permit one final iterator step to detect completion; do not read a 4,097th entry value. |
| Combined converted code, label and entry-point strings | 2,097,152 UTF-16 code units | Track one per-call total; reject before publishing a cache/native result. |

These are logical conversion limits, not physical VRAM, UTF-8 byte limits,
working-set leases or wall-clock guarantees. They cannot interrupt a getter or
iterator method that never returns, and cannot undo memory allocated inside
caller code. A finite list budget prevents the converter itself from consuming
an unbounded number of returned entries. The alternative is standard-compatible
conversion without new finite limits, which must explicitly forgo that guarantee.
Do not reuse the unrelated storage working-set service as GPU authority.

**Standard-only compatibility boundary.** Chromium's developer-feature
`strictMath` field is absent from the standard shader dictionary. The proposed
profile rejects a supplied non-undefined `strictMath` value with a fixed
unsupported-profile error, rather than silently changing its requested behavior.
That check performs one guarded property read, including inherited getters and
getters that return `undefined`. This extra observation is an explicit profile
change: the standard dictionary normally ignores that field. It follows standard
field conversion and occurs before cache/native effects. It does not enumerate
or reflect arbitrary unknown keys.
Other unknown standard dictionary members remain ignored. This is not universal
support for browser extensions or future dictionary versions. The original shared
facade keeps its current descriptor path and browser-specific behavior.
(Source: [Chromium shader descriptor IDL](https://raw.githubusercontent.com/chromium/chromium/main/third_party/blink/renderer/modules/webgpu/gpu_shader_module_descriptor.idl).)

**Original layout union, not a caller assertion.** Forwarding an arbitrary object
unchanged is insufficient: a non-layout object can trigger native enum coercion.
Stringifying every object is also incorrect because genuine GPU layouts must keep
their identity. The candidate solution captures the native
`GPUPipelineLayout.prototype.label` getter during trusted bootstrap and calls that
retained getter as a nonmutating interface-brand check. It must not read candidate
properties, use `instanceof`, trust prototype equality or infer authenticity from
function source text. A successfully branded layout is retained unchanged;
nonbrands undergo guarded enum conversion before final admission.

The proposal inferred the brand strategy from the
[WebIDL attribute getter rules](https://webidl.spec.whatwg.org/#es-attributes)
and the [pipeline-layout interface](https://raw.githubusercontent.com/chromium/chromium/main/third_party/blink/renderer/modules/webgpu/gpu_pipeline_layout.idl),
before native-browser evidence existed. Acceptance requires real same-realm and
cross-realm layouts, wrong GPU interfaces, prototype forgeries and proxies.
An unavailable or untrusted native accessor is a missing prerequisite, not
permission to substitute a caller-supplied brand checker. Interface branding does
not establish device compatibility, Realm ownership or permission to use a resource;
existing browser and Realm checks remain required.

**Cache compatibility.** Convert the complete standard descriptor on every
protected invocation, including cache hits, so cached work cannot bypass current
admission or profile validation. Preserve the current code-only cache policy and
raw-string eligibility: a once-read raw string remains the cache key; an object
coerced to a string does not newly become cache-eligible. Do not mix cache-key
redesign, label updates or hint-key partitioning into conversion fencing.
Because cache hits previously skipped label/hint conversion, the newly observable
reads and possible rejections are part of the requested profile approval.

The eight dependency-ordered implementation/review pieces are:

1. **[MODIFY] Freeze the profile:** record approval for exact limits, extension
   rejection and complete conversion on protected cache hits; keep legacy paths.
2. **[NEW] Private scalar conversion:** guarded dictionary reads and USVString
   coercion, required/default handling, inherited properties, exact error paths
   and per-call accounting. Reuse pinned apply/freeze/record operations.
3. **[NEW] Private hint sequence:** capture iterator and next once, guard every
   caller-controlled observation and apply the finite budget. Propagate standard
   conversion failures without reading/calling iterator `return`; quota and
   revocation aborts likewise discard private partial state without that callback.
   Publish no caller iterator or mutable-prototype hook.
4. **[NEW] Native layout brand:** capture the original accessor, preserve branded
   leaves and convert other values before final proof. No authority registry or
   supplied predicate is added; a missing authentic prerequisite blocks acceptance.
5. **[NEW] Complete shader snapshot:** create an immutable, fixed-field descriptor
   with captured scalar values and inert hint records/iteration. The original
   descriptor never reaches native shader creation or post-admission cache work.
6. **[MODIFY] Strict-view integration:** reuse `createTrackedShaderModule()`, its
   independent cache, accounting and `callNativeMethod()`. Add no Broker-to-Realm
   import, `_buildFacade()` reentry, shared-facade mutation or cleanup work guard.
7. **[MODIFY] Independent evidence:** positive conversion/order/Unicode/limit/cache
   twins, exact revocation effect counts, genuine native union differentials and
   existing source/canonical regressions. Do not relabel an unrun native test passed.
8. **[MODIFY] Plan and memory:** publish source-bound results, limitations and the
   next conversion family; keep the ten-row ledger and M1C status unchanged.

The private Broker implementation is preferred for this bounded gate. A new pure
helper module would add a reviewed dependency to every Broker-containing graph;
it is not necessary merely to reuse a name. Reuse the existing work check and
native call boundary, not strict JSON validators: those reject accessors and
opaque objects and do not implement WebIDL. Keep fixed error identifiers and
Presenter diagnostics, with no logging callback in the final authority tail.
Rollback reverts only this profile's routing and new private helpers/tests,
preserving the approved native view, prior sources and independent cleanup.

| Required evidence | What must be observed |
| --- | --- |
| Original witness, valid snapshot | Caller code getter runs once; the second-read stop trap is never reached; one current native effect uses the captured code. This positive case replaces neither actual-revocation checks nor historical failure evidence. |
| Actual revocation | A reached label/code/hint getter, coercion or iterator callback revokes the original claim; zero native shader effects and zero cache publication follow. Count callbacks and effects, not merely a rejected promise. |
| Native input | A distinct immutable snapshot contains only captured standard fields and genuine opaque leaves. Native lookup-time mutation cannot alter it or trigger caller conversion again. |
| Conversion parity | Inherited/function dictionaries, defaults, required errors, empty strings, Symbol rejection, surrogate normalization and order agree with the declared profile. |
| Iterator and limits | Positive finite iterables, malformed steps, truthy done conversion, exact-limit success and over-limit rejection preserve the specified result. Conversion, quota and revocation failures never read/call iterator `return`; test with hostile return getters. No implicit for-of cleanup semantics. |
| Layout union | Authentic cross-realm leaves preserve identity; forged/proxied/wrong-interface values do not gain a brand. Nonbrand enum coercion happens only before final proof. |
| Cache and siblings | Complete protected conversion cannot publish a stale hit; raw-string-only eligibility remains. Same-mount ordinary/rootless callers preserve current behavior and terminal cleanup stays independent. |

The remaining native conversion families stay flat and separate:

| Existing route | Conversion work not accepted by the shader proposal |
| --- | --- |
| `createSampler` | Labels, enums, finite floating-point fields and anisotropy conversion are accepted by the later [protected sampler profile](#protected-sampler-descriptor-conversion), with explicitly approved installed-native numerical behavior. This does not certify native-return handling or other creation families. |
| `createBindGroupLayout` | [Entry-sequence and nested-layout profile](#protected-binding-layout-conversion-review) accepted with standard traversal,4096-entry conversion cap and explicit experimental-member rejection;126 profile/27 native checks pass in source and both canonical import orders. Other creation families and native returns remain separate. |
| `createPipelineLayout` | [Approved pipeline-layout implementation](#approved-pipeline-layout-implementation): required layout sequence, nullable native BGL identities and current-standard immediateSize. Standard iteration and an independent4096-layout cap are approved; implementation and verification are underway, not accepted yet. |
| `createBindGroup` | Exact layout and entry resource unions, including buffer-binding records. |
| `createRenderPipeline` | Stage constants, vertex/target sequences and nested raster/depth/stencil/blend state. |
| Encoder creation and finish | Label descriptors and optional/default argument handling. |
| Queue writes | Numeric offsets, buffer-source brands, sharing/detachment, copy/layout dictionaries and extent unions. |
| Queue submit | Iterable-to-native conversion and immutable traversal in addition to accepted private command provenance. |
| Pass creation | Attachments, clear values, timestamp/query fields and nested opaque resources. |
| Copy/clear/query commands | Numeric overloads, texture-copy dictionaries, extents and resource brands. |
| Reached binding/draw/compute commands | Dynamic-offset overloads, typed arrays, immediate data, nullable groups, bundle iteration and indirect offsets. |
| Debug commands and label setters | String conversion before native calls or setters. |
| Dynamically forwarded pass extensions | Explicit supported signatures; unknown methods cannot be certified by a generic proxy. |
| Native returns | Thenable/promise assimilation remains a separate conversion boundary. |

This map describes work to review, not new callable APIs or grants. It excludes
device-level compute-pipeline creation and queue external-image copying, which
are absent from WorkView8/Queue3. Full-provider isolation, opaque resource children,
mapped memory, physical GPU evidence, authenticated frame readiness, activation,
telemetry, recovery and M1C first submitted city frame remain separate gates.

**Fresh verification preflight, not a rerun of734/605.** The unmodified runner
stopped before browser launch at a new, unreviewed storage import. Exact inspection
traced it to `webgpu-os/storage/OPFSDriver.js` and `MountDriver.js`, which import
`AsyncByteSource.js`. That module imports the already-reviewed `FileStreamWrite.js`
and new `WorkingSetBudget.js`; both leaf dependencies have no imports. These are
two additional wider browser graph nodes, not a change to authority83 or its
four-member/five-edge cycle. Only OPFSDriver and MountDriver differ from the prior
receipt among equivalent-preprocessed covered inputs; all three native-view
production modules still match their accepted hashes.

The existing native work-view structural gate was rerun separately and passes
**18/18 in8.33 seconds**. This verifies the retained source/authority checks,
not the proposed shader profile or a new browser/physical-GPU acceptance.

A read-only transient union of those two exact reviewed paths measures203 modules
for ordinary, native-gap and descriptor-gap, with the same reviewed cycles and
zero skips or further denied paths. No persistent inventory, production or test
source was changed for this preflight. The stored90/2 passing and descriptor0/1
results remain historical until the exact wider inventory and count pins are
reconciled and the browser reruns. Do not add wildcard exceptions or read an
unreachable factory SDK merely because it occurs in the larger allowlist.
First Shard and full OS/API/docs discovery remain excluded.

##### Protected shader descriptor profile implementation

The approved shader profile is implemented inside `GpuDeviceBroker.js`, with
no new production import or public export. This is the shader portion of flat
piece9, not a new milestone, full native conversion coverage or M1C acceptance.
**Final bounded acceptance:887/887 browser executions across29 gates and625/625
Python checks across39 exact files.** After final browser-test hardening, the40
affected Python checks also passed again; those are reruns, not40 new cases.
The earlier734/605 native-view checkpoint remains separate historical evidence.
Trusted bootstrap and kernel internals remain prerequisites; captured intrinsics
are not isolation from malicious same-origin replacement before import.

`snapshotProtectedShaderDescriptor()` captures inherited label, required code
and compilation hints in standard dictionary order, converting each field before
reading the next. It then performs the approved single `strictMath` read.
Non-undefined extension values fail with `GPU_PROTECTED_SHADER_UNSUPPORTED_PROFILE`.
Unknown keys are not enumerated. Original shared-facade calls keep their prior
descriptor identity, browser-extension handling and cache behavior.

`guardedShaderObservation()` reasserts the original work restriction before and
after each reached getter or call, including thrown callbacks. Private scalar
conversion separates primitive-hook lookup from invocation, implements the
string-hint fallback order and rejects Symbol results. It replaces lone UTF-16
surrogates while retaining valid pairs and checks all five approved limits.
Broker-generated limit and validation failures use fixed RangeError and TypeError
codes. Caller exceptions and native conversion failures retain their propagation
unless the original-authority recheck supersedes them. For example, a noncallable
retained iterator `next` fails at its native invocation. No logger callback is
inserted into the final authority tail.

Independent review found a concrete native-compatibility defect in the first
implementation: `typeof value === 'function'` misses the callable
`document.all` legacy object. A real shader call accepted a primitive hook that
the first protected converter rejected. `isShaderCallable()` now handles that
specific callable exception without candidate reflection or invocation.
The native accessor check remains separate and still requires the retained
platform getter. This follows the
[HTMLAllCollection callable rules](https://html.spec.whatwg.org/multipage/common-dom-interfaces.html#the-htmlallcollection-interface),
not a generic caller-supplied authenticity claim.

`snapshotShaderHintSequence()` captures the input iterator method and `next`
once. It guards calls, `done` and `value` reads, respects truthy completion and
rejects a non-complete4097th step before reading its value. Conversion, quota
and revocation failures never read or call iterator `return`. Owned hint records,
their indexed table and the published iterable/iterator/result records are
frozen and have null prototypes. Native consumption reaches only fixed own data
and retained private functions, not ambient Array/Object iteration hooks.

`shaderHintLayout()` probes with the import-retained native pipeline-layout
label getter. Genuine layouts retain their exact opaque identity; a nonbrand
must complete guarded conversion to `auto`. Authority failures cannot be caught
as brand failures. Only the native getter's ordinary TypeError selects enum
fallback; other native failures propagate. Missing native branding is an explicit
prerequisite error, not permission to fabricate a checker. Branding still grants
no device compatibility, resource ownership or Realm authority.

`createTrackedShaderModule()` converts the full protected descriptor before
either cache lookup or native method lookup. It preserves raw-string cache keys
separately from normalized code, so string-coerced objects do not newly gain
caching. The protected cache uses retained Map operations. The shared path keeps
its original has/get/set behavior. Original descriptor objects never enter the
protected native shader call.

The rejection harness counts shader results immediately when creation returns,
before any following submission. A later submit failure therefore cannot mask
a stale cached return. A separate direct original WorkView cache-hit test uses
its genuine generic cohort restriction and exact denial identity, so an Adapter
post-check cannot hide an inner cache failure. That generic restriction test is
not Realm-origin proof; the existing actual-claim revocation twin remains separate.

The limits bound this converter's completed observations and accepted string
totals. They cannot interrupt nonreturning caller code, recover memory allocated
inside callbacks or prove physical VRAM reclamation. Other descriptor and command
families, thenable return conversion, raw resource children, mapped memory,
authenticated frame readiness, full-provider activation, recovery and the real
M1C-to-first-submitted-city-frame route remain open. The following sampler slice
stays within the existing remaining-family map; it does not extend shader
acceptance to every native argument family.

**Source and canonical browser evidence:**

| Reviewed cases | Source | Presenter-first bundle | Controller-first bundle |
| --- | --- | --- | --- |
| Descriptor regression twins | 2/2 | 2/2 | 2/2 |
| Protected shader profile | 42/42 | 42/42 | 42/42 |
| Genuine native GPU evidence | 7/7 | 7/7 | 7/7 |
| Preserved ordinary-work regressions | 90/90 | 90/90 | 90/90 |
| Original native-member regressions | 2/2 | 2/2 | 2/2 |

The full29-gate matrix also reruns generation, stable allocation, owned allocation,
pre-bind, host lifecycle, protected startup, cohort terminal cleanup, Presenter
terminal cleanup and both initial module import orders. It has zero skips,
unexpected browser errors or denied requests. Each of14 canonical bundles emits
only its exact predeclared missing-`engine/core/gpu/VirtualGPU.js` diagnostic.
That excluded module was not read or supplied; the diagnostic is not suppressed.

Native evidence used installed Chrome151.0.7922.174 with reported adapter
architecture `blackwell`, without special GPU flags. Real same-realm and
cross-realm layouts survive protected snapshots and native shader creation;
the positive native shaders report no compilation errors. Wrong interfaces,
forgeries and proxies fail the retained native brand probe. Genuine layout
property traps and a later prototype-getter replacement remain unobserved.
The browser reads compilation hints, entry point and layout once each in all
three variants. These observations do not claim exhaustive native hint-dictionary
parity, device compatibility, physical GPU quiescence or a submitted city frame.

The new shader structural gate contains20 tests. The exact39-file run passed625
checks in307.50 seconds. After the publication-counter/direct-cache strengthening,
the affected ordinary-work and shader gates passed40/40 in23.922 seconds with
unchanged before/after source hashes. The authority graph remains83 modules with
its exact four-member/five-edge component; Entry155, B3114 and wrapper115 remain
unchanged. The two separately reviewed storage nodes affect only wider test
inventories. The shader source graphs contain203 modules; canonical equivalents
contain202. No production dependency or frozen interface changed.

The final browser receipt is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-_dodq_7w.json`,
SHA256 `36642ef353d3e94077309edf1e71abbdba2ef5df07b7ddd71570786f1246b98d`.
It binds269 served routes; the served-set aggregate is
`0de78b00ec1c7fef781feaafcf0e5f6660bbb1aea05a496a4c624c3d931ff136`.
At that shader checkpoint, Broker, Core, Adapter, test and fixture normalized
bytes matched that receipt. The checkpoint Broker's normalized SHA256 is
`464e7f643303dd3bacb8abeef1297ae2d79454d2fba0472c7bd92548bdc9358c`;
Core and Adapter retain their prior accepted hashes.

The625-check JUnit report is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-shader-structural-20260912144849.xml`,
SHA256 `72b018ab1287a0ceed96fbb431d7984997ccaff2bdcf25cc0b5b966132f1f250`.
The final40-check companion is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-shader-structural-20260912144849-final-browser.xml`,
SHA256 `e7a5db02a94b22db2e536d0ac1a117b7241af0e41d018fc162c281a4fc73e685`.
Full selection details and intermediate findings are retained in session memory.

Reproduce the final browser matrix from the repository root:

```powershell
$vrShaderGates = @(
    'generation', 'stable', 'owned', 'prebind', 'host', 'protected', 'cohort-terminal', 'terminal', 'ordinary', 'native-gap'
    'descriptor-gap', 'shader-profile', 'shader-native', 'presenter-first', 'controller-first'
    'bundle-presenter-first', 'bundle-controller-first', 'bundle-terminal-presenter-first', 'bundle-terminal-controller-first'
    'bundle-ordinary-presenter-first', 'bundle-ordinary-controller-first', 'bundle-native-gap-presenter-first', 'bundle-native-gap-controller-first'
    'bundle-descriptor-presenter-first', 'bundle-descriptor-controller-first', 'bundle-shader-profile-presenter-first', 'bundle-shader-profile-controller-first'
    'bundle-shader-native-presenter-first', 'bundle-shader-native-controller-first'
)
python -B tests/virtual-realm/run_protected_startup_browser.py @vrShaderGates
```

One earlier full attempt stopped on the existing15-second browser-control socket
timeout before producing a receipt. The same generation gate then passed alone,
and the final29-gate retry completed without timeout changes. That interrupted
attempt is not accepted evidence. The original two-read descriptor witness and
its failing baseline receipt are retained as history, not registered as a passing
test. Acceptance uses both the one-read current-effect twin and reached actual-
revocation checks, including immediate-return and direct-cache assertions.
No First Shard scan, full OS bundle or broad docs/API/SPDX discovery generator
was run. Curated documents receive exact heading/link/ledger and hygiene checks.

Sources: `webgpu-os/kernel/GpuDeviceBroker.js`, private shader-profile helpers,
`createTrackedShaderModule()` and `createWorkView()`;
`tests/virtual-realm/m2-gpu-presenter-ordinary-work.test.js`;
`tests/virtual-realm/test_m2db4h_gpu_shader_descriptor_profile.py`.

##### Protected sampler descriptor conversion

The Virtual Realm's protected sampler path snapshots `GPUSamplerDescriptor`
inside `GpuDeviceBroker.js` before native sampler method lookup and invocation.
This is a continuation of flat piece 9, not a new milestone or public interface.
It closes caller-input conversion for this one creation method. It does not
certify other descriptor families, native return conversion or visible-city
integration. The user approved matching the installed browser on 2026-09-12
after reviewing two numerical differences from WebIDL. The selected behavior
is implemented and accepted as this bounded conversion slice:1175/1175 browser
executions across35 gates, plus the explicitly recorded Python regression
run and corrected companion below. This is not full B4H or visible-city acceptance.

This profile is tied to the reviewed Chromium `151.0.7922.174` behavior, not a
claim of universal browser parity. No user-agent sniff, runtime version switch,
native effect probe or new browser admission restriction is introduced. Other
engines and changed browser behavior require explicit parity evidence before
their compatibility can be certified. Original shared-facade behavior, the
accepted shader profile and independent terminal authority remain preserved.

The fresh, unchanged baseline passed 143/143 browser cases: ordinary (90),
native-member (2), descriptor (2), shader-profile (42) and shader-native (7).
All five source graphs retained 203 modules, and every served source matched the prior
accepted shader receipt. Before the fix, an ephemeral strict sampler witness
failed both the actual rooted route and the direct original generic WorkView:
one reached getter revoked access, but one native creation effect still ran.
Neither caller received a result. A rejected call alone therefore could not
prove the native effect had been prevented. The positive twin recorded one
getter, one creation effect and one immediate return.

Six dependency-ordered implementation pieces stay within the existing ledger:

1. [MODIFY] Extract shared private primitive/error/USV conversion mechanics;
   preserve the shader's exact limits, error codes and cache behavior.
2. [NEW] Capture sampler fields in standard inherited-dictionary order into
   a frozen null-prototype record containing only converted scalar values.
3. [MODIFY] Route only protected WorkView sampler calls through that snapshot;
   retain the original shared facade and independent terminal authority.
4. [NEW] Exercise reached field and coercion revocations, caller exceptions,
   native lookup mutation, immediate returns and original generic-view twins.
5. [NEW] Compare conversion against genuine same-realm and cross-realm WebGPU
   calls, with separate synchronous exceptions and device-validation results.
6. [MODIFY] Rerun the explicit browser/Python inventories and update the three
   curated plans and session memory without broad repository discovery.

`snapshotProtectedSamplerDescriptor()` accepts omitted, null and undefined
descriptors using standard defaults. Function and inherited dictionaries remain
valid; other primitives reject. The formal `descriptor` parameter avoids
reading a missing rest-array index. Extra arguments and unknown dictionary keys
are not inspected. Each listed field is fully converted before the next read:

| Observation order | Field | Conversion and undefined handling |
| --- | --- | --- |
| 1 | `label` | USVString; default empty string. |
| 2-4 | `addressModeU`, `addressModeV`, `addressModeW` | Address enums; default `clamp-to-edge`. |
| 5 | `compare` | Comparison enum; omit when undefined. |
| 6 | `lodMaxClamp` | Installed-native finite float32 conversion; default `32`. |
| 7 | `lodMinClamp` | Installed-native finite float32 conversion; default `0`. |
| 8 | `magFilter` | Filter enum; default `nearest`. |
| 9 | `maxAnisotropy` | Installed-native clamped uint16 conversion; default `1`. |
| 10 | `minFilter` | Filter enum; default `nearest`. |
| 11 | `mipmapFilter` | Mipmap filter enum; default `nearest`. |

The field names and defaults follow the [WebGPU sampler descriptor](https://gpuweb.github.io/gpuweb/#dictdef-gpusamplerdescriptor)
and the [Chromium sampler IDL](https://raw.githubusercontent.com/chromium/chromium/main/third_party/blink/renderer/modules/webgpu/gpu_sampler_descriptor.idl).
Dictionary ordering follows the [WebIDL dictionary conversion rules](https://webidl.spec.whatwg.org/#es-dictionary).
The two approved numerical compatibility differences are documented in
[Sampler compatibility decision and approval](#sampler-compatibility-decision-and-approval).
These primary references informed the implementation; local verification is
separate evidence, not a claim that this custom converter is browser code.

`protectedPrimitiveValue()` reuses the existing original-work observation fence.
It separates each primitive-hook lookup from invocation. String hints try
`toString` before `valueOf`; number hints reverse that fallback. Symbol string
results and Symbol/BigInt numeric results fail before native creation. The
existing HTMLAllCollection callable handling remains intact. Callback-free
`normalizeProtectedUsvString()` is shared with shaders; sampler labels acquire
no shader text limit or additional extension read.

`samplerFloatValue()` rejects nonfinite input and raw values outside
`[-3.4028234663852886e38, 3.4028234663852886e38]` before retained float32 rounding.
Both endpoints are inclusive. Signed zero and in-range subnormal rounding remain
intact. The `NATIVE_SAMPLER_FLOAT32_MAX` constant is the IEEE finite endpoint,
not an added resource quota. `samplerAnisotropyValue()` maps NaN and nonpositive
values to positive zero, saturates at 65535, then truncates the remaining positive
fraction with retained `Math.floor`. It does not use WebIDL nearest-even rounding,
wrap modulo 65536, invent a device cap of 16 or prevalidate cross-field rules.
Actual GPU validation, including LOD ordering and anisotropic filter compatibility,
remains native. The deliberate differences from
[WebIDL float conversion](https://webidl.spec.whatwg.org/#es-float) and
[WebIDL integer conversion](https://webidl.spec.whatwg.org/#abstract-opdef-converttoint)
are covered by direct native comparisons.

Every directly reached caller getter or coercion call is fenced before and
after observation, including thrown callbacks. The fixed dictionary reaches
at most 66 direct member/coercion observations: 11 field reads and up to five
primitive-hook observations per field. That count excludes authority callbacks,
native member/result observations, nested re-entry and work inside caller hooks.
There is no label-size, callback-time, memory or physical VRAM bound. Missing
future native extensions require an explicit review; unknown keys are ignored
under the current standard, not probed or silently promoted into supported input.

The snapshot owns all ten defaulted fields and adds `compare` only when its
observed value is not undefined.
No caller dictionary, hook, prototype or mutable collection reaches the native
sampler argument. Original checks still surround native method lookup and
publication through the existing work route. There is no new sampler cache,
resource issuance, allocation request, registry writer, app dependency or lifecycle
channel. Original shared-facade calls retain descriptor identity and their prior
native conversion behavior, including the lack of this protected conversion fence.

Broker-generated conversion failures are frozen TypeErrors with fixed
`GPU_PROTECTED_SAMPLER_` codes: `DESCRIPTOR_INVALID`,
`STRING_CONVERSION_INVALID`, `NUMBER_CONVERSION_INVALID`, `ENUM_INVALID`, and
`FLOAT_INVALID`. Caller exceptions propagate unless the final original-work
check supersedes them. Existing Broker/Presenter diagnostics remain in use;
there is no new logger callback between the final authority proof and an effect.
Rollback is limited to this sampler routing and private conversion refactor;
the accepted original WorkView, shader policy and terminal channel must survive.

###### Sampler compatibility decision and approval

The user approved the installed-browser-compatible choice by answering
"do it" to the explicit request to match native sampler behavior while
documenting and testing its WebIDL differences. This is the selected numerical
contract, not an outstanding approval request. The following comparison and
failed-candidate receipts retain the evidence that prompted that decision.

The installed Chrome reports version `151.0.7922.174`. Independent native
observations and that exact Chromium tag establish two differences from the
WebIDL-based candidate, not a failed authority check or a fixture-only issue:

| Input | Historical standard candidate | Approved installed-native behavior |
| --- | --- | --- |
| `lodMaxClamp: 3.4028235e38` | Rounds to finite `3.4028234663852886e38`. | Throws TypeError before rounding. The exact maximum float32 remains accepted. |
| `maxAnisotropy: 1.5` | Rounds to `2`; default nearest filters then fail native validation. | Truncates to `1`; default filters remain valid. |
| `maxAnisotropy: 3.5` | Rounds to `4`. | Truncates to `3`. |

The exact-tag [Chromium float bindings](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/bindings/core/v8/v8_binding_for_core.h)
check the finite float32 interval before casting. An out-of-range double produces
infinity in `ToFloat`; the restricted-float wrapper then throws. The combined
restricted conversion therefore rejects rather than rounding that double to a
finite endpoint.
The exact-tag [Chromium integer bindings](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/bindings/core/v8/v8_binding_for_core.cc)
use `ClampTo` for the clamped uint16 path; the
[retained ClampTo implementation](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/platform/wtf/math_extras.h)
casts an in-range double to an integer, truncating its fractional part. Both
paths are source-confirmed for this installed version, not inferred solely from
the latest upstream branch. This is not a claim about every browser or future
Chromium release.

The two reviewed alternatives were:

- Preserve the installed browser behavior with an explicitly documented,
  tested native-compatibility profile. Other engines and browser changes need
  independent parity review; no runtime admission rule or caller-provided
  profile flag is inferred from that certification boundary.
- Retain the standard WebIDL candidate and explicitly approve its numerical
  differences from the installed native API. Native tests must then prove the
  declared differences as well as the common cases; they must not claim full
  native parity or simply delete the failing comparisons.

Installed-native behavior was selected explicitly; a passing source-only test
did not choose the policy. Forwarding guarded ToNumber doubles and
letting native conversion finish later is not an automatic third solution: an
invalid early numeric field could allow later caller getters to run before the
native rejection. That changes dictionary observation and exception ordering.
Any alternative requires a complete conversion-order design and new evidence.

The standalone native observation receipt is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-gbed2moi.json`,
SHA256 `3fabbf91e9b48ac2ef4e182decfa87605cb0e0389d5f05a92d794cab9916c2d2`.
It records browser observations, not sampler acceptance. The first candidate
run also exposed a test-only raw-facade assumption: that facade retains its
original native method, whereas WorkView performs lazy lookup. The corrected
test checks the original fixture's descriptor and call records, not the later
WorkView sink. No shared-facade production behavior was changed to satisfy it.

**Historical standard-candidate verification, not acceptance:** the seven explicitly
selected source browser gates reported 236/238 passing executions. The preserved ordinary90,
native-member2, descriptor2, shader-profile42 and shader-native7 pass 143/143.
The new sampler-profile gate passes 87/87; the strict sampler-native gate passes
6/8, failing precisely the float-limit and anisotropy comparisons. Its two
harness failure console records remain visible. There are zero skipped cases
or denied requests, and the overall receipt correctly records `allPassed: false`.

The final candidate receipt is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-teutydcu.json`,
SHA256 `c6631574fbb83948dff63d99733b29cee1239ba0d1e5b8e39a70aaf2f9aa5d18`.
It binds 216 served routes with aggregate
`679f7161b3bf77cd32fe767b2eb977b32d3cd1d47cc1b95fd7ddd0baeb9c9d7e`.
All seven source graphs retained 203 modules. At that candidate checkpoint,
the full 35-gate matrix and both canonical sampler orders were not executed.
These historical diagnostics are distinct from the approved-profile verification.

The candidate's focused Python diagnostic passed 58/58: native18, shader20 and sampler20.
Its report is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-sampler-structural-diagnostic-20260912155802.xml`,
SHA256 `ce53012550acc3d1ff889444be8a49870fdff770d154707d65fc77ddfc1b9b23`.
Thirteen exact source/test files retained identical before/after hashes.
The candidate Broker's normalized SHA256 is
`55cbe24abf04aedc1bdd704d2ef187cdeb11903c337ea44a7ac6d2c901eb735a`;
Core, Adapter and the ordinary fixture are unchanged. The original authority83
and frozen wires remained unchanged. No full 40-file/645-check run was performed
at that historical candidate checkpoint.
The counts describe diagnostics; they cannot overrule failed native comparisons.

The same focused commands exercise the selected native-compatible profile from
the repository root; they no longer select the historical standard candidate:

```powershell
python -B tests/virtual-realm/run_protected_startup_browser.py ordinary native-gap descriptor-gap shader-profile shader-native sampler-profile sampler-native
$env:PYTEST_DISABLE_PLUGIN_AUTOLOAD='1'
python -B -m pytest --noconftest -p no:cacheprovider -q --tb=line tests/virtual-realm/test_m2db4h_gpu_native_work_view.py tests/virtual-realm/test_m2db4h_gpu_shader_descriptor_profile.py tests/virtual-realm/test_m2db4h_gpu_sampler_descriptor.py
```

The retained historical receipt records two failures; it is not overwritten
or reclassified by a passing run against newer native-compatible source.
An earlier candidate run reached 82/83 profile and 6/8 native results, then
timed out during isolated Chrome process cleanup and produced no final receipt.
It is not accepted evidence. The final seven-gate run closed successfully and
retains the failures durably. No broader cleanup, First Shard scan, full OS
bundle or repository-wide docs/API/SPDX generator was run. Curated headings,
links, exact ledger rows and source hygiene were checked without broad discovery.

###### Approved sampler verification checkpoint

The approved numerical change fixes the two strict native differences; the
native comparisons were not removed or relabeled as observations. The focused
seven-source-gate run passed239/239: existing143, sampler-profile88 and
sampler-native8, with zero skipped cases, browser errors or denied requests.
Its receipt is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-a1kuvbcq.json`,
SHA256 `8e2821036c9cda33d69ea15de59cfb5f6240594535f10f39cad9919511fabf0c`.

A subsequent test strengthening makes boxed and coerced anisotropy values
observable through nearest-filter native validation diagnostics. In particular,
native3 versus4 cannot hide behind two successful linear-filter creations.
The final hardened native8/8 receipt is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-_cs9_bkt.json`,
SHA256 `ecec6c9b5efb0eb4c96623b021ce08281bbdd028bfaa27b139138518ce9b2883`.
It also has zero skipped cases, browser errors or denied requests. These eight
are a repeated strengthened gate, not eight additional unique cases. Direct and
coerced float vectors cover both inclusive endpoints, just-outside values that
would round back to finite float32, and early rejection before later fields.

The exact40-file Python run completed644/645, with no errors or skips. Its sole
failure was an old structural test counting every `}, true);` occurrence across
the shared browser test file, including three unrelated sampler helper calls.
The correction counts the exact two original native test registrations, pins
their names and registration endings, and preserves native2 browser counts.
The affected ordinary20/native18/shader20/sampler20 group then passed78/78.
This is composite regression evidence, not a claim of a single green645 run.
The original failed report remains
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-sampler-compatible-full-20260912161655.xml`,
SHA256 `f21582bf00b7f3b28c9632150d8e855b4385d6c7b33309670f40f8bf278c3d74`.
Its50 exact before/after source/test hashes were unchanged. The corrected
companion report is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-sampler-compatible-affected-20260912163439.xml`,
SHA256 `7fc636af00d007c0a64eadf9de063d83f3dc5518c3ca3dfed919ef93bceb72d4`.
It records78 tests and zero failures/errors/skips. Separately, all50 before/after
raw file hashes remained unchanged; its elapsed619.030s includes the host/tool
stall. The ordinary
Python test's final raw SHA256 is
`d48cf8ef80b47694487349f14f0401d5184c80c63018026b04234766e4c7d0a9`.

Current Broker normalized SHA256 is
`ca10ed5bb5da21758d59d16e4a4ae56271d0ff5789d9ad5219ac8350cd851aaf`
(raw `962ade8ae7705cabae72fb2f638eac4dc9126a9bf359bfe38f6c5ce91982b880`).
The final ordinary browser test is
`737a5f7397f287d145e7ff6c4f18e7a001511ee749baa867436681ee8036bd33`.
Core, Adapter and the original fixture retain their previous accepted bytes.
Root independently matched these five files to the hardened native receipt.
Authority83, Entry155, B3114, wrapper115 and the exact four-member/five-edge
authority component remain unchanged; no public wire or production import grew.

The first full35 browser attempt completed exact graph preflight,
but its generation gate's browser-control evaluation hit the existing15s
transport timeout before publishing a terminal receipt. A serialized generation
retry had the same interruption. Neither attempt is a pass or a failing assertion
on the32 generation cases. No full1175 result or canonical sampler-order result
is claimed from those interrupted attempts. A separate host-wide tool stall also delayed simple file
reads and the Python companion. Existing production and runner limits were not
changed to make a timeout look like acceptance.

A one-off diagnostic with a60s socket allowance and the unchanged90s polling
deadline then passed the actual generation32/32 in21.000s. A browser-control
evaluation took19.891s, exceeding the original15s connection allowance without
failing the test assertions. Its receipt is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-72o5pyk4.json`,
SHA256 `3f3a18053eaad18db07eb0f1ac0c07b0fe262b4dc079d6fc592001ef115bf14f`.
No skipped cases, browser errors, denied requests or cleanup failure occurred.
This justified one full35 retry using the same explicitly recorded transient
test-transport override. The runner source and all production/browser-test bytes
remained unchanged. This diagnostic is not itself the full matrix or a new
application compatibility policy.

**Final bounded acceptance:** that full35 retry passed1175/1175 executions on
Chrome151.0.7922.174. Sampler-profile88 and genuine-native8 pass in source and
both canonical import orders, alongside the preserved shader and original-work
gates. All gates have terminal receipts; there are zero failures, skips,
unexpected browser errors or denied requests. The18 canonical gates each retain
exactly the reviewed `[PE] missing module: engine/core/gpu/VirtualGPU.js`
diagnostic; its excluded source was not read or served. The receipt is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-xtudx91z.json`,
SHA256 `16d427db59e1ddf935d55eb5cf7d00c23b3289cc100803799e03c181f178a303`.
It binds281 served routes; served-content aggregate SHA256 is
`ae10cd26aa89e5b7a94bd098a0f87a08e3c6cea847b921f6e388c0a2fa026d71`.
Sampler source graphs retain203 modules and canonical graphs202, with no new
production import or authority-closure amendment.

Every final gate records the transient60s socket allowance and unchanged90s
polling deadline. The longest gate completed in48.609s. This is measured test
timing, not a performance guarantee or a persistent runner change. Cleanup
completed successfully. All six bound production/test/runner files retained
identical before/after hashes; the five served production/test files also match
the final receipt's normalized hashes. Root independently verified the final
counts, timing policy, expected diagnostics and five current served bindings.
Python evidence remains the preserved644/645 run plus the corrected78/78
companion, not a rewritten all-green645 receipt. Historical failed and
interrupted receipts are not reclassified by this acceptance.

The following exact PowerShell invocation records the transient connection
allowance, per-gate timings and before/after source hashes without editing the
runner. Its explicit35 selections perform no directory discovery. The90s value
is the existing between-polls deadline, not a new hard execution-time guarantee.
Interrupted runs remain non-acceptance; only complete strict receipts count.

```powershell
$vrFullTransportDiagnostic = @'
import sys,time,json,hashlib
sys.path.insert(0,'tests/virtual-realm')
import run_protected_startup_browser as r
original_init=r.Cdp.__init__
original_call=r.Cdp.call
original_run_gate=r.run_gate

def diagnostic_init(self,url):
 original_init(self,url)
 self.socket.settimeout(60)

def diagnostic_call(self,method,params=None):
 began=time.monotonic()
 try:
  result=original_call(self,method,params)
  elapsed=time.monotonic()-began
  if elapsed>=1:
   print(json.dumps({'diagnosticCall':method,'elapsedSeconds':round(elapsed,3),'status':'returned'}),flush=True)
  return result
 except Exception as error:
  events=[]
  for event in self.events[-30:]:
   item={'method':event.get('method')};data=event.get('params',{})
   if event.get('method')=='Runtime.consoleAPICalled':item.update(type=data.get('type'),arguments=[x.get('value',x.get('description',x.get('className'))) for x in data.get('args',[])])
   elif event.get('method')=='Runtime.exceptionThrown':item['details']=data.get('exceptionDetails')
   elif event.get('method')=='Log.entryAdded':item['entry']=data.get('entry')
   events.append(item)
  print(json.dumps({'diagnosticCall':method,'elapsedSeconds':round(time.monotonic()-began,3),'status':'raised','error':repr(error),'capturedEventCount':len(self.events),'events':events}),flush=True)
  raise

def diagnostic_gate(*args,**kwargs):
 began=time.monotonic()
 try:
  result=original_run_gate(*args,**kwargs)
  timing={'elapsedSeconds':round(time.monotonic()-began,3),'unchangedPollingDeadlineSeconds':90,'transientTransportTimeoutSeconds':60,'terminalReceiptArrived':True}
  result['diagnosticTransport']=timing
  print(json.dumps({'diagnosticGate':args[3],**timing,'passed':result['passed']}),flush=True)
  return result
 except Exception:
  print(json.dumps({'diagnosticGate':args[3],'elapsedSeconds':round(time.monotonic()-began,3),'unchangedPollingDeadlineSeconds':90,'transientTransportTimeoutSeconds':60,'terminalReceiptArrived':False}),flush=True)
  raise
r.Cdp.__init__=diagnostic_init
r.Cdp.call=diagnostic_call
r.run_gate=diagnostic_gate
paths=[r.CORE,r.ADAPTER,'webgpu-os/kernel/GpuDeviceBroker.js','tests/virtual-realm/m2-gpu-presenter-ordinary-work.test.js','tests/virtual-realm/m2-gpu-presenter-ordinary-work.fixture.js','tests/virtual-realm/run_protected_startup_browser.py']
def bindings(stage):
 for path in paths:
  raw=(r.ROOT/path).read_bytes();print(json.dumps({'sourceStage':stage,'source':path,'rawSha256':hashlib.sha256(raw).hexdigest(),'normalizedSha256':hashlib.sha256(raw.decode('utf-8').replace('\r\n','\n').encode()).hexdigest()}),flush=True)
bindings('before')
sys.argv=['full-matrix-transient-transport']+'''generation stable owned prebind host protected terminal ordinary native-gap descriptor-gap shader-profile shader-native sampler-profile sampler-native cohort-terminal presenter-first controller-first bundle-presenter-first bundle-controller-first bundle-terminal-presenter-first bundle-terminal-controller-first bundle-ordinary-presenter-first bundle-ordinary-controller-first bundle-native-gap-presenter-first bundle-native-gap-controller-first bundle-descriptor-presenter-first bundle-descriptor-controller-first bundle-shader-profile-presenter-first bundle-shader-profile-controller-first bundle-shader-native-presenter-first bundle-shader-native-controller-first bundle-sampler-profile-presenter-first bundle-sampler-profile-controller-first bundle-sampler-native-presenter-first bundle-sampler-native-controller-first'''.split()
try: status=r.main()
finally: bindings('after')
raise SystemExit(status)
'@
python -B -c $vrFullTransportDiagnostic
```

With this bounded sampler profile accepted, the next slice is the
[binding-layout conversion review](#protected-binding-layout-conversion-review).
Any new sequence quota, extension rule or compatibility restriction requires its
own decision. Native-return/thenable handling, raw resource children, mapped
memory, authenticated frame readiness, full-provider activation and recovery,
and M1C-to-first-submitted-visible-city integration remain separate and unaccepted.
First Shard, RealmForge authoring paths and AI Echo ownership remain untouched.

Sources: `webgpu-os/kernel/GpuDeviceBroker.js`, shared private conversion helpers,
`snapshotProtectedSamplerDescriptor()` and `createWorkView()`;
`tests/virtual-realm/m2-gpu-presenter-ordinary-work.test.js`.

##### Protected binding-layout conversion review

Status on2026-09-12: the user approved the complete profile by replying CONTINUE
to the explicit three-part approval request. The protected snapshot is now
implemented and accepted after the complete bounded verification below. This remains the caller-input
slice inside existing flat piece9, not a new milestone. The diagnostic checkpoint
records the preceding read-only review, when no production or permanent test
changes were made. A passing sampler regression alone does not close this gap.

Before this implementation, the protected WorkView forwarded caller arguments from
`createBindGroupLayout()` through `forwardDeviceOperation()` and
`callNativeMethod()`. Its checks surround the native call, but the browser can
run descriptor getters, iterator callbacks and scalar coercions inside that
call. Revocation then prevents immediate publication without preventing the
layout's native creation. Source: `webgpu-os/kernel/GpuDeviceBroker.js`,
`createWorkView()`; the original shared facade is a separate policy path.

###### Binding-layout diagnostic checkpoint

The isolated Chrome151.0.7922.174 diagnostic uses both a genuine rooted Realm
route and a genuine generic WorkView. Each row below was exercised once per
route with a current positive twin and a revoking twin. All eight current
twins passed. All eight revoking twins **failed** their strict zero-native-effect
assertion; these failures are not converted into passing security tests.

| Revocation observation | Reached per hostile case | Native call entries | Genuine native layouts created | Immediate publications |
| --- | --- | --- | --- | --- |
| Descriptor `label` getter | 1 | 1 | 1 | 0 |
| Descriptor `entries` getter | 1 | 1 | 1 | 0 |
| Entries `Symbol.iterator` getter | 1 | 1 | 1 | 0 |
| Nested buffer `minBindingSize` getter | 1 | 1 | 1 | 0 |

Every hostile layout had null validation error and genuine `GPUBindGroupLayout`
evidence. Generic twins retained the exact original denial sentinel; rooted
twins retained `VR_M2DB4H_GPU_PROTECTED_ALLOCATION_ROUTE_REQUIRED`. Independent
teardown passed. These witnesses measure creation, not physical GPU quiescence.

| Diagnostic receipt | Result | Served routes and content aggregate |
| --- | --- | --- |
| `C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-3p1r32ax.json` | Sampler88/88, sampler-native8/8, BGL12/20; overall108/116, eight strict failures, eight corresponding assertion console errors, zero skips/denied requests | 208; `a465faefa8fd1f7368438e167057d682a5fca46b7ec8a92327b3bfa83066554c` |
| `C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-5e1d_2m_.json` | Five native observation groups5/5, zero errors/skips/denied requests; not a fixed protected boundary | 204; `fc33112fec1d6597d1328955494d7372aec52c2e052249b992f139745f978ad6` |

Receipt SHA256 values are respectively
`5e0ac22db4488fb9f181e920448ec69af3f3793106a5ddaa25003e5cf57ef30f`
and `e9f96ca956d7fe1fb9f5724a735ce89eb4b9cb724f885b2fb9d38ecb469e4c8b`.
Root independently checked receipt hashes, counts, failed-case evidence and
current source bindings. The first run exited1; the follow-up exited0. Neither
receipt supersedes the previous1175/1175 sampler acceptance matrix.

The diagnostic used the existing explicit203-module source preflight and only
already-allowed routes. After preflight, the wrapper replaced the ordinary
test and main module's served bytes in memory, appending a private diagnostic
registration. Production and fixture bytes were not replaced. First selectors
were `sampler-profile sampler-native ordinary`; the transient ordinary gate was
named `bind-group-layout-diagnostic` with20 cases. Follow-up used only `ordinary`
with five native observation groups. No route or source inventory was expanded.

Both invocations used the already-measured transient60s connection allowance
and unchanged90s polling deadline, with unchanged browser flags. First gate
times were38.969s,6.203s and9.047s; follow-up was3.234s. Both completed normal
browser/profile/server cleanup. The Python wrapper and injected JavaScript
existed only in command memory/tool-call history; **no standalone rerunnable
diagnostic source file was saved**. Receipts retain results and served-byte
hashes, not the complete injected source. A future acceptance run must first
add durable, reviewed tests and exact runner bindings. Calling the unchanged
ordinary selector alone does not reproduce these temporary diagnostics.

###### Binding-layout conversion map

The descriptor inherits `label` (USVString, default empty), then requires
`entries` (a sequence of entry dictionaries). Standard dictionary processing
finishes each member conversion before reading the next. Unknown keys are not
enumerated. See [descriptor IDL](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/modules/webgpu/gpu_bind_group_layout_descriptor.idl)
and [WebIDL dictionary ordering](https://webidl.spec.whatwg.org/#es-dictionary).

| Entry order | Field | Conversion or presence |
| --- | --- | --- |
| 1 | `binding` | Required EnforceRange uint32 |
| Approved extra read | `bindingArraySize` | Explicit policy below; not a standard member |
| 2 | `buffer` | Optional buffer-layout dictionary |
| 3 | `externalTexture` | Optional empty external-texture dictionary |
| 4 | `sampler` | Optional sampler-layout dictionary |
| 5 | `storageTexture` | Optional storage-texture dictionary |
| 6 | `texture` | Optional texture-layout dictionary |
| 7 | `visibility` | Required EnforceRange uint32 flags |

The experimental member is runtime-gated in the exact
[Chromium entry IDL](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/modules/webgpu/gpu_bind_group_layout_entry.idl).
It was not read by the tested default device, whose adapter did not report
the binding-array feature. That observation is not evidence about an
experimental-feature-enabled browser or device.

| Nested dictionary | Complete lexical member order | Enum values |
| --- | --- | --- |
| [Buffer](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/modules/webgpu/gpu_buffer_binding_layout.idl) | `hasDynamicOffset=false`; `minBindingSize=0`; `type="uniform"` | Type: uniform, storage, read-only-storage |
| [External texture](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/modules/webgpu/gpu_external_texture_binding_layout.idl) | No members | None |
| [Sampler](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/modules/webgpu/gpu_sampler_binding_layout.idl) | `type="filtering"` | Type: filtering, non-filtering, comparison |
| [Storage texture](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/modules/webgpu/gpu_storage_texture_binding_layout.idl) | `access="write-only"`; required `format`; `viewDimension="2d"` | Access: write-only, read-only, read-write; complete texture-format enum; view dimension below |
| [Texture](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/modules/webgpu/gpu_texture_binding_layout.idl) | `multisampled=false`; `sampleType="float"`; `viewDimension="2d"` | Sample type: float, unfilterable-float, depth, sint, uint; view dimension below |

View dimensions are exactly `1d`, `2d`, `2d-array`, `cube`, `cube-array`, `3d`.
The format conversion catalog is all101 current `GPUTextureFormat` values,
not merely storage-capable formats. It includes the six16-bit normalized
formats despite the stale non-standard comment in Chromium's catalog.
Independent comparison found the current GPUWeb and reviewed Chromium enum
sets identical. Sources: [view dimensions](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/modules/webgpu/gpu_texture_view_descriptor.idl),
[complete format enum](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/modules/webgpu/gpu_texture_descriptor.idl).

Conversion must accept inherited members and callable dictionary objects;
`undefined` optional sub-layouts remain absent, while `null` supplies an empty
dictionary. Empty buffer/sampler/texture dictionaries receive defaults;
storage texture still lacks required `format`. Other primitives reject.
Do not substitute plain-record validation or prototype/constructor inspection.
Preserve actual HTMLAllCollection object behavior despite its unusual `typeof`.
For required descriptor/entry members, missing or undefined values reject.
No error-message wording parity is claimed by this approved host profile.

For numeric fields, guarded number-hint primitive conversion precedes ToNumber,
nonfinite rejection, truncation toward zero and range enforcement. BigInt and
Symbol reject; `-0.5` becomes zero. `binding` and `visibility` allow integers
through4294967295; `minBindingSize` allows through9007199254740991. Boolean
members use ToBoolean without coercion callbacks, including false
`document.all`. Sources: [WebIDL integer conversion](https://webidl.spec.whatwg.org/#abstract-opdef-converttoint),
[Chromium numeric conversion](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/bindings/core/v8/v8_binding_for_core.cc),
[WebGPU numeric typedefs](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/modules/webgpu/gpu.idl).

All present sub-layouts must finish conversion even when their combination is
semantically invalid. Duplicate bindings, incompatible sub-layout combinations,
visibility bits, device limits, sample-type compatibility and format usage
remain native validation. Format feature checking can throw a synchronous
TypeError before creation; tests must not assume every semantic rejection is
an asynchronous GPUValidationError. Source:
[native binding-layout conversion and creation](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/modules/webgpu/gpu_bind_group_layout.cc).

###### Approved binding-layout profile decision

The approved policy is **bounded standard-sequence conversion**, not universal
installed-native equivalence. It changes only the protected WorkView path;
the original shared facade retains native forwarding. No browser admission
rule, UA switch, native allocation probe or public profile selector is proposed.

| Decision | Approved protected behavior | Compatibility consequence |
| --- | --- | --- |
| Sequence protocol | Use the WebIDL iterator algorithm for every input, including actual Arrays | Honor `Symbol.iterator`; read `done` before `value`; skip terminal `value`. Installed Chromium does not do this in all cases. |
| Conversion-work bound | At most4096 fully converted entries, plus one completion probe | A new host limit, unrelated to shader approval or device binding limits; an otherwise convertible longer sequence rejects. |
| Experimental member | One guarded inherited `bindingArraySize` read after `binding`, before `buffer`; reject every nonundefined value without coercing it; omit it from the snapshot | Even an undefined getter is newly observable on the tested browser. Other unknown keys remain unread. |
| Label | Full USVString conversion with no added label quota | Preserves the sampler-style unbounded label policy; does not bound text memory/time. |

Native diagnostics confirmed that actual Arrays bypass custom `Symbol.iterator`,
but Proxy Arrays and ordinary iterables use it. Both an actual Array and its
Proxy satisfy `Array.isArray`, so that predicate cannot reproduce the native
selection. Native array conversion also observes inherited indices and changing
length; sparse entries fail conversion. Generic native iteration reads `value`
before `done`, including terminal steps; a throwing terminal `value` prevented
the `done` read. These are observable results, not hypothetical differences.
Sources: [Chromium sequence conversion](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/bindings/core/v8/native_value_traits_impl.h),
[Chromium iterator implementation](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/bindings/core/v8/script_iterator.cc),
and the two diagnostic receipts above.

Standard sequence conversion captures the iterator method and `next`, then
reads each step's `done` before its nonterminal `value`. It does not invoke
IteratorClose for entry conversion failure. See
[WebIDL sequence conversion](https://webidl.spec.whatwg.org/#create-sequence-from-iterable).
The approved host loop additionally rejects overflow after observing the
4097th non-done step but **before** its value or entry-member reads. Exactly4096
entries followed by completion passes conversion. It must not read or call
`iterator.return` on normal completion, conversion failure, quota rejection or
revocation. No `for...of`, spread or Array.from cleanup shortcut is acceptable.

Before and after every caller getter/call, including throwing observations,
revalidate the original WorkView restriction. A revoked original restriction
takes precedence over caller or conversion errors. Complete one entry before
requesting the next. Publish only deeply frozen project-owned null-prototype
records and an inert iterable backed by private immutable values. No live
caller record, iterator, hook or prototype may reach native conversion. Each
result produced by the private output iterator must expose fixed own
`done`/`value` data properties containing a boolean, undefined, or the
already-frozen entry snapshot; native ordering differences must not reintroduce
caller observations.

This cap does not bound a non-returning getter, `next` call, caller allocation,
nested reentry, total label length or wall time. It is not resource admission,
a device guarantee, a DoS proof or a solution for native returns. Faithful native
Array/Proxy selection has no reviewed non-observing discriminator in this JS
boundary. Prototype/constructor/instanceof heuristics and effectful native
probes are not substitutes for explicit policy approval.

###### Reuse and eight-piece build order

The exact presenter call sites use layouts with2 geometry entries,1 identity
entry and2 presentation entries: ordinary arrays, short labels and no
`bindingArraySize`. This supports those current authored callers only, not all
future app or device compatibility. Sources:
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuPresenter.js`,
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationPortContract.js`.

Production scope is only `webgpu-os/kernel/GpuDeviceBroker.js`, with no new
imports or exports. Reuse `guardedShaderObservation()`,
`protectedPrimitiveValue()`, `shaderStringValue()` with its error factory,
`normalizeProtectedUsvString()` and the inert publisher mechanics of
`freezeShaderHintSequence()`. Do not reuse `snapshotShaderHintSequence()`
unchanged: its empty default, entry shape and shader quotas are different.
Numeric factoring must preserve the accepted sampler wrapper and numerical
pins. `exactSafeInteger()` and `_requestNumber()` impose other policies and
cannot implement this conversion. `TextureMath` is size accounting, not a
complete exact format validator; its normalization must not admit wrong-case
enum strings. No existing reusable complete binding-layout snapshot was found.

1. [NEW] Add private BGL error/profile/enum constants, with the approved entry
   bound and complete101-value format catalog. Preserve fixed inert errors;
   numeric conversion failures use TypeError, the new work quota uses RangeError.
2. [MODIFY] Share guarded scalar mechanisms without changing shader or sampler
   behavior. Preserve rejection timing, primitive-hook order, error precedence,
   boolean semantics, USVString handling and uncapped label conversion.
3. [NEW] Implement the five fixed nested dictionary snapshots with complete
   defaults, absence semantics and required-field checks. Avoid reflective
   schema walkers and do not replace native GPU semantic validation.
4. [NEW] Convert each entry in the exact reviewed order, including the approved
   experimental-member read/rejection. Freeze own data fields and never retain
   caller dictionaries or coerce rejected extension values.
5. [NEW] Implement required sequence traversal using the selected protocol,
   per-observation restriction checks,4096 boundary and one completion probe.
   Reuse only the inert publisher mechanics; preserve old shader behavior.
6. [MODIFY] Replace only protected WorkView binding-layout forwarding. Snapshot
   before native method lookup/effect, keep the original receiver and method
   fence, and recheck before immediate publication. Preserve legacy identity.
7. [NEW/MODIFY] Add durable profile/native browser gates and one focused Python
   gate, plus narrowly affected structural assertions. Review and hash exact
   runner routes/import inventories before source and both canonical orders.
8. [MODIFY] Record independent production/test review, regressions, exact receipts
   and source hashes in these three curated plans and session memory. Keep both
   ledgers at ten rows and their piece9 rows identical; accept only this bounded
   input slice.

Observability uses fixed error codes and existing gate/authority diagnostics,
with reached/native-entry/native-effect/immediate-publication counters and
independent teardown witnesses. Do not insert caller-supplied logging between
authority proof and native effect. Capture test timing without asserting a new
production performance guarantee. If candidate gates fail, keep the slice
unaccepted and preserve the failed receipts; revert only this slice's owned
changes if needed, never unrelated dirty work or the accepted sampler profile.

###### Required acceptance evidence after approval

| Gate family | Required evidence |
| --- | --- |
| Descriptor shape | Omitted/undefined/null/primitive descriptor, required entries, inherited/function/HTMLAllCollection dictionaries, ignored extra arguments, poisoned extra-argument prototype indices, no unknown-key enumeration |
| Dictionary and scalar values | All ordered fields/defaults, absent versus null branches, required format, all enums and101 formats, wrong case/invalid strings, surrogate labels, booleans without hooks, exact uint32/safe-uint64 boundaries, fractions/negative zero/nonfinite/BigInt/Symbol, boxed/cross-realm/fallback coercions |
| Protocol and quota | Empty/one/4095/4096/4097 entries, infinite productive iterator, single captured iterator/next, done-first and skipped terminal value, exact overflow read boundary, malformed iterator/results, sparse/inherited/growing/shrinking Arrays, Proxy/custom iterators, no return reads/calls |
| Revocation | Current and hostile twins at every reachable member, iterator and primitive-hook get/call, including thrown observations and reentry; both genuine rooted and generic paths; reached1, native effect0, publication0 and exact denial precedence after revocation |
| Native boundary | Original native method getter/call fences, exact receiver, inert recursive snapshot, caller mutation during native lookup cannot change converted data, shared-facade descriptor identity remains unchanged; native validation and synchronous feature rejection preserved |
| Differential behavior | Strict native equality for the common conversion subset; separate explicit assertions for approved Array/iterator/terminal-value/extension/quota differences. Never relabel all profiles as native equivalent. |
| Teardown and regressions | Independent original-root cleanup after every case; existing shader/sampler/native/ordinary/cohort-terminal tests; source and both canonical import orders; measured explicit test inventories, no First Shard discovery |

The four affected structural suites are
`tests/virtual-realm/test_m2db4h_gpu_sampler_descriptor.py`,
`test_m2db4h_gpu_shader_descriptor_profile.py`,
`test_m2db4h_gpu_native_work_view.py` and
`test_m2db4h_gpu_presenter_ordinary_work.py` in that same directory. Sampler
source sections currently terminate at `originalResourceError`; inserting BGL
helpers before it requires narrowing those endpoints, not weakening forbidden
operations or exact field counts. Sharing the inert publisher must preserve
shader quota/protocol pins. Native WorkView8 stays8. Keep the two historical
native registrations exact, and scope any brittle global `checkedDenial` count
to its actual registration region rather than unrelated new tests. New test
imports require measured explicit wider test inventories, not authority growth.

No new full35-browser or full40-file Python sweep was run for the preceding
documentation-only review. Its historical Broker raw SHA256 was
`962ade8ae7705cabae72fb2f638eac4dc9126a9bf359bfe38f6c5ce91982b880`
(normalized `ca10ed5bb5da21758d59d16e4a4ae56271d0ff5789d9ad5219ac8350cd851aaf`).
At that review checkpoint, Core, Adapter, browser test, fixture and runner retained
the accepted sampler hashes. Frozen v1/v2/v3, v4lease6/dependency16/start9,
Source1/Token4/Core3/Control5/WorkSource6/WorkView8/Queue3, authority83 and its
four-member/five-edge cycle, Entry155/B3114/wrapper115 remain unchanged.

The subsequent user approval resolves the sequence protocol,4096-entry conversion
cap and experimental-member policy decisions. The implementation checkpoint
below records the new work and its complete bounded verification.
Full provider, activation, telemetry, recovery, other native argument/command families,
native returns/thenables, raw children/mapped memory, physical quiescence and
the actual M1C-to-first-submitted-visible-city route remain separate and open.
First Shard was not scanned. RealmForge authoring and AI Echo ownership remain
untouched; global discovery/doc/API/SPDX generators and full OS builds remain
excluded from this bounded work.

###### Approved binding-layout implementation checkpoint

The accepted implementation is in `webgpu-os/kernel/GpuDeviceBroker.js`.
Its single protected `createBindGroupLayout` route now converts a formal
descriptor argument before native method lookup. Thirteen private helpers were
added: shared `protectedNumberValue()`, the binding-layout error/dictionary/
integer/enum helpers, five nested dictionary snapshots, entry and sequence
snapshots, and the top-level descriptor snapshot. `samplerNumberValue()` now
delegates to the same guarded numeric primitive conversion without changing
the accepted sampler's numeric profile. No production import, export, cache,
public field, authority grant or original shared-facade forwarding policy changed.

The profile uses a frozen null-prototype101-format catalog, pinned truncation,
post-truncation uint32/safe-uint64 bounds and positive-zero normalization.
Undefined optional layouts remain absent; null layouts receive dictionary
defaults. It completes all present nested layouts before native validation.
Every Broker-issued caller get/call is guarded; the frozen snapshot contains
no live caller dictionary or iterator. The existing inert sequence publisher
is reused unchanged. No `iterator.return`, feature query, GPU effect probe or
added label quota was introduced.

This guarantee does not interrupt execution *inside* an arbitrary getter,
iterator call or coercion callback. For example, a native ArrayIterator `next`
may internally read both Proxy length and index before returning. The Broker
checks its original restriction when that call returns and does not issue the
next observation or native layout creation after revocation. This is not a
wall-time, callback-preemption or reentry-isolation claim.

Independent production review found no actionable counterexample in candidate
Broker SHA256 `cd7937f3fe4436c228c3a71d7a83f7b1bf7454c2e5acff44120cdf6920f80747`.
The reviewer independently compared its catalog against exact Chromium IDL:
101 entries,101 unique,101 expected, zero differences. The following durable
gates provide execution evidence separately from that source review.

###### Durable binding-layout verification

The new profile gate registers exactly126 cases and the native gate27. Their
separate source entries and both canonical import orders use the existing
allowlisted runner:203 modules per source graph and202 per canonical graph.
The existing ordinary90, native2, descriptor2, shader42/native7 and sampler88/
native8 registrations are unchanged. Profile tests distinguish instrumented
conversion sinks from actual GPU effects. Native tests require genuine GPU
objects and real rooted/generic mounts; unavailable prerequisites do not skip.

The strict revocation witnesses count reached callbacks, later forbidden
observations, native method entry, actual native layout creation and immediate
publication separately. The native numeric witness also proves an exact
minimum binding size of8: size7 rejects, while a separate min7/size7 control
passes. A frozen snapshot assertion pins binding1/minimum8 before native use.
Poisoned inherited array indices,4096-entry completion, overflow before the
4097th value, untouched iterator return hooks, sibling raw-facade identity and
independent cleanup all have explicit checks. Independent final test-source
review found no remaining actionable counterexample at browser-test SHA256
`589e5150ebd0fe89a2d7c4ea7d2d21ac7d76becf84f89e62d6c72340ee7ab23a`.

The first implementation receipt remains a failed run: profile125/126 plus
native27/27, one assertion error, zero skips/denied requests. Its raw-facade
test expected a ledger increment that the retained fixture's native layout
method never records. The correction asserts two distinct returned records
with the exact original descriptor before/after protected stop, while keeping
the protected effect/publication and no-cache assertions. This was not a
teardown reset and required no production change. Receipt:
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-u52g9gtp.json`,
SHA256 `69829d62f881534b9238ca1173f83b36d944e4a417fb9cc33c98bf1b6cd3f76f`.
An early structural test also incorrectly matched `set ` within
`hasDynamicOffset`; its accessor prohibition was narrowed to actual getter/
setter syntax, not removed. Neither historical failure is relabeled as green.

After those test-only corrections and stronger native numeric controls,
focused browser9 passed392/392 with zero errors, failures, skips or denied
requests. Receipt:
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-gj0d7bso.json`,
SHA256 `e944070137864c3aceb41791071512dfc853234d578f5e15a3606f88ccb6d240`.
Its220 served routes have content aggregate
`7d9cf5493bbbdc772654dfff59c46f236e18042192708891808c85bbda5a3107`.
Focused ordinary20/native18/shader20/sampler20/binding24 Python checks passed
102/102 in49.910s, with zero failures/errors/skips and55 before/after-bound files
unchanged. JUnit:
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-binding-layout-focused-20260912141034.xml`,
SHA256 `ce54f39ec54e66abf7fb00e2cdd1afbc27bc1477e044c651e49460ff257cb473`.
The fresh literal41-file Python run passed669/669 in264.003s, with zero
failures/errors/skips. JUnit:
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-binding-layout-full-20260912141819.xml`,
SHA256 `2539a6d14b0989f3d717c79be4e4cc082eaace4f849eaea72019d75095ddc5b7`.
All55 recorded source/test files remained byte-identical before/after the run.
Root independently checked those hashes against the current files and matched
the JUnit classes, in order, to the exact41 selected paths. Combined evidence:
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-binding-layout-full-20260912141819-bindings.json`,
SHA256 `f504bf305da8e1fcec920424ecfa990af96c4ddd2dc56a65d65301cb01102e0c`.
Its exact invocation and omitted runner options are documented below. This is
a fresh green run, unlike the historical sampler's composite Python evidence;
it does not rewrite that history.

The complete41-selection browser run passed1634/1634 on
Chrome151.0.7922.174, with zero failed/skipped cases, unexpected browser errors
or denied requests. All35 previous selections passed. The126-case profile and
27-case native gate each passed in source and both canonical import orders.
Receipt:
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-zr7xfpr4.json`,
SHA256 `f0679f29b24d9d3cc3b01b599882897fb7ae4e744831caae979257fc1d8e0ac2`.
It binds all293 served routes. Each of the22 canonical pages emitted exactly
its expected `[PE] missing module: engine/core/gpu/VirtualGPU.js` diagnostic;
that excluded source was not served or read. Those expected diagnostics are
not hidden failures or evidence of a complete OS bundle. The startup content
aggregate was lost from the retained truncated output; no aggregate is invented
or substituted with a digest of the hash map. The receipt retains each route's
actual normalized-content hash.

The longest gate completed in64.156s under the recorded transport policy.
Root independently verified counts, all22 diagnostic texts, every gate's
terminal/timing policy, nine current served-source bindings and all55 recorded
Python source/test hashes. The24 native revocation executions across the three
native variants retain reached callbacks and zero subsequent native entry,
creation or publication. No source change occurred during final verification.

Final Broker raw SHA256 is
`cd7937f3fe4436c228c3a71d7a83f7b1bf7454c2e5acff44120cdf6920f80747`,
normalized `e1faf377e062ec4d546a714d7e84c04a88dd99abb37c742c5fd63e4927987a12`.
Browser test raw/normalized SHA256 is
`589e5150ebd0fe89a2d7c4ea7d2d21ac7d76becf84f89e62d6c72340ee7ab23a`;
runner raw/normalized SHA256 is
`97d14f31bb6519964c5c75f9938152bb10c5db9daf2dbc0bef4306ff01607249`.
The complete55-file binding artifact above records the other exact hashes.

This accepts only the approved binding-layout input snapshot inside flat
piece9. It does not accept the full provider, M2D-B4H as a whole, other native
arguments/commands, return/thenable handling, raw children/mapped memory,
physical quiescence, or the actual M1C-to-first-submitted-visible-city path.
The next bounded continuation is a read-only review of the existing
`createPipelineLayout` sequence, opaque-leaf and versioned-field boundary.
Do not infer a new conversion quota, extension policy or authority from this
acceptance. RealmForge/AI Echo ownership and First Shard exclusion remain intact.

The transient diagnostic wrapper sets a60s **per-receive socket timeout**, not
a60s whole-call or wall-clock execution limit. The unchanged90s deadline is
checked between polls. The focused profile completed in65.203s; its
`Runtime.evaluate` took64.438s while receives continued. The earlier failed
profile run similarly returned after76.094s in that call. This is recorded
transport behavior, not weakened browser assertions, a production timeout
change, callback preemption or a browser admission rule.

The exact full41 browser invocation below is retained independently of temporary
files. It uses the unchanged flags, allowlists, assertions and expected counts;
only the transient transport wrapper is applied. The saved command artifact is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-binding-layout-full41-589e5150.ps1`,
SHA256 `4177119fb0c0d0096e02ac4005dd0e2563f3b64a3c2cb4bbb4b75af8100656f8`.
Unlike the historical35-selection sampler invocation, this one includes all six
binding-layout selectors. It records six exact before/after source bindings;
the browser receipt separately binds every served route.

```powershell
Set-Location -LiteralPath C:/Coding/game
$vrBindingLayoutTransport = @'
import sys,time,json,hashlib
sys.path.insert(0,'tests/virtual-realm')
import run_protected_startup_browser as r
original_init=r.Cdp.__init__
original_call=r.Cdp.call
original_run_gate=r.run_gate
def diagnostic_init(self,url):
 original_init(self,url)
 self.socket.settimeout(60)
def diagnostic_call(self,method,params=None):
 began=time.monotonic()
 try:
  result=original_call(self,method,params)
  elapsed=time.monotonic()-began
  if elapsed>=1:
   print(json.dumps({'diagnosticCall':method,'elapsedSeconds':round(elapsed,3),'status':'returned'}),flush=True)
  return result
 except Exception as error:
  events=[]
  for event in self.events[-30:]:
   item={'method':event.get('method')};data=event.get('params',{})
   if event.get('method')=='Runtime.consoleAPICalled':item.update(type=data.get('type'),arguments=[x.get('value',x.get('description',x.get('className'))) for x in data.get('args',[])])
   elif event.get('method')=='Runtime.exceptionThrown':item['details']=data.get('exceptionDetails')
   elif event.get('method')=='Log.entryAdded':item['entry']=data.get('entry')
   events.append(item)
  print(json.dumps({'diagnosticCall':method,'elapsedSeconds':round(time.monotonic()-began,3),'status':'raised','error':repr(error),'capturedEventCount':len(self.events),'events':events}),flush=True)
  raise
def diagnostic_gate(*args,**kwargs):
 began=time.monotonic()
 try:
  result=original_run_gate(*args,**kwargs)
  timing={'elapsedSeconds':round(time.monotonic()-began,3),'unchangedPollingDeadlineSeconds':90,'transientTransportTimeoutSeconds':60,'terminalReceiptArrived':True}
  result['diagnosticTransport']=timing
  print(json.dumps({'diagnosticGate':args[3],**timing,'passed':result['passed']}),flush=True)
  return result
 except Exception:
  print(json.dumps({'diagnosticGate':args[3],'elapsedSeconds':round(time.monotonic()-began,3),'unchangedPollingDeadlineSeconds':90,'transientTransportTimeoutSeconds':60,'terminalReceiptArrived':False}),flush=True)
  raise
r.Cdp.__init__=diagnostic_init
r.Cdp.call=diagnostic_call
r.run_gate=diagnostic_gate
paths=[r.CORE,r.ADAPTER,'webgpu-os/kernel/GpuDeviceBroker.js','tests/virtual-realm/m2-gpu-presenter-ordinary-work.test.js','tests/virtual-realm/m2-gpu-presenter-ordinary-work.fixture.js','tests/virtual-realm/run_protected_startup_browser.py']
def bindings(stage):
 for path in paths:
  raw=(r.ROOT/path).read_bytes();print(json.dumps({'sourceStage':stage,'source':path,'rawSha256':hashlib.sha256(raw).hexdigest(),'normalizedSha256':hashlib.sha256(raw.decode('utf-8').replace('\r\n','\n').encode()).hexdigest()}),flush=True)
bindings('before')
sys.argv=['binding-layout-transient-transport']+'''generation stable owned prebind host protected terminal ordinary native-gap descriptor-gap shader-profile shader-native sampler-profile sampler-native cohort-terminal presenter-first controller-first bundle-presenter-first bundle-controller-first bundle-terminal-presenter-first bundle-terminal-controller-first bundle-ordinary-presenter-first bundle-ordinary-controller-first bundle-native-gap-presenter-first bundle-native-gap-controller-first bundle-descriptor-presenter-first bundle-descriptor-controller-first bundle-shader-profile-presenter-first bundle-shader-profile-controller-first bundle-shader-native-presenter-first bundle-shader-native-controller-first bundle-sampler-profile-presenter-first bundle-sampler-profile-controller-first bundle-sampler-native-presenter-first bundle-sampler-native-controller-first binding-layout-profile binding-layout-native bundle-binding-layout-profile-presenter-first bundle-binding-layout-profile-controller-first bundle-binding-layout-native-presenter-first bundle-binding-layout-native-controller-first'''.split()
try: status=r.main()
finally: bindings('after')
raise SystemExit(status)
'@
python -B -c $vrBindingLayoutTransport
```

The exact full41 Python selection is the saved39 shader gates plus the sampler
and binding-layout gates, with no directory discovery. The recorded command
artifact is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-binding-layout-full-20260912141819-command.ps1`,
SHA256 `83856e15975e5110f19ed5e627e46c27914eca912b69b7aa4795a52f04f8f182`.
It disabled plugin autoload and the cache provider, but the actual invocation
omitted the requested `--noconftest` and `--tb=line` options. Root checked the
exact possible ancestor paths (`C:/conftest.py`, `C:/Coding/conftest.py`, and
`conftest.py` at the repository root, `tests/` and `tests/virtual-realm/`): none
existed. Thus there was no ancestor conftest to load for this literal selection;
the traceback option only controls failure presentation. This is the actual
command, not a retroactively corrected account. Future runs should additionally
pass `--noconftest --tb=line` explicitly.

```powershell
# SPDX-FileCopyrightText: 2026 Jake Wehmeier (BTSpaniel) <https://github.com/BTSpaniel>
# SPDX-License-Identifier: LicenseRef-ParticleRealms-Alpha

# Exact literal selection and options used for the recorded full BGL structural run.
# Re-execution creates a fresh timestamped JUnit report; it does not reuse acceptance.
Set-Location -LiteralPath 'C:/Coding/game'
$env:PYTEST_DISABLE_PLUGIN_AUTOLOAD='1'
$vrBglGates = @(
    'tests/virtual-realm/test_m2db4h_surface_receipt_provenance.py'
    'tests/virtual-realm/test_m2db4h_runtime_lifecycle_binding.py'
    'tests/virtual-realm/test_m2db4h_runtime_host_lifecycle.py'
    'tests/virtual-realm/test_m2db4h_runtime_diagnostics_source.py'
    'tests/virtual-realm/test_m2db4h_runtime_attempt_binding.py'
    'tests/virtual-realm/test_m2db4h_process_owner_telemetry_binding.py'
    'tests/virtual-realm/test_m2db4h_process_owner_identity_authority.py'
    'tests/virtual-realm/test_m2db4h_operator_transition_drain.py'
    'tests/virtual-realm/test_m2db4h_local_selection_head_storage.py'
    'tests/virtual-realm/test_m2db4h_local_operator_snapshot_source.py'
    'tests/virtual-realm/test_m2db4h_local_operator_policy_head_storage.py'
    'tests/virtual-realm/test_m2db4h_lifecycle_session_authority.py'
    'tests/virtual-realm/test_m2db4h_lifecycle_port_composition.py'
    'tests/virtual-realm/test_m2db4h_lifecycle_participant_authority.py'
    'tests/virtual-realm/test_m2db4h_lifecycle_generation_head_storage.py'
    'tests/virtual-realm/test_m2db4h_lifecycle_composition_telemetry_source.py'
    'tests/virtual-realm/test_m2db4h_lifecycle_allocation_authority.py'
    'tests/virtual-realm/test_m2db4h_guarded_frame_telemetry_source.py'
    'tests/virtual-realm/test_m2db4h_gpu_terminal_cleanup_contract.py'
    'tests/virtual-realm/test_m2db4h_gpu_surface_allocation_source.py'
    'tests/virtual-realm/test_m2db4h_gpu_stable_allocation_source.py'
    'tests/virtual-realm/test_m2db4h_gpu_presenter_generation_source.py'
    'tests/virtual-realm/test_m2db4h_gpu_presentation_epoch_source.py'
    'tests/virtual-realm/test_m2db4h_gpu_prebind_allocation_binding.py'
    'tests/virtual-realm/test_m2db4h_gpu_owned_adapter_allocation.py'
    'tests/virtual-realm/test_m2db4h_gpu_original_resource_registry.py'
    'tests/virtual-realm/test_m2db4h_gpu_mount_allocation_source.py'
    'tests/virtual-realm/test_m2db4h_gpu_cohort_terminal_cleanup.py'
    'tests/virtual-realm/test_m2db4h_gpu_allocation_cohort.py'
    'tests/virtual-realm/test_m2db4h_frame_producer_telemetry_source.py'
    'tests/virtual-realm/test_m2db3_runtime_production_composition.py'
    'tests/virtual-realm/test_m2db2_gpu_presentation_syscall_adapter.py'
    'tests/virtual-realm/test_m2db4h_gpu_protected_startup.py'
    'tests/virtual-realm/test_m2db4h_gpu_presenter_terminal_cleanup_entry.py'
    'tests/virtual-realm/test_m2db4h_gpu_presenter_terminal_cleanup.py'
    'tests/virtual-realm/test_m2db2_gpu_presentation_port.py'
    'tests/virtual-realm/test_m2db4h_gpu_presenter_ordinary_work.py'
    'tests/virtual-realm/test_m2db4h_gpu_native_work_view.py'
    'tests/virtual-realm/test_m2db4h_gpu_shader_descriptor_profile.py'
    'tests/virtual-realm/test_m2db4h_gpu_sampler_descriptor.py'
    'tests/virtual-realm/test_m2db4h_gpu_binding_layout_descriptor.py'
)
$vrBglReport = Join-Path $env:TEMP ('virtual-realm-binding-layout-full-' + (Get-Date -Format 'yyyyMMddHHmmss') + '.xml')
Write-Output $vrBglReport
python -B -m pytest -p no:cacheprovider -q @vrBglGates --junitxml=$vrBglReport
```



##### Protected pipeline-layout conversion review

Historical review on2026-09-12 measured the live-conversion gap before approval.
The subsequent CONTINUE explicitly approves the eight-piece implementation,
standard iterator behavior, independent4096-layout cap and full immediateSize
conversion. Implementation and verification are now in progress; see
[approved pipeline-layout implementation](#approved-pipeline-layout-implementation).
The review itself did not modify production or permanent tests. The preceding1634/1634 browser and669/669
Python receipts remain historical acceptance for their exact binding-layout
source, not acceptance of pipeline-layout conversion.

`createWorkView()` still forwards live `createPipelineLayout(...args)` through
`forwardDeviceOperation()` and `callNativeMethod()`. Those helpers guard native
method lookup and publication, but the browser still performs descriptor
conversion inside the native call. This caller-input boundary permits native
creation after revocation during conversion. It is not the already-accepted native
method-getter boundary. No native-effect result is inferred solely from a
rejected caller promise. (Source: `webgpu-os/kernel/GpuDeviceBroker.js`.)

###### Pipeline-layout field and ownership map

| Input | Required conversion | Boundary retained |
| --- | --- | --- |
| `label` | Inherited member first; USVString, default empty string | Reuse uncapped label conversion; no added text quota. |
| `bindGroupLayouts` | Required nonnullable sequence, fully converted before the next field | Null/undefined sequence is invalid; this is distinct from nullable elements. |
| A layout element | Strict null/undefined becomes null; otherwise require the native `GPUBindGroupLayout` interface | Sparse holes become null slots. No string/number coercion or shader-style `auto` fallback. |
| `immediateSize` | Default0; guarded numeric conversion, finite check, truncation, uint32 range and positive-zero normalization | Device limits and four-byte alignment remain native validation, not host conversion rules. |

The current standard includes `immediateSize`; it is not merely an unknown
extension to reject. The exact Chromium151 descriptor places it behind
`WebGPUImmediatesFeature`, whose declaration is stable, and native construction
forwards the converted value. The selected profile should preserve this field;
actual installed-browser getter/coercion behavior is measured separately.
Sources: [pinned WebGPU specification](https://raw.githubusercontent.com/gpuweb/gpuweb/e0aff163a37eb3633ffd612e2a943ceb6196d6af/spec/index.bs),
[Chromium151 pipeline descriptor](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/modules/webgpu/gpu_pipeline_layout_descriptor.idl),
[Chromium151 feature declaration](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/platform/runtime_enabled_features.json5),
and [native pipeline-layout construction](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/modules/webgpu/gpu_pipeline_layout.cc).

The native object leaf needs a different converter from `shaderHintLayout()`.
That helper recognizes `GPUPipelineLayout` and can fall back to the `auto`
string union; pipeline inputs instead require nullable `GPUBindGroupLayout`.
Reuse the guarded native-probe mechanism, not that different union policy.
A trusted-bootstrap capture of the genuine BGL prototype's native label getter
can test the native interface without reading a caller's own label, prototype,
constructor or coercion hooks. Preserve the genuine object by identity.
Missing native getter support must fail when a non-null leaf needs branding;
empty/all-null sequences do not need that probe. It must not permit
an `instanceof`, property, provider or allocation-probe fallback. A native probe's
error classification must not swallow the original restriction's denial.
Sources: `webgpu-os/kernel/GpuDeviceBroker.js` (`shaderHintLayout()`);
[BGL native interface](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/modules/webgpu/gpu_bind_group_layout.idl),
[WebIDL interface conversion](https://webidl.spec.whatwg.org/#es-interface),
and [nullable conversion](https://webidl.spec.whatwg.org/#es-nullable-type).

The snapshot's records, iterable and iterator results must be inert and frozen.
Its retained GPU objects are not deeply frozen or replaced with records.
Interface branding proves neither device compatibility nor Realm ownership.
Foreign-device, invalid or exclusive-layout restrictions remain native
validation. Use a nonempty foreign layout when testing the ownership error:
empty layouts may be collapsed to null slots by the native validation algorithm.
Do not mistake `document.all` for null or undefined; it remains an object and
must satisfy the genuine interface check. Native differential tests must cover
cross-realm identity, wrong interfaces, proxies, prototype forgeries and poisoned
own properties, rather than trusting JavaScript shape alone.

###### Pipeline-layout sequence decision and reuse blueprint

The proposed sequence policy is standard traversal for every input: honor its
iterator method, capture `next` once, inspect `done` before nonterminal `value`,
and never observe `iterator.return` on completion, conversion failure, quota
rejection or revocation. The proposed independent host cap is4096 converted layout elements,
plus one completion probe; reject a non-done overflow step before its value.
Neither choice is inherited approval from the preceding binding-layout family.
This cap is a conversion policy, not `maxBindGroups`, a GPU resource quota or a
wall-time guarantee. Callbacks, nested reentry, caller allocation and uncapped
labels remain outside that bound.

Chromium's actual-Array shortcut and its generic value-before-done iteration
differ from standard traversal. `Array.isArray` cannot distinguish an actual
Array from a Proxy Array, so it cannot implement native parity. No prototype
heuristic, native-effect probe or silent policy switch is proposed. Pipeline
diagnostics must measure these differences with nullable native leaves; the
preceding BGL dictionary-entry observations are not sufficient by themselves.
Sources: [Chromium sequence/interface conversion](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/bindings/core/v8/native_value_traits_impl.h),
[Chromium iterator](https://raw.githubusercontent.com/chromium/chromium/151.0.7922.174/third_party/blink/renderer/bindings/core/v8/script_iterator.cc),
and [WebIDL sequence conversion](https://webidl.spec.whatwg.org/#create-sequence-from-iterable).

The implementation proposal has eight bounded pieces. It is not implemented or
approved by this review:

1. **[NEW] Private profile prerequisites.** Add fixed pipeline-layout errors,
   the trusted native BGL getter capture and an independently approved cap.
   Add no import, export, public field, capability or device-feature query.
2. **[MODIFY] Shared scalar conversion.** Reuse guarded primitive/string/USV
   helpers. Parameterize the existing integer converter's private error factory,
   preserving its three-argument BGL calls, codes and numeric order.
3. **[MODIFY/NEW] Native interface conversion.** Extract only the shared guarded
   brand-probe/error classification. Preserve shader's existing wrapper and
   union fallback; add the separate nullable BGL leaf policy without coercion.
4. **[MODIFY] Shared sequence mechanics.** Factor the accepted BGL loop into a
   private converter/error/limit-parameterized helper. Keep its exact field
   order, cap, errors, inert publisher and no-return behavior unchanged. Leave
   the shader's default-empty, budgeted sequence converter unchanged.
5. **[NEW] Pipeline descriptor snapshot.** Complete label, required layout
   sequence and immediateSize in order. Retain native leaves; freeze only the
   project-owned containers. Guard each Broker-issued caller observation.
6. **[MODIFY] Protected route only.** Snapshot a formal descriptor argument
   before native lookup/effect. Preserve ordinary/rootless forwarding, current
   mount proof, post-call fencing and independent terminal cleanup.
7. **[MODIFY/NEW] Durable tests.** Add genuine positive/hostile native twins,
   profile and structural gates. Fix only the old ordinary pipeline positive
   descriptor to include bindGroupLayouts:[]; preserve its90 registrations.
8. **[MODIFY] Verification and plan.** Run exact affected checks, both canonical
   orders and the documented bounded regressions. Preserve failed receipts,
   exact source bindings, independent review and both flat piece9 rows.

Existing authored calls require no redesign: the presenter's geometry, identity
and presentation pipeline layouts each supply one BGL in an ordinary array,
with a short label and no immediateSize field. The ordinary-work test helper
currently supplies only a label for this method; after conversion is added,
that positive descriptor needs the required empty layout sequence so its
existing native lookup/effect/publication checks still reach the intended
stage. (Sources: `webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuPresenter.js`
`#createPipelines()`; `tests/virtual-realm/m2-gpu-presenter-ordinary-work.test.js`
`creationDescriptor`.)

Structural assertions must follow any shared helper extraction without dropping
their original guarantees. In particular, pin BGL defaults/error codes and
shader's exact union behavior; narrow descriptor-section endpoints before new
pipeline helpers; preserve the inert publisher's fixed own result properties.
New source/native test entries may extend only explicit reviewed test inventories.
They do not grow authority83, the four-member/five-edge cycle, Entry155,
B3114/wrapper115 or WorkView8/Queue3. No Core/Adapter/fixture rewrite is proposed.
Sources: `tests/virtual-realm/test_m2db4h_gpu_binding_layout_descriptor.py`,
`test_m2db4h_gpu_shader_descriptor_profile.py`, `test_m2db4h_gpu_sampler_descriptor.py`,
`test_m2db4h_gpu_native_work_view.py`, and `run_protected_startup_browser.py`.

###### Pipeline-layout diagnostic findings and preserved interruptions

The separate 62-case source diagnostic completed with **34 passes and 28
failures**, zero skipped or blocked cases. These failures remain failures;
they are not an accepted implementation. Six native observation groups and
all 28 genuine positive twins passed. Every hostile twin reached its selected
revocation callback exactly once, entered native creation once and produced one
native pipeline object. The original denial then prevented immediate publication.
This independently demonstrates that post-call denial is too late to prevent
the native effect. Validation scopes were empty in all 56 twins.

The 14 stages are label getter, label primitive-hook getter/call, layout-sequence
getter, iterator getter/call, next getter/call, step value/done getters, actual
Array index getter, and immediateSize getter/primitive-hook getter/call. Each
has an original-rooted and a generic-cohort positive/hostile pair. Generic
denials retain exact sentinel identity; rooted denials retain the original
`VR_M2DB4H_GPU_PROTECTED_ALLOCATION_ROUTE_REQUIRED` code. All 56 witnesses
independently completed fixture resource destruction exactly once, one retirement
receipt and no abandonment log. This is not physical-quiescence evidence.
Durable post-fix tests must assert **zero native entries as well as zero native
effects and zero immediate publications** after revocation. Do not weaken the
existing effects assertion or count a rejected job as effect prevention.

Installed Chrome151.0.7922.174 observations refine the proposed profile:

- Required empty sequences work. Sparse holes, null and undefined elements
  become null slots; `document.all` fails native interface conversion.
- Inherited label conversion precedes complete sequence conversion, followed
  by the immediateSize getter and numeric coercion. Unknown extension getters
  are not observed by this native descriptor.
- An actual Array bypasses its custom iterator. A Proxy Array honors it even
  though both return true from `Array.isArray`. Growth during index conversion
  reaches an appended invalid element; shrinkage and inherited indices are
  observed. Generic iteration reads value before done, including terminal
  value; a throwing terminal value propagates without reading done or return.
- The default device exposes `maxImmediateSize:64`. Each immediateSize getter
  runs once. Values0 and4 pass;1 reaches native four-byte-alignment validation.
  Negative1, nonfinite values, uint32 overflow, BigInt and Symbol fail numeric
  conversion. Fractions, boxed fractions and numeric-hook fractions are
  accepted after truncation; uint32 maximum reaches native validation rather
  than a conversion-range error. The measured device limit is not a host cap.
- Labels replace lone surrogates, reject Symbol, stringify BigInt and honor
  fallback coercion. A throwing label hook prevents the later sequence getter.

The original 63-case diagnostic did **not** complete. Its preceding BGL source
gates passed126/126 and27/27, then observation group5 crashed the isolated
browser before any of the 56 revocation twins began. A fresh one-case isolation
also ended in `Inspector.targetCrashed`, with no terminal receipt. Its 20 saved
checkpoints show completed GPU acquisition and BGL creation, valid same-device
conversion, ordinary same-frame foreign-device validation, and a successful
retained native getter probe of the genuine cross-frame BGL. The last marker
precedes the cross-frame/other-device pipeline **attempt**, which includes scope
push, synchronous creation and awaited validation settlement. It does not
identify which of those operations crashed. No crash is relabeled as a TypeError
or an assertion failure. The 62-case selection explicitly excludes original
group5; it is not a full 63-case rerun or acceptance.

Two separately registered, fresh-page controls subsequently passed1/1 each,
with zero failures, skipped/blocked cases or browser errors. The brand-only
matrix tested ten leaf vectors without any pipeline creation. The retained
native getter accepted genuine same-device, same-frame foreign-device and
cross-frame BGL objects, while rejecting proxies, prototype forgeries, a wrong
GPU interface, plain records, HTMLAllCollection and nullish receivers. Poisoned
own label/constructor/coercion properties and proxy traps were never read.
The nullable conversion policy still handles null/undefined before branding.

The second control awaited iframe load before GPU acquisition, then used a
nonempty child-frame BGL with its own child-frame device, invoked from parent
JavaScript using a parent-realm descriptor and array. Document identity remained
stable; native creation returned the genuine labeled pipeline, the validation
promise settled with no error, and fixture cleanup completed. Its separate
scope/creation/settlement checkpoints establish usable same-owner cross-realm
objects, not support for the known-crashing cross-frame/foreign-device
combination. The load-awaited acquisition is temporary diagnostic code, not a
silent correction of the permanent fixture. Neither passing control replaces
original group5 or repairs the browser crash.

The cross-frame/foreign-device crash remains a separate browser/native
limitation. It does not justify rejecting genuine cross-realm objects using
`instanceof`, inventing a device-owner heuristic, adding an allocation probe or
claiming that native interface branding authenticates Realm ownership.

Reproduction artifacts are temporary diagnostics, not permanent test changes.
From `C:/Coding/game`, each exact wrapper is run with `python -B`:

| Artifact under `C:/Users/btspa/AppData/Local/Temp/` | Purpose and evidence |
| --- | --- |
| `virtual-realm-pipeline-layout-review-20260912-v1.py` | BGL153 baseline plus original63 diagnostic; interrupted without pipeline receipt. Uses diagnostic source `virtual-realm-pipeline-layout-diagnostic-20260912-v1.js`, SHA256 `640ca97a4fa57bddf8d474b3f2b988e22ff68550db9a603063f47ab8c61b9ef9`. |
| `virtual-realm-pipeline-layout-review-evidence-q5ngelsb/` | Preserved original injected test/main, complete served bytes and interrupted stdout. Served208 routes; content aggregate `5c1755ab8df8bf3834221ebb93f76ff5a0d0cb822dafbc39954d8f4872633398`. |
| `virtual-realm-pipeline-layout-review-20260912-v2.py` | Original group5 only, with incremental checkpoints; SHA256 `545dbda9bdfc035b77f2ae9b7b5692f4917fc7be78c2d03b8158e8e438e50b80`. Uses diagnostic source v2, SHA256 `147fedcdad8afe5661da6d2a420f4f213e5a7b01ee4a67147a248a3c3bbba873`. |
| `virtual-realm-pipeline-layout-brand-isolation-is27pjlf/interrupted-call-aem5o0ka.json` | Second crash,39 events; SHA256 `843bd58a554ef865023f5c447a8946d81556790a590a8ef05e5579b6fc1f96f4`. Adjacent `incremental-progress.ndjson` retains20 checkpoints, SHA256 `3add3dc5191776e749a3a7c5950da8c082100d8fad796953862a45c15246e37b`. |
| `virtual-realm-pipeline-layout-review-20260912-v3.py` | Explicit original IDs1–4 and6–63, assertions unchanged, source v2; SHA256 `cc69ec4c861f142f8f769945793d8460f306f71ca10d04403a7671deac28fe18`. |
| `virtual-realm-pipeline-layout-remaining-p7fzb7nw/pipeline-layout-review-remaining.terminal.json` | Final34/62,28 failed,0 skipped/blocked; SHA256 `f9bf2f06cc35b1eeed549ad264718d14ed745c2f6512719e158245735c5e5a35`. Adjacent `served-bytes.json` SHA256 `815eb7617f613a59d612764539d1463245cc8c60da793123335d46643f69d373`;204 routes, content aggregate `dd08cee8812f8695002c8144aea08ba6bf759e98fdd59e0db39be5b1cd619940`. |
| `virtual-realm-protected-startup-receipt-k2u9cnkm.json` | Complete failed62-case runner receipt,204 served hashes and zero denied requests; SHA256 `f7f504db1e9f5c62e54bb834460494ee4a57deee1f7ab73a88b3677ec21da11f`. |
| `virtual-realm-pipeline-layout-review-20260912-v4.py` | Separate brand-only and load-awaited child-owner controls; SHA256 `85b3a02a99b98596cdd3014b44e366a7a46dd846d7f1e4baaeccc7cfc77821e6`. Diagnostic source v4 SHA256 `038cf0f33d6cbb9a134bb5fab200d53bea1e75eaa1f61594a2eef9fe37b9139b`. |
| `virtual-realm-pipeline-layout-two-isolations-ll0glmnk/` | Brand-only terminal1/1, SHA256 `e468098b963659e661c313e1ef2f804e361043c80c7851749c80896196866c49`; loaded-cross-owner terminal1/1, SHA256 `973417e62b8b5b6c1e3fff70ba8d3d168dbc7cc6b1c2ee27a779d458df363f84`. Files are `pipeline-layout-brand-only.terminal.json` and `pipeline-layout-loaded-cross-owner.terminal.json`. Adjacent complete `served-bytes.json` SHA256 `03c1d401fbaff120ce79cfd1a81c4863a32280f99a9bb8a4780c1ed54de3c430`;206 routes, content aggregate `40445ecceede4548f0e224cdae1c3f1e9752e5f14208677e2441cec22eb67905`. |

Each wrapper checks six exact production/fixture/runner source hashes before
and after, and compares every pre-injection served route with the preceding
accepted binding-layout receipt. The only served edits append diagnostic source
to the existing ordinary test and replace the selected existing main registrars. Full injected
bytes and route hashes are retained for replay. Reviewed source closures remain
203 modules with zero skipped modules and no new inventory paths. The transient
60-second **per-receive** socket timeout and unchanged90-second between-poll
deadline are test transport, not runtime policy or a whole-call wall-time cap.
The completed62 gate took31.156s. Its28 browser console errors are precisely the
strict assertion failures, not ignored errors or passing evidence. The two
additional control gates took2.485s and2.437s. Their wrapper changes two existing
main registrars, not just the ordinary main. Independent source and artifact
review found no weakened assertion or source-inventory expansion. The preserved
v1/v2 crash probes are not routine acceptance reruns. To reproduce the completed
diagnostic selection without those attempts:

```powershell
python -B C:/Users/btspa/AppData/Local/Temp/virtual-realm-pipeline-layout-review-20260912-v3.py
```

This command is expected to fail the28 zero-effect assertions on the exact
unchanged source. Run v4 separately for the two controls. Temporary artifacts
must remain present; missing files require restoring the recorded exact bytes,
not treating a skipped probe as acceptance. Durable source/canonical tests are
part of the proposed implementation, not supplied by this read-only review.

This historical review accepted no pipeline snapshot or full-provider isolation.
The subsequent explicit approval and its verification are tracked separately.
First Shard,
RealmForge authoring, AI Echo ownership, global discovery/API/SPDX generation
and full OS builds remain excluded from this review.

##### Approved pipeline-layout implementation

The user approved the reviewed pipeline-input profile by replying CONTINUE to
the explicit standard-iterator/4096-layout/full-immediateSize question. This
authorizes the eight bounded pieces in the review, not a new public wire,
browser admission policy, device-ownership filter or provider activation.

The approved production snapshot in `webgpu-os/kernel/GpuDeviceBroker.js` is
accepted as a bounded pipeline-layout input slice on2026-09-13. Its final
verification passed1955/1955 browser executions across47 gates and693/693 Python
checks across42 literal files. This is not acceptance of the full GPU boundary,
provider, or visible city. Ordinary forwarding,
shader union behavior and its separately budgeted sequence loop, sampler numeric
behavior, BGL defaults/error codes/cap, and the inert sequence publisher must be
preserved. Existing authored presenter calls need no redesign. The ordinary
test's pipeline positive descriptor now supplies the required empty layout list.
The terminal-delivery and terminal-entry fixtures also required a narrow
prerequisite correction: prepare genuine native binding layouts after capturing
the original raw facade, then release that prerequisite during independent
fixture cleanup. The production interface check was not weakened for test data.

**Historical continuation checkpoint, 2026-09-12:** browser-test authoring was interrupted
by a Codex platform safeguard, as shown in the user's screenshot and the agent
failure status. This is not a browser test result or proof of an engine failure.
The exact classification is not established here. No completed work is rolled
back, and no unfinished check is counted as passing.

| Artifact | Observed state at the checkpoint |
| --- | --- |
| Broker candidate | Written; SHA256 `5aef9928afa156da79f9391d49267be33222bfde11be03179642de431e515c95`. |
| Terminal-delivery fixture | Written; SHA256 `cb70f3e29aa08f7bdee1df991e4ab09b19fe7dd6d5cd5079e212fefeb6f29813`. |
| Terminal-entry fixture | Written; SHA256 `bf5ad7d070eb1222ce0d4ef55731476dce3bdd797f514a10ce35cea1d1627e7b`. |
| New pipeline browser groups | Two selection exports exist, but neither has test registrations. The four planned HTML/main entry files are absent and the runner has no pipeline selectors. |
| New Python gate | 22 checks are authored, not all verified. Its hygiene check intentionally requires the four missing browser entry files; the entire gate cannot pass in this state. |
| Actual new verification | The earlier production-only selection passed20/20. No complete post-change browser or Python regression receipt exists. Historical1634/1634 and669/669 results are not evidence for this candidate. |

The retained early JUnit result is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-pipeline-layout-early-20260912232816.xml`
(SHA256 `4b23076bfa8d7808bf44978d8f8ca8c857bd3c6de7f2ee9edbc92e30357fb0c9`).
Its adjacent `-bindings.json` records the exact command and eight unchanged
before/after source bindings (SHA256
`8455b7c4b3151395e1543c72625bc681f8a99ebf369761f1b81efd8ccd35d559`).
At that checkpoint, the incomplete browser selections were not passing gates
and the candidate remained unaccepted. The completed evidence is recorded here
separately; the historical failure and interruption records are preserved.

**Durable tests completed, 2026-09-13:** the existing ordinary-work registrar
now contains43 pipeline profile cases and64 pipeline native cases. Four explicit
HTML/main entry files expose those groups independently. The existing runner
adds only their two main modules to its reviewed allowlist and registers source
plus presenter-first/controller-first canonical selections. Source test closures
remain203 modules and canonical test closures202; the original authority closure
and public interfaces do not grow. Each page and runner checks exact nonzero
counts and zero skips. (Sources:
`tests/virtual-realm/m2-gpu-presenter-ordinary-work.test.js`;
`m2-gpu-presenter-pipeline-layout-profile.main.js`;
`m2-gpu-presenter-pipeline-layout-native.main.js`;
`run_protected_startup_browser.py`.)

The profile checks required fields versus nullable elements, callable/inherited
dictionaries, complete label conversion, immediate-size defaults/truncation/range,
ordered observations, frozen inert containers, sparse/mutating/custom sequences,
the independent4096 limit, exception identity and independent cleanup. The native
group includes all14 historical callback stages in both rooted and generic modes,
each with a current and revoking twin:56 native witnesses. Revoking twins require
zero native method entries, zero native objects, zero immediate publications,
zero later caller callbacks and no iterator closing. Current twins require one
entry/object/publication. The remaining eight native groups distinguish the
common conversion subset, deliberate iterator/quota differences, real interface
identity, numeric device validation and load-awaited child-frame same-owner use.
They do not replay the known cross-frame/foreign-device crash.

An independent review corrected one test-reporting error before browser execution:
the numeric-hook vector now has an inert display label, so collecting its metrics
does not call the supplied coercion hook again. No production change was needed.
The structural gate retains its original22 checks and adds two exact entry/closure
and native-witness evidence checks. These24 Python checks describe structure and
source boundaries, not JavaScript execution or a visible city.

**Measured focused and structural evidence, 2026-09-13:** the two source browser
groups passed107/107 (43 profile and64 native), with zero failures, skips, browser
errors or denied requests on Chrome151.0.7922.174. The focused receipt is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-z_xnbru1.json`,
SHA256 `91991cf2a4ba80c286da3c1339238ff52f9ec2f33cb63c1a6e073db71df9958b`.
Its complete command, output and source bindings are retained in
`C:/Users/btspa/AppData/Local/Temp/vr-pipeline-focused-879baa2f46c24abfb0a819cdfa075c6b/`.
All56 native twins were independently rechecked against their reported counters.
All206 served paths match current source bytes after the runner's existing
normalization:203 raw/LF-normalized modules/pages and three WGSL-preprocessed
shader modules. The existing shader preprocessing is not a source edit.
The focused wrapper used a60-second connection-and-receive timeout; this differs
from the historical initial15-second connection followed by a60-second receive
timeout. Neither setting changes runtime policy or the90-second between-poll
deadline. The full regression repeats these source gates with the exact
historical connection/receive setup.

The exact42-file Python regression passed693/693, zero failures/errors/skips,
in255.254 seconds according to its parsed JUnit report. All53 explicitly bound
source files were unchanged before/after. Plugin autoload and cache were disabled;
the invocation included `--noconftest --tb=line`. The report is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-pipeline-python-20260913-204659.xml`,
SHA256 `dfacb5412c4bbfaac4a7fcbf2b0ec2c6f79f6d2cd9a2316a682dbf13a0aa412a`.
The selection is the41 literal files in
[durable binding-layout verification](#durable-binding-layout-verification),
plus `tests/virtual-realm/test_m2db4h_gpu_pipeline_layout_descriptor.py`.
This result supersedes the early20-check evidence for current structural
verification; it does not reclassify any historical failed browser diagnostic.

Acceptance requires genuine positive and revoking native twins, exact converted
values, standard iterator and quota boundaries, native BGL identity without
freezing native objects, and zero native entry/effect/immediate publication on
revocation. All prior strict denial and independent cleanup assertions remain.
The source and both canonical import orders now pass their exact new tests and
the bounded existing regressions. The historical34/62 diagnostic remains a
failed pre-fix result, not a test rerun on the accepted source.

**Final bounded browser acceptance, 2026-09-13:** all47 selections passed1955/1955,
zero failures/skips/unexpected browser errors/denied requests. The previous41
selections passed1634/1634 again on this exact candidate; the six new selections
add321 executions (43 profile plus64 native, each in source and both canonical
orders). All168 native twin records were independently checked:84 revoking
executions prevented native entry, object creation and immediate publication;
84 current twins retained exactly one of each. All retained independent cleanup,
zero iterator-return observations and zero later caller callbacks.

The final receipt is
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-protected-startup-receipt-obq0mujt.json`,
SHA256 `6bd7e8132d52a23df45bad57365f140f27f2b3b2fd90a587c713ff0459dd2bb2`.
The isolated Chrome151.0.7922.174 run used305 preloaded routes, with content
aggregate `c2910781c75258f8d009638c7fa6cbc6ef245e2e1d6441fc5bbcc0c8b0e5ed06`.
The251 local raw/LF-normalized source bindings were identical before/after and
matched current files in the root audit. All305 final served hashes match the
recorded preflight manifest. The three shader sources use the existing WGSL
transformation, as recorded in the focused evidence. Two initial-import receipts
have the existing exact1 result shape without a per-test array; the remaining45
receipts carry complete harness cases. No absent array was counted as a failed
test or silently treated as a skipped check.

There are exactly26 expected canonical diagnostics:
`[PE] missing module: engine/core/gpu/VirtualGPU.js`. The absent module is not
read or served. No other browser error is ignored. Gate durations total949.463
seconds, maximum67.937 seconds; all terminal receipts arrived normally. The
historical initial15-second connection and subsequent60-second per-receive
timeout were used with the unchanged90-second between-poll deadline. The receive
timeout is not a whole-gate wall-time cap. Isolated browser/profile/server cleanup
completed and the process exited0. No timeout, browser flag, assertion, native
prerequisite or source-boundary relaxation was needed.

Complete artifacts are retained under
`C:/Users/btspa/AppData/Local/Temp/vr-pipeline-full-20c587dd621948319fc6bb2d96274e1c/`:

| Artifact | SHA256 |
| --- | --- |
| `run_pipeline_full47.py` | `6b459c57733145287854f6e5136abdf68545fab263ea5cd3d679787d42262b97` |
| `command.ps1` | `53b87d8e6c29a3814c5f0b8eedcec05b2a93a20a4f32d272ae68aa65fef3888d` |
| `source-before.json` and `source-after.json` | `b9b5d4b8d1d41f2853d61cb900d179cecd022043db48b6ae4bc7f32d11acdd24` |
| `served-bindings.json` | `d1eb7264daac0c3c040e0ea00bd4d209e44fe6db483dd65bfeacbdb09e9e2513` |
| `output.log` | `07857b33b29d8ed5146a7f7c89c0baaa76bebca4ed4a70497c0e89b76ba98db8` |

The accepted Broker retains SHA256
`5aef9928afa156da79f9391d49267be33222bfde11be03179642de431e515c95`;
no production edits were required during this verification continuation.
The final ordinary-work test is
`13633d65b4b2f9765c6819e244ca4b5bbb88117cc8c2ba21b44a191d67ab7a5d`,
runner `5c64970e0e12466e26c792685e57ed11c68f9cfd4b74085c26af8518d8069111`,
and pipeline Python gate
`e0ac19437ec56a0fdd2c07e6335371956c13ad705fb55a48a6bb66a54dc89363`.
The source manifests bind all four entry files and retained fixture corrections.
Independent production/test review and scoped SPDX/whitespace checks passed.
No global documentation/API generators, full OS build, provider activation,
publication, commit, or First Shard scan was performed.

The cross-frame/foreign-device crash remains unresolved and is not replayed as
a routine acceptance test. Separate passing brand-only and same-owner controls
do not replace it. Remaining native argument/return families, full provider
integration and M1C-to-first-submitted-visible-city stay open. Both flat ledgers
retain ten pieces, with this work remaining inside piece9.

###### Durable pipeline-layout reproduction

These exact command bodies are retained in the plan so reproducing the gate
does not depend on temporary command files surviving. Run from
`C:/Coding/game`. The browser wrapper is the full47 selection, uses only the
existing guarded runner, and writes fresh evidence alongside its saved file.
The Python command is the actual42-file invocation; it captures53 explicit
before hashes, compares them after execution, and prints the comparison.
Its report filename receives a fresh time on each execution. These commands
execute tests and do not activate a Realm provider.

Browser wrapper (saved as a local Python file and run with `python -B`):

```python
# SPDX-FileCopyrightText: 2026 Jake Wehmeier (BTSpaniel) <https://github.com/BTSpaniel>
# SPDX-License-Identifier: LicenseRef-ParticleRealms-Alpha
"""Saved 41-selector command plus six pipeline gates, exact established transport."""

import hashlib
import json
import sys
import time
from pathlib import Path

ROOT = Path(r"C:\Coding\game")
OUTPUT = Path(__file__).parent
sys.path.insert(0, str(ROOT / "tests/virtual-realm"))
sys.path.insert(0, str(ROOT))
import run_protected_startup_browser as runner

SELECTORS = """generation stable owned prebind host protected terminal ordinary native-gap descriptor-gap shader-profile shader-native sampler-profile sampler-native cohort-terminal presenter-first controller-first bundle-presenter-first bundle-controller-first bundle-terminal-presenter-first bundle-terminal-controller-first bundle-ordinary-presenter-first bundle-ordinary-controller-first bundle-native-gap-presenter-first bundle-native-gap-controller-first bundle-descriptor-presenter-first bundle-descriptor-controller-first bundle-shader-profile-presenter-first bundle-shader-profile-controller-first bundle-shader-native-presenter-first bundle-shader-native-controller-first bundle-sampler-profile-presenter-first bundle-sampler-profile-controller-first bundle-sampler-native-presenter-first bundle-sampler-native-controller-first binding-layout-profile binding-layout-native bundle-binding-layout-profile-presenter-first bundle-binding-layout-profile-controller-first bundle-binding-layout-native-presenter-first bundle-binding-layout-native-controller-first pipeline-layout-profile pipeline-layout-native bundle-pipeline-layout-profile-presenter-first bundle-pipeline-layout-profile-controller-first bundle-pipeline-layout-native-presenter-first bundle-pipeline-layout-native-controller-first""".split()
assert len(SELECTORS) == len(set(SELECTORS)) == 47
original_init = runner.Cdp.__init__
original_call = runner.Cdp.call
original_preflight = runner.preflight
original_run_gate = runner.run_gate
gate_results = []
source_paths = []


def diagnostic_init(self, url):
    original_init(self, url)
    self.socket.settimeout(60)


def diagnostic_call(self, method, params=None):
    began = time.monotonic()
    try:
        result = original_call(self, method, params)
        elapsed = time.monotonic() - began
        if elapsed >= 1:
            print(json.dumps({"diagnosticCall": method, "elapsedSeconds": round(elapsed, 3), "status": "returned"}), flush=True)
        return result
    except Exception as error:
        print(json.dumps({"diagnosticCall": method, "elapsedSeconds": round(time.monotonic() - began, 3),
                          "status": "raised", "error": repr(error), "events": self.events[-30:]}), flush=True)
        raise


def bindings(stage):
    records = {}
    for relative in source_paths:
        assert "first-shard" not in relative.lower()
        path = (ROOT / relative).resolve()
        path.relative_to(ROOT.resolve())
        raw = path.read_bytes()
        records[relative] = {"rawSha256": hashlib.sha256(raw).hexdigest(),
                             "normalizedSha256": hashlib.sha256(raw.decode("utf-8").replace("\r\n", "\n").encode()).hexdigest()}
    (OUTPUT / f"source-{stage}.json").write_text(json.dumps(records, indent=2), encoding="utf-8")
    print(json.dumps({"sourceStage": stage, "boundFileCount": len(records),
                      "artifact": str(OUTPUT / f"source-{stage}.json")}), flush=True)


def recorded_preflight(names):
    content, gates = original_preflight(names)
    assert len(gates) == 47 and sum(count for _, _, count in gates) == 1955
    assert all(count > 0 for _, _, count in gates)
    source_paths.extend(key.lstrip("/") for key in sorted(content) if not key.startswith("/__reviewed-"))
    artifact = {"selectors": names, "gates": gates, "initialConnectionTimeoutSeconds": 15,
                "perReceiveTimeoutSeconds": 60, "betweenPollDeadlineSeconds": 90,
                "servedFiles": {key: hashlib.sha256(body).hexdigest() for key, body in sorted(content.items())},
                "servedContentDigest": hashlib.sha256(b"".join(
                    key.encode() + content[key] for key in sorted(content))).hexdigest()}
    (OUTPUT / "served-bindings.json").write_text(json.dumps(artifact, indent=2), encoding="utf-8")
    bindings("before")
    return content, gates


def diagnostic_gate(*args, **kwargs):
    began = time.monotonic()
    try:
        result = original_run_gate(*args, **kwargs)
        timing = {"elapsedSeconds": round(time.monotonic() - began, 3), "unchangedPollingDeadlineSeconds": 90,
                  "transientTransportTimeoutSeconds": 60, "terminalReceiptArrived": True}
        result["diagnosticTransport"] = timing
        gate_results.append(result)
        (OUTPUT / "gate-results.json").write_text(json.dumps(gate_results, indent=2), encoding="utf-8")
        print(json.dumps({"diagnosticGate": args[3], **timing, "passed": result["passed"],
                          "completedGates": len(gate_results),
                          "completedCases": sum(item["browserReceipt"]["totalCount"] for item in gate_results)}), flush=True)
        return result
    except Exception:
        print(json.dumps({"diagnosticGate": args[3], "elapsedSeconds": round(time.monotonic() - began, 3),
                          "terminalReceiptArrived": False}), flush=True)
        raise


runner.Cdp.__init__ = diagnostic_init
runner.Cdp.call = diagnostic_call
runner.preflight = recorded_preflight
runner.run_gate = diagnostic_gate
sys.argv = [str(ROOT / "tests/virtual-realm/run_protected_startup_browser.py")] + SELECTORS
try:
    status = runner.main()
finally:
    if source_paths:
        bindings("after")
raise SystemExit(status)
```

Python structural regression (PowerShell):

```powershell
$env:PYTEST_DISABLE_PLUGIN_AUTOLOAD = '1'
$taskPipelineGates = @(
    'tests/virtual-realm/test_m2db4h_surface_receipt_provenance.py'
    'tests/virtual-realm/test_m2db4h_runtime_lifecycle_binding.py'
    'tests/virtual-realm/test_m2db4h_runtime_host_lifecycle.py'
    'tests/virtual-realm/test_m2db4h_runtime_diagnostics_source.py'
    'tests/virtual-realm/test_m2db4h_runtime_attempt_binding.py'
    'tests/virtual-realm/test_m2db4h_process_owner_telemetry_binding.py'
    'tests/virtual-realm/test_m2db4h_process_owner_identity_authority.py'
    'tests/virtual-realm/test_m2db4h_operator_transition_drain.py'
    'tests/virtual-realm/test_m2db4h_local_selection_head_storage.py'
    'tests/virtual-realm/test_m2db4h_local_operator_snapshot_source.py'
    'tests/virtual-realm/test_m2db4h_local_operator_policy_head_storage.py'
    'tests/virtual-realm/test_m2db4h_lifecycle_session_authority.py'
    'tests/virtual-realm/test_m2db4h_lifecycle_port_composition.py'
    'tests/virtual-realm/test_m2db4h_lifecycle_participant_authority.py'
    'tests/virtual-realm/test_m2db4h_lifecycle_generation_head_storage.py'
    'tests/virtual-realm/test_m2db4h_lifecycle_composition_telemetry_source.py'
    'tests/virtual-realm/test_m2db4h_lifecycle_allocation_authority.py'
    'tests/virtual-realm/test_m2db4h_guarded_frame_telemetry_source.py'
    'tests/virtual-realm/test_m2db4h_gpu_terminal_cleanup_contract.py'
    'tests/virtual-realm/test_m2db4h_gpu_surface_allocation_source.py'
    'tests/virtual-realm/test_m2db4h_gpu_stable_allocation_source.py'
    'tests/virtual-realm/test_m2db4h_gpu_presenter_generation_source.py'
    'tests/virtual-realm/test_m2db4h_gpu_presentation_epoch_source.py'
    'tests/virtual-realm/test_m2db4h_gpu_prebind_allocation_binding.py'
    'tests/virtual-realm/test_m2db4h_gpu_owned_adapter_allocation.py'
    'tests/virtual-realm/test_m2db4h_gpu_original_resource_registry.py'
    'tests/virtual-realm/test_m2db4h_gpu_mount_allocation_source.py'
    'tests/virtual-realm/test_m2db4h_gpu_cohort_terminal_cleanup.py'
    'tests/virtual-realm/test_m2db4h_gpu_allocation_cohort.py'
    'tests/virtual-realm/test_m2db4h_frame_producer_telemetry_source.py'
    'tests/virtual-realm/test_m2db3_runtime_production_composition.py'
    'tests/virtual-realm/test_m2db2_gpu_presentation_syscall_adapter.py'
    'tests/virtual-realm/test_m2db4h_gpu_protected_startup.py'
    'tests/virtual-realm/test_m2db4h_gpu_presenter_terminal_cleanup_entry.py'
    'tests/virtual-realm/test_m2db4h_gpu_presenter_terminal_cleanup.py'
    'tests/virtual-realm/test_m2db2_gpu_presentation_port.py'
    'tests/virtual-realm/test_m2db4h_gpu_presenter_ordinary_work.py'
    'tests/virtual-realm/test_m2db4h_gpu_native_work_view.py'
    'tests/virtual-realm/test_m2db4h_gpu_shader_descriptor_profile.py'
    'tests/virtual-realm/test_m2db4h_gpu_sampler_descriptor.py'
    'tests/virtual-realm/test_m2db4h_gpu_binding_layout_descriptor.py'
    'tests/virtual-realm/test_m2db4h_gpu_pipeline_layout_descriptor.py'
)
$taskPipelineBindings = $taskPipelineGates + @(
    'webgpu-os/kernel/GpuDeviceBroker.js'
    'webgpu-os/kernel/realm/RealmGpuAllocationCohortCore.js'
    'webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js'
    'tests/virtual-realm/m2-gpu-presenter-ordinary-work.test.js'
    'tests/virtual-realm/m2-gpu-presenter-terminal-delivery.fixture.js'
    'tests/virtual-realm/m2-gpu-presenter-terminal-entry.fixture.js'
    'tests/virtual-realm/run_protected_startup_browser.py'
    'tests/virtual-realm/m2-gpu-presenter-pipeline-layout-profile.main.js'
    'tests/virtual-realm/m2-gpu-presenter-pipeline-layout-profile.test.html'
    'tests/virtual-realm/m2-gpu-presenter-pipeline-layout-native.main.js'
    'tests/virtual-realm/m2-gpu-presenter-pipeline-layout-native.test.html'
)
$taskPipelineBefore = @{}
foreach ($taskPath in $taskPipelineBindings) { $taskPipelineBefore[$taskPath] = (Get-FileHash -Algorithm SHA256 -LiteralPath $taskPath).Hash.ToLowerInvariant() }
$taskPipelineReport = 'C:/Users/btspa/AppData/Local/Temp/virtual-realm-pipeline-python-20260913-' + (Get-Date -Format 'HHmmss') + '.xml'
Write-Output ('JUnit report: ' + $taskPipelineReport)
python -B -m pytest --noconftest -p no:cacheprovider -q --tb=line @taskPipelineGates --junitxml=$taskPipelineReport
$taskPipelineExit = $LASTEXITCODE
$taskPipelineChanged = @()
foreach ($taskPath in $taskPipelineBindings) { if ($taskPipelineBefore[$taskPath] -ne (Get-FileHash -Algorithm SHA256 -LiteralPath $taskPath).Hash.ToLowerInvariant()) { $taskPipelineChanged += $taskPath } }
[PSCustomObject]@{Report=$taskPipelineReport;ExitCode=$taskPipelineExit;BoundCount=$taskPipelineBindings.Count;Changed=$taskPipelineChanged;Bindings=$taskPipelineBefore} | ConvertTo-Json -Depth 3
exit $taskPipelineExit
```

The recorded Python command artifact has SHA256
`2e0799bacbe8c8bec27a64ea60ae95b745167345ab49d7100c3b4b50f51fec57`.
Its `-bindings.json` has SHA256
`c409b7435b3ca2dcdda56a1443fe7d7361344e275c473d15df663aac1b92bf8d`;
the before map and empty after-run change list are preserved, not a separately
emitted after-hash map. The consolidated `-stdout.txt` has SHA256
`8e3fc67bf2afd1ae92b6379454ec5ada8b0375b11bc820b31b5c89c77087ab31`.
It contains the complete streamed text normalized to LF, not byte-for-byte
OS-level redirected output. All three artifacts share the JUnit report's
`virtual-realm-pipeline-python-20260913-204659` prefix.

##### Protected-head observation and writer-ownership decision

Status on 2026-09-19: the user approved the single trusted local writer by
replying CONTINUE to the explicit ownership question. The first reservation
prerequisite is implemented and accepted within the bounded scope below. It belongs to existing
flat piece 3, not another milestone or an extension of the accepted pipeline
slice. This section does not accept a live subscription, an isolation boundary,
M1C production composition, the provider, or a visible frame.

The current snapshot source can establish a coherent selection/policy cut, but
cannot keep an active consumer current. `RealmLocalOperatorSnapshotSource`
returns only `readSnapshot`. `RealmProtectedHeadStorage` exposes
`readCurrent`, `assertCurrent`, and `replaceCurrent`, with useful CAS and
uncertain-write recovery but no observation protocol. Their existing APIs and
frozen B4A/B4F records must be preserved.
(Sources: `webgpu-os/kernel/realm/RealmLocalOperatorSnapshotSource.js`;
`webgpu-os/kernel/realm/RealmProtectedHeadStorage.js`.)

The missing notification cannot be filled with an ordinary storage listener:

- `StorageManager.bindOperatorServiceRoot` creates a new scoped binding on each
  acquisition. A registry attached to one source or view misses sibling writers.
- `StorageManager.writeAtomic` checks its expected predecessor and writes under
  the mutation lock, then emits `write` after readback and hashing. That event
  arrives too late to invalidate already-active consumers before dispatch.
- `StorageCoordination.publish` sends a broadcast without an acknowledgment.
  `StorageManager._receiveRemoteEvent` queues delivery. Mutation serialization
  does not itself make other contexts stop using an earlier observation.
- Manager object identity is not backing-storage identity. A second manager or
  tab can refer to the same protected data. Native same-origin storage access
  remains outside a JavaScript observer registry.

(Sources: `webgpu-os/storage/StorageManager.js`,
`StorageOperatorServiceScopeBinding`, `bindOperatorServiceRoot`, `writeAtomic`,
`_emit`, and `_receiveRemoteEvent`;
`webgpu-os/storage/StorageCoordination.js`, `exclusive` and `publish`.)

**Approved decision:** use one enforced, trusted local OS owner for Virtual
Realm selection and local-policy mutation. Other windows or contexts communicate
through a dedicated bounded channel; they do not independently acquire a writer.
This ownership applies to these Realm control heads, not every file, remote
city, multiplayer participant, or RealmForge authoring action. Approval permits
implementation of that ownership model; it is not evidence that enforcement or
the controlled client channel already exists.

The single-owner recommendation is not satisfied by a singleton variable,
caller-supplied owner ID, a source import allowlist, or an unacknowledged message.
Admission must establish genuine owner identity and lifetime, exclude competing
writers, and enforce the previously required protected-backend isolation before
exposing live app ports. If a second context cannot join that domain safely, its
live service stays unavailable. Owner loss closes existing observations; restart
requires fresh identity, storage reconciliation, and new observations rather than
silently reviving old registrations. Existing privileged legacy storage must not
be disabled globally as a shortcut.

An alternative would retain multiple writer owners and introduce a bounded,
acknowledged invalidation protocol across them. That alternative needs explicit
membership, timeout, crash, cancellation, and recovery rules before activation;
the current broadcast mechanism does not supply them. That alternative was not
selected; the new explicit ownership approval, not an earlier graphics approval,
authorizes the single-owner implementation.

After the ownership decision, complete this bounded work in dependency order:

| Work item | Reuse and proposed change | Required evidence |
| --- | --- | --- |
| 1. Define the owner and observation domain | Bind the private observer authority to the actual boot-owned storage lifetime. Keep existing app wires and view surfaces unchanged; specify the internal registration and channel records before editing production. | A second view joins the same genuine owner; a foreign or competing manager/context is denied or safely joined, never accepted by matching string IDs. |
| 2. Add the pre-mutation barrier | Integrate at the protected storage authority, not only `RealmProtectedHeadStorage`. Reuse existing CAS and scope fences. Cover every permitted mutation route for selection and local-policy heads. | All affected observations become unusable before backend mutation can begin. Direct protected-view writes cannot bypass the barrier. |
| 3. Close the initial observation race | Attach observation before the existing selection-policy-selection read and reassert its revision after every asynchronous step. Keep snapshot semantics separate from a live observation. | A change during attachment, read, or publication cannot produce a usable stale observation. Missing or cleared selection stays unavailable. |
| 4. Bind the actual lifecycle | Consume genuine operator/lifecycle signals. Translate only the closed B4A/B4F invalidation reasons. Dispose bounded subscriptions without forwarding raw storage events or paths. | Operator switch, lock, local selection, authority/policy change, owner stop, disposal, and callback reentry preserve currentness and exact cleanup. |
| 5. Preserve uncertainty and retry | Retain invalidation after a dispatched write with unknown outcome. Reuse protected-head recovery; a later successful read permits a new observation, not resurrection of an old one. | CAS conflict, pre-dispatch cancellation, failed dispatch, uncertain completion, and readback failure have explicit results and leave no stale live observer. |
| 6. Implement the controlled client boundary | Keep writer and native protected-storage authority at the trusted owner. Use bounded messages, genuine session binding, cancellation, subscription disposal, and revocation. Reuse the existing isolated-host primitive only where its behavior meets those requirements. | Unknown messages, wrong sessions, stale replies, unsupported contexts, and unavailable isolation fail closed. A real protected-storage sentinel is inaccessible to the isolated client. |
| 7. Run focused and existing regressions | Reuse `RealmProtectedHeadTestFixtures.js` and existing selection, policy, snapshot, B4A/B4F, private-storage, and operator-switch gates. Proposed new gate: `tests/virtual-realm/m2-local-head-observation.test.js`, with matching browser entry and scoped structural checks. | Exercise real sibling views and separate managers/contexts, not only injected callbacks. Record exact sources and actual results; do not predict pass counts. |
| 8. Document bounded acceptance and rollback | Update this section, the two existing flat ledgers, composition notes, and session memory only after evidence is available. Keep full provider registration disabled during this slice. | Observer/domain acceptance is distinguished from admission, activation, rendering, and full provider acceptance. Failed installation tears down the new domain and keeps the Realm unavailable without deleting heads or altering unrelated storage. |

Candidate impact is `webgpu-os/storage/StorageManager.js`,
`webgpu-os/kernel/OperatorPrivateServiceStorageView.js`, the existing Realm
selection/policy/snapshot source peers, and focused tests. Any new private owner
or channel module is a proposed implementation detail, not an existing API.
`StorageCoordination.js` is reusable serialization infrastructure, not authority
evidence. Preserve existing storage behavior outside the explicitly opted-in
Realm control domain. Diagnostics should record bounded status, revision,
subscription count, and duration, not account identifiers, paths, head payloads,
or callback-supplied values.

Production M1C composition follows this prerequisite. Its existing constructor
already requires a genuine operator-context port and matched captured storage
generation/partition. Fabricating those inputs would not complete piece 8.
(Source: `webgpu-os/kernel/realm/RealmM2PrivateBakeAdmissionComposition.js`.)

The original decision checkpoint was a source audit plus independent review,
not a browser execution. Historical 1,955/1,955 browser and 693/693 Python results
still certify the accepted pipeline slice only. The separate cross-frame/foreign-device crash, other native boundaries,
activation/checkpoint/handoff/action owners, full provider, and first city frame
remain open. No First Shard source was scanned.

##### Single-owner reservation prerequisite

`webgpu-os/kernel/realm/RealmLocalHeadOwnerReservation.js` now implements the
first bounded prerequisite for the approved piece-3 owner. Reservation verification
passed on 2026-09-19; there is no live writer-owner or observation acceptance yet. The module
is not imported by boot, the storage manager, the app, or a provider composition.
It performs no storage read, write, or initialization.

The factory `acquireRealmLocalHeadOwnerReservation` accepts exactly frozen
`{ operatorContext, storageManager, signal }`. It captures the active operator
scope and requests a nonqueued exclusive native Web Lock named
`webgpu-os.virtual-realm.local-head-owner.v1:<accountId>`. Generation is excluded
from that name: a new generation cannot coexist with an old retained reservation
for the same account. Different accounts have independent reservations. This
uses a separate lifetime lock, never the existing global storage mutation lock.
No caller-selected name, lock implementation, steal option, or local fallback is
available. Native `ifAvailable` requests cannot also take a cancellation signal;
the implementation uses its captured native listeners and fences instead.
(Platform semantics: [Web Locks specification](https://www.w3.org/TR/web-locks/).)

Cancellation uses a private native `AbortSignal.any([signal])` relay. A listener
installed earlier on the caller's signal cannot hide cancellation using
`stopImmediatePropagation()`, and a synthetic `abort` event is not cancellation.
The relay and synchronous fences do not claim to precede every earlier source
signal listener. Missing native dependent-signal support fails closed; no event-only
fallback is installed.
(Platform semantics: [DOM abort signals](https://dom.spec.whatwg.org/#abortsignal-signal-abort).)

The exact frozen result is `{ signal, assertCurrent, close }`. The returned
signal is native and carries only bounded failure codes. `assertCurrent()` is
synchronous and returns `true` only while the reservation remains usable.
`assertRealmLocalHeadOwnerReservation(reservation, bindings)` additionally
requires the original issued object and exact frozen
`{ operatorContext, storageManager }` identity pair; copied or proxied handles
do not qualify. Matching account strings alone do not establish that binding.

Cancellation or operator change permanently retires the published reservation
and aborts its signal, but **does not release the lock**. The future trusted owner
must drain its work before calling `close()`. Close publishes one idempotent
promise before abort callbacks can reenter, releases the native holder, and
resolves the frozen `{ released: true }` receipt after native request settlement.
The receipt proves only reservation release, not storage or GPU cleanup.
Unreturned failed acquisitions clean up automatically. Native lock loss also
retires the handle; a subsequent reservation never revives it.

This is cooperative exclusion among participants using this lock in the same
browser storage bucket, not machine-wide exclusion. Other browser profiles,
storage partitions, or direct OPFS calls are not protected by this primitive.
The manager value is retained by identity without authenticating it or observing
its `close()`; future owner composition must bind genuine boot acquisition,
manager lifetime, drain, and storage mutation enforcement. `OperatorContext`
notifications do not themselves make switching await that drain. The reservation
alone does not change storage writers; the subsequent shared-write guard is
described in [cooperative head-write exclusion](#cooperative-head-write-exclusion).
A privileged same-origin lock stealer is not
prevented by this primitive; native request loss invalidates the reservation.
Backend isolation, the pre-mutation barrier, coherent observation, client
transport, and full provider registration remain required and disabled.

**Bounded verification:** Chrome 153.0.8010.48 passed 118/118 browser cases:
38 owner-reservation cases plus the unchanged snapshot24, selection32, and
policy24 regressions. There were zero failures, skips, browser errors, or denied
HTTP routes. Tests cover real native contention between separate managers and
loaded same-origin contexts, generation-independent exclusion, operator changes,
cancellation before and after grant, retained exclusion until close, reentrant
and repeated close, native lock loss, captured-method integrity, and unavailable
native facilities. Failure-only platform injections never fabricate a successful
lock. These tests do not execute protected storage writes through the reservation.

At the reservation-only checkpoint, the scoped Python group passed 45/45 checks: new reservation17, snapshot10,
selection9, and policy9, with zero failures, errors, or skips. The production
import closure contains exactly24 modules. Browser gate closures are70/76/73/74
for owner/snapshot/selection/policy. The isolated runner used88 preloaded routes
and96 raw source bindings, with no directory walk. Root independently verified
all served bytes, all96 current browser-bound source hashes, all11 Python-bound
source hashes, exact before/after equality, and the receipt counts. Existing
Entry155 and composition114 guarded closures remain unchanged and do not import
the reservation. No global generator or full OS bundle was run.

Evidence artifacts:

- Browser directory: `C:/Users/btspa/AppData/Local/Temp/virtual-realm-head-owner-ukpc6frv/`.
  `receipt.json` SHA256 `78860f102cbf32a70715cf406fa324c4e73bda2344d345d7b6209f5dce9db79b`;
  `source-before.json` and `source-after.json` both
  `e9675ed01aac5a0bb8cbb791ae6c73412ccb202df6474dd14494758480704ac7`.
- Python directory: `C:/Users/btspa/AppData/Local/Temp/virtual-realm-head-owner-python-15770275c95f4d478156c5940b1e17e3/`.
  `pytest.xml` SHA256 `2498889e74f3609c49730871ace1efd387f7031bb890aad11306e45de477b78a`;
  `source-before.json` and `source-after.json` both
  `599a3e0843fbe369d5c9b47972a98d7c6539bd3c877bab9c49a5ab90ee0450e3`.
- Accepted reservation source SHA256:
  `12050b788fd4c3ec4a54483bfd0240bf6e841eaafe6cf9a40f9106a32a380e33`.

Reproduce the browser group from the repository root:

```powershell
python -B tests/virtual-realm/run_local_head_owner_browser.py owner snapshot selection policy
```

Reproduce the scoped Python group (use a new report path when retaining JUnit):

```powershell
$env:PYTEST_DISABLE_PLUGIN_AUTOLOAD='1'
python -B -m pytest --noconftest -p no:cacheprovider -q --tb=short `
  tests/virtual-realm/test_m2_local_head_owner_reservation.py `
  tests/virtual-realm/test_m2db4h_local_operator_snapshot_source.py `
  tests/virtual-realm/test_m2db4h_local_selection_head_storage.py `
  tests/virtual-realm/test_m2db4h_local_operator_policy_head_storage.py
```

The next implementation after that checkpoint is the cooperative head-write
exclusion described next. Genuine storage-owner binding and pre-mutation
invalidation, followed by coherent observation and the controlled client boundary,
remain required. Reservation success alone must never admit a live provider.
The existing ten-piece provider ledger and frozen app dependency record are
unchanged. First Shard was not scanned.

##### Cooperative head-write exclusion

The existing selection and local-policy writers now participate in the approved
account-level reservation protocol. This bounded slice passed verification on
2026-09-19. This is a continuation of flat piece3, not a live
single-writer service, observer, or provider. The owner still has no authorized
write path while it holds its exclusive reservation.
(Sources: `webgpu-os/storage/StorageCoordination.js`,
`webgpu-os/storage/StorageManager.js`,
`webgpu-os/kernel/realm/RealmLocalHeadOwnerReservation.js`.)

`withRealmLocalHeadWriteReservation(accountId, operation)` takes a native shared,
nonqueued Web Lock using the same exported `REALM_LOCAL_HEAD_OWNER_LOCK_PREFIX`
as the exclusive reservation. `StorageManager.writeAtomic` supplies the account
from its privately issued service scope and opts in only
`virtual-realm-local-selection-v1` and `virtual-realm-local-policy-v1`.
Neither a public option nor a matching caller-supplied account string bypasses
the guard. Other services and generic storage retain their existing behavior.

The account lock is acquired before the existing global mutation lock. It is
held while queued for global serialization and throughout predecessor comparison,
backend dispatch, exact text/byte readback, hashing, and receipt construction.
Concurrent legacy writers can hold shared guards but still serialize under the
global lock. An exclusive owner cannot acquire its reservation until earlier
guarded work settles. While an exclusive owner holds or retains that reservation,
all of these managed legacy writes fail with `STORAGE_REALM_HEAD_OWNER_BUSY`,
including writes attempted through that owner's original manager. Retiring an
owner does not reopen writes; only releasing its reservation does.

Captured native entry points validate the returned lock name and mode. Missing
native facilities fail with `STORAGE_REALM_HEAD_COORDINATION_UNAVAILABLE`, with
no process-local fallback. Busy/unavailable errors prove no guarded atomic-operation
callback dispatch; prior service-directory activation is outside this proof.
If native lock loss rejects the lock request while its callback remains active,
the helper waits for that work to settle before rejecting with
`STORAGE_REALM_HEAD_LOCK_LOST` and an unknown-outcome classification. This wait
does not restore stolen exclusion. An ordinary operation failure retains its
original error and conditional-write semantics.
(Platform behavior: [Web Locks API](https://www.w3.org/TR/web-locks/).)

Manager-open and captured-service-currentness checks run at admission, after
global-lock acquisition, and immediately before `_writeTextUnlocked`. Closing a
manager during awaited predecessor reads therefore prevents backend dispatch.
Closure or operator change after dispatch cannot cancel already-issued OPFS work;
the guard remains held through completion/failure. No new manager-close drain
service or owner bypass is introduced.

The direct storage denial can prove no effect, but the existing higher-level
`RealmProtectedHeadStorage.replaceCurrent` conservatively marks any rejection
after calling `writeControlAtomic` as `WRITE_UNCONFIRMED` and requires recovery.
This continuation preserves that behavior. It does not make a busy high-level
write automatically retryable or revive an earlier observation.

The protected view's only permitted head mutation remains `writeControlAtomic`.
Control deletion is forbidden for both services; neither exposes a content
namespace. Existing guards reject unscoped mutations within protected service
trees and the explicitly listed ancestors: `/os`, `/os/state`,
`/os/state/operators`, and exact operator roots. This slice does not establish
generic `/`-root or low-level backend denial. Service-directory activation, raw backend/OPFS calls, older contexts
running unguarded code, other browser storage buckets, and privileged lock
stealing remain outside this cooperative guarantee. Protected-backend isolation
is still required before any live app/provider admission.

**Verification:** all five browser gates passed151/151 in Chrome153.0.8010.48:
writer33, owner38, snapshot24, selection32, and policy24. There were no failures,
skips, browser errors, or denied HTTP routes. New cases exercise genuine OPFS
writes, separate managers and loaded same-origin contexts, shared/exclusive
contention, waiting for global serialization, held predecessor/backend/readback
phases, manager closure before dispatch, cancellation, failed completion, native
lock loss, and real high-level recovery. Platform and backend failure injection
is explicitly distinguished from the successful native/storage paths. Test
cleanup drains pending work before removing only newly created test-account
roots in the isolated browser profile.

The five-file Python group passed60/60: writer15, owner17, snapshot10,
selection9, and policy9, with zero failures/errors/skips. It pins the original
61-line CAS/readback/receipt core after reversing only the documented immediate
pre-dispatch fence substitution. The owner source closure is now25 modules
because it imports the existing, import-free coordination leaf for the shared
namespace. Writer browser closure76; existing owner70/snapshot76/selection73/
policy74, Entry155, and composition114 closures remain unchanged. No provider
import, dependency record, or owner write bypass was added.

Root independently verified all151 individual case receipts, all92 preloaded
served-file hashes, all101 browser-bound current sources, all14 Python-bound
sources, the JUnit counts, and exact before/after equality. Final acceptance runs
had no failures or retries. Review fixed test-only failure cleanup before the
run. Inline-frame preflight now uses its actual `.context.html` identity so an
import of the test helper is not misreported as a self-cycle; its literal
allowlist and preloaded-route restrictions remain enforced.

Evidence artifacts:

- Browser: `C:/Users/btspa/AppData/Local/Temp/virtual-realm-head-owner-4wbftiy9/receipt.json`.
  SHA256 `d223e2d9fc75169c279220e18506108549ae0926d262e8d19470b914b5dab832`.
  Adjacent before/after manifests both
  `a47a45df016b94bfd3c98d8d4be5c5df7a6560cbf75381f00c169bd99d6ce200`.
- Python: `C:/Users/btspa/AppData/Local/Temp/virtual-realm-head-write-python-f523292ff3484689bc8e7ac438869368/pytest.xml`.
  SHA256 `091256ac816f47ce2436bdb9aa6e307416b8185048141dc4100d64d61b0d8558`.
  Adjacent before/after manifests both
  `e317508bede2b9b3eeb470bdf28801def68f7928a9d038ddf1239210651b6583`.
- Production SHA256 at this historical checkpoint: `StorageCoordination.js`
  `95f6995e5483e1d1b5c040846dd7f7a292238098119e6bed643aa9df33f22899`;
  `StorageManager.js` `29cfaba6ddd16f1216cefaeb4b7e4382687e93b8adf48cae42487e49b31d0add`;
  `RealmLocalHeadOwnerReservation.js`
  `e77ee89483827d2ee838ad092e1f83f540bfecd9a06b20ea0ac3171cfe380f45`.

Reproduce from the repository root (use a new output path for any retained report):

```powershell
python -B tests/virtual-realm/run_local_head_owner_browser.py writer owner snapshot selection policy
$env:PYTEST_DISABLE_PLUGIN_AUTOLOAD='1'
python -B -m pytest --noconftest -p no:cacheprovider -q --tb=short `
  tests/virtual-realm/test_m2_local_head_write_exclusion.py `
  tests/virtual-realm/test_m2_local_head_owner_reservation.py `
  tests/virtual-realm/test_m2db4h_local_operator_snapshot_source.py `
  tests/virtual-realm/test_m2db4h_local_selection_head_storage.py `
  tests/virtual-realm/test_m2db4h_local_operator_policy_head_storage.py
```

The next implemented prerequisite is operation draining, described next. Genuine
boot-owned manager/context lifetime, owner-only writes, and pre-mutation
invalidation remain required. The attach-before-read observation protocol and
controlled client channel follow under the approved eight-item plan. No new app
dependency or additional milestone is introduced; First Shard remains excluded.

##### Admitted owner-operation drain

The Virtual Realm owner reservation now tracks operations explicitly admitted
through `runRealmLocalHeadOwnerOperation(reservation, bindings, operation)`.
Closing the reservation retires admission synchronously and retains its native
lock until tracked work settles. This bounded prerequisite belongs to existing
flat piece 3 and passed verification on 2026-09-19. It does not authorize owner
writes or install a boot service,
observation domain, client channel, or live provider.
(Source: `webgpu-os/kernel/realm/RealmLocalHeadOwnerReservation.js`.)

The new trusted-kernel helper reuses the existing private reservation membership
and exact frozen `{ operatorContext, storageManager }` binding checks. It adds
no method to the frozen three-field reservation `{ signal, assertCurrent,
close }`. A copied/proxied reservation or a different manager/context pair is
not accepted. The callback receives no arguments or capabilities.

Each admitted callback owns a private token before callback dispatch is queued.
At most 64 operations may be pending. The 65th rejects with
`VR_M2DB4H_HEAD_OWNER_OPERATION_LIMIT` without invoking it or retaining a token;
a settled slot can be reused while the reservation remains current. A
non-function callback rejects with `VR_M2DB4H_HEAD_OWNER_OPERATION_REQUIRED`.
Currentness is checked at admission, immediately before invocation, and after
fulfilled callback completion. Retirement before invocation prevents dispatch;
retirement detected at the completion fence rejects with
`VR_M2DB4H_HEAD_OWNER_RESERVATION_RETIRED`. Ordinary callback rejection preserves
the original thrown value, including when retirement occurred while it ran.
The result is not a continuing authority lease. Downstream use requires its own
currentness fence rather than treating an earlier success as permanent proof.

Both fulfillment and rejection remove exactly that operation's token. Finishing
work does not release a still-live reservation. `close()` first publishes its
one idempotent promise, then retires and checks whether work remains. This order
preserves abort-callback reentry. It resolves to the existing frozen
`{ released: true }` receipt only after both native request settlement and the
tracked drain. Native lock loss may settle the request first; it cannot bypass
the operation drain. Waiting does not restore stolen exclusion, and the receipt
does not certify physical storage/GPU cleanup or whole-OS shutdown.

The callback boundary is trusted, not a general hostile-code evaluator. A
callback must return the completion of **all** work it starts and an inert final
result. Detached work is not tracked. An active operation must not await its own
owner's `close()` directly or indirectly: close waits for the operation, so that
dependency would deadlock. An operation may request close without awaiting it,
then finish its own work. Already-dispatched work is not cancelled by retirement,
and failure is not reclassified as proof of no effect. Manager-close observation,
boot authenticity, protected writes, and backend isolation remain outside this
helper. Fixed bounded error codes provide diagnostics without account, path, or
payload logging.

The future owner must enroll the complete pre-mutation invalidation, conditional
write, readback, and receipt path as one tracked operation. The helper itself
does not invoke any of those operations or bypass the existing shared-write
guard. An owner still cannot write through its legacy managed view while holding
its exclusive reservation. Enabling that reservation at boot before its genuine
owner-only write path is ready would disable those legacy Realm writes; this
continuation therefore leaves boot activation off.

**Verification:** final browser execution passed 174/174 in Chrome 153.0.8010.48:
drain 23, writer 33, owner 38, snapshot 24, selection 32, and policy 24. There were no
failures, skips, browser errors, or denied HTTP routes. The new cases use native
lock contention and query round trips, not sleeps, to prove retained exclusion
and pending close. They cover staggered success/failure, original error identity,
ordinary thenable settlement, immediate/reentrant close, cancellation, operator
change, native lock loss, exact binding rejection, and 64-slot reuse. Test cleanup
releases every held callback and drains its operation before closing reservations
and managers. The three new browser files introduce no new iframe route.

The six-file Python group passed 73/73 with zero failures/errors/skips in 29.067s:
drain 13, writer 15, owner 17, snapshot 10, selection 9, and policy 9. Structural proofs
pin token admission/removal, the independent native/work drain, cap 64, exact
frozen shapes, and absence of boot/storage/provider integration. The source
closure stays 25 modules; the new browser closure is 70, with existing writer 76,
owner 70, snapshot 76, selection 73, and policy 74 unchanged. Entry 155 and
composition 114 remain unchanged. Python checks are structural evidence, not
JavaScript execution.

Root independently checked all 174 individual browser results, 95 served hashes,
105 current raw browser source bindings, 73 JUnit cases, 14 Python source bindings,
and exact before/after manifest equality. One earlier run passed its cases but
correctly failed acceptance because a JSDoc clarification changed a bound file
during execution. That diagnostic remains at
`C:/Users/btspa/AppData/Local/Temp/virtual-realm-head-owner-ob2jqlf7/receipt.json`.
The final unchanged-source run, not that diagnostic, is the acceptance evidence.

Final evidence artifacts:

- Browser: `C:/Users/btspa/AppData/Local/Temp/virtual-realm-head-owner-zwein2xa/receipt.json`.
  SHA256 `add1cd8c14b694a9e78aba32300237b9e99f70a546c04772e937b1b40184f779`.
  Adjacent before/after manifests both
  `fab0935153451b0951170a077912932d1207507ab28a6267889242ec220a572e`.
- Python: `C:/Users/btspa/AppData/Local/Temp/virtual-realm-head-drain-python-dda53e2cd71e4b22b5b61d336a8f980f/pytest.xml`.
  SHA256 `cc6eecc55b6bb395117f24b75576e9631da9c4113720146119d3b52d7df808a7`.
  Adjacent before/after manifests both
  `c28c9c40cd8674b702f2a4a6cd89af307a64c8db85b70ffd988f86d3ef376854`.
- Current `RealmLocalHeadOwnerReservation.js` SHA256:
  `ac6cf90eb24c3d098d184f1b2962236e49a766da4ae4fd80f074b20a0ef9138b`.
  The preceding checkpoint's coordination and StorageManager hashes remain
  unchanged. No other production module changed in this drain slice.

Reproduce from the repository root (use a fresh output path for retained reports):

```powershell
python -B tests/virtual-realm/run_local_head_owner_browser.py drain writer owner snapshot selection policy
$env:PYTEST_DISABLE_PLUGIN_AUTOLOAD='1'
python -B -m pytest --noconftest -p no:cacheprovider -q --tb=short `
  tests/virtual-realm/test_m2_local_head_owner_drain.py `
  tests/virtual-realm/test_m2_local_head_write_exclusion.py `
  tests/virtual-realm/test_m2_local_head_owner_reservation.py `
  tests/virtual-realm/test_m2db4h_local_operator_snapshot_source.py `
  tests/virtual-realm/test_m2db4h_local_selection_head_storage.py `
  tests/virtual-realm/test_m2db4h_local_operator_policy_head_storage.py
```

Rollback remains local to this reservation/helper and its focused tests. No
stored-head migration, boot import, provider registration, or app dependency was
introduced. Do not activate a partial owner service as a recovery shortcut.
Scoped source/SPDX/Markdown checks replace global regeneration for this turn;
global docs/API/SPDX generators and the full OS bundle remain unrun to preserve
the explicit First Shard exclusion and unrelated concurrent work.

**Next boot integration map, not implemented by this slice:**

| Existing source | Required owner integration |
| --- | --- |
| `webgpu-os/kernel/KernelBootstrap.js`, constructor and `_boot` | Retain the actual imported storage manager, newly created operator context, and kernel lifetime privately. Do not accept reread mutable kernel properties or caller-matching IDs as boot authority. Register the lifecycle participant before `operatorContext.initialize()`. |
| `webgpu-os/kernel/OperatorContext.js`, `registerParticipant`, `_runTransition`, `_settleActive` | The reservation factory calls `capture()`, so acquire only after an active scope exists, not during `bind` or `resume`. Keep the live owner unavailable while asynchronous acquisition is pending; recheck generation and lifetime before publishing. |
| `webgpu-os/kernel/OperatorContext.js`, `_runParticipantPhase` | Priority orders participant invocation, not completion: phase results are awaited together. Freeze must close admission synchronously. Drain must await its own retained operations, even if a newer transition has superseded the original request. |
| `webgpu-os/kernel/KernelBootstrap.js`, `stop` | The current `Promise.allSettled` includes operator lock and does not propagate its rejection. Add an explicit idempotent private owner shutdown and preserve its failure instead of treating the existing aggregate as proof of Realm drain. Retire only this kernel's owner; the imported StorageManager is a shared device service. |
| `webgpu-os/platform/runtime-host/KernelRuntimeHandoff.js`, `freeze`, `resume`, and `shutdown` | Freeze currently coordinates desktop/network/media, not an explicit head-owner drain. Add a genuine private owner handoff hook before advertising Realm handoff readiness, or keep that Realm service unavailable. Shutdown already awaits `kernel.stop()` and collects its rejection; the kernel must actually propagate owner-drain failures for this to cover them. |

These changes remain inside the existing approved owner/lifecycle work. Neither
the ten-piece provider ledger nor frozen 16-field app dependency/host wire shapes change.
Next is the genuine owner-only write path with pre-mutation invalidation, followed
by attach-before-read observation and controlled client isolation. First Shard
was not scanned; the accepted GPU slice and separate browser crash are unchanged.

##### Remaining provider integration and flat construction ledger

Sources: `webgpu-os/kernel/realm/RealmGpuAllocationCohortCore.js`;
`webgpu-os/kernel/realm/RealmOwnerCoupledGpuPresentationPort.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationSyscallAdapter.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmGpuPresentationPortContract.js`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticGpuPresenter.js`;
`webgpu-os/kernel/GpuDeviceBroker.js`.

This is deliberately not an incomplete six-field owner handle. Activation
child registration, transfer, and unregistration still require the genuine
activation service, retained per-operator/Realm selection fence, preallocated
single-use tuple receipt slots, and exact terminal resource evidence. No child
methods or process port discriminator are introduced. Full provider registration,
host isolation, first-person traversal, Operations View, and first frame remain
unaccepted. (Sources:
`webgpu-os/kernel/realm/RealmProcessOwnerIdentityAuthority.js`;
`webgpu-os/kernel/realm/RealmLifecycleAllocationAuthority.js`.)

The integration scan also distinguishes reusable mechanisms from missing
authority. `OperatorContext` synchronously invalidates the old generation and
emits `operator:changing` before asynchronous freeze/drain. Its raw events must
be translated to the closed B4A/B4F invalidation records, never forwarded.
`RealmOsLifecycleAdapter` consumes lifecycle allocation/retirement but is not
the genuine owner required by piece 9. StorageManager notifications are not an
atomic head snapshot/subscription protocol. Piece 3 therefore still needs
coherent lifecycle binding and pre-change invalidation, not polling or no-op
subscriptions. (Sources: `webgpu-os/kernel/OperatorContext.js`;
`webgpu-os/apps/the-virtual-realm/runtime/RealmOsLifecycleAdapter.js`;
`webgpu-os/storage/StorageManager.js`.)

The participant continuation must also preserve real OS ownership boundaries.
`OperatorContext.registerParticipant()` is boot-time registration, not a runtime
per-app API; `onChange()` invalidation alone does not make switching await Realm
cleanup. Desktop sends suspension directly to an app instance for window and
document conditions; generic visibility events omit per-window minimization.
Generic GPU event-bus messages cannot authenticate a particular owner. A genuine
host callback bridge must connect those sources to the private identity lookup
and queued intents before the full lifecycle port can be accepted. Existing
Entry suspend/resume handling preserves ownership but does not yet pause a real
renderer. (Sources: `webgpu-os/kernel/OperatorContext.js`;
`webgpu-os/shell/Desktop.js`; `webgpu-os/apps/the-virtual-realm/VirtualRealmEntry.js`.)

The existing `PackageHostRealm` supplies an opaque-origin iframe primitive, but
its current bridge cannot carry the Realm provider: Desktop excludes factory
and GPU-panel paths; the bridge drops subscriptions and uncloneable values,
reflectively dispatches syscalls, and has no dedicated bounded provider channel.
Before activation, isolate the untrusted consumer, define exact bounded
transport with cancellation, real subscription delivery/disposal, and lifetime
revocation, and settle the GPU/renderer placement without exposing raw host
authority or falling back to shared execution. Native OPFS sentinel isolation,
privileged import denial, unknown-message rejection, and cleanup must be tested
in the browser. No such transport or renderer relocation is implemented here.
This remains acceptance work inside pieces 3 and 10, not a new gate or a change
to the frozen sixteen-key dependency record. (Sources:
`webgpu-os/shell/PackageHostRealm.js`; `webgpu-os/shell/Desktop.js`.)

The immediate continuation is the piece-3
[protected-head observation decision](#protected-head-observation-and-writer-ownership-decision).
Do not reopen accepted pipeline-layout work or treat a point-in-time snapshot
as a live subscription. The following rows are ten flat construction pieces.
They are not renamed B4H subgates or nested contract families.

| Piece | Readiness | Required completion |
| --- | --- | --- |
| 1. Protected local-policy head source | Implemented and verified bounded source, reusing the shared transaction helper; B4H remains unaccepted | Keep writes kernel-private and adapt the matching selected Realm's policy head through piece 3. |
| 2. Current-local-Realm and authority-epoch sources | Implemented and verified bounded source: one 4,096-byte per-account selection head with an epoch global across Realm changes | Keep writes private and adapt only the current non-null selection/exact epoch through piece 3; selection grants no ownership or capability. |
| 3. Operator-context and local-policy adapters | Read-only coherent snapshot prerequisite implemented; live adapters, authenticated acquisition, and backend isolation remain unresolved | Reuse `RealmLocalOperatorSnapshotSource` for the private point-in-time join, not a lease. Before activation, establish authenticated acquisition and backend isolation with exact bounded transport. Bind genuine lifecycle/current operator and head epochs into B4A/B4F; missing/cleared selection stays unavailable. Publish pre-change bounded invalidation and real subscriptions without exposing writes. |
| 4. Runtime-activation owner | Missing | Own the active-bundle head, eligibility lifecycle, private handle and CSE verification, activation clock, recovery, and exact active-bake binding required by B4B. |
| 5. Runtime-checkpoint owner | Missing | Own checkpoint-source leases, protected head and root transactions, retention, retirement, and restart recovery required by B4C. |
| 6. Runtime-handoff owner | Missing | Bind the protected handoff head to a verified checkpoint edge, runtime pin, profile, policy, CAS lineage, tombstone, and recovery required by B4D. |
| 7. Action-authority owner | Missing | Mint secure correlations, own replay and result ledgers, reassert current bundle and context immediately before dispatch, and recover partial settlement required by B4E. |
| 8. Production M1C admission sources | Missing production composition | Feed the existing private-bake admission composition with genuine generation-bound storage, content, policy, trust, evidence, quota, selection, and signature sources. Give the app only `bakeAdmissionPort`. |
| 9. Runtime support sources | Durable reservation, session authority, versioned attempt binding, allocation/currentness/retirement owner, genuine private process-owner identity, approved v3 transport, participant notification, genuine lifecycle-port composition, boot-owned operator-switch cleanup tracking, bounded diagnostic clock/logger sources, exact-producer frame accounting, private exact-mount buffer/texture/creation accounting, separate original-surface reservation accounting and retained original-owner teardown authentication are implemented, with a private guarded-frame bridge, weak historical surface receipt/view pairing and a composition-derived genuine-owner companion plus historical original-epoch presentation-result provenance and reentrant GPU-control protection. The separate terminal-cleanup v1 inert wire is accepted; it grants no destruction authority. The private original buffer/texture issuer registry and captured-operation rollback are implemented; their read-only source does not establish Realm lifecycle ownership. The opt-in original B3/lifecycle composition installer authenticates the configured owner before GPU epoch publication. Separate original allocation cohorts now join that genuine owner prospectively to explicit buffer/texture routes, preserving disjoint membership across shared mounts and retained original-root teardown validation. A separate original-only terminal delivery now provides bounded destruction with genuine teardown revalidation, exact cumulative counts, retention draining and explicit unresolved retries. The original-companion core and opt-in pre-acquisition original mount/facade installation now prepare a genuine primary cohort before GPU epoch binding, validate exact configured device returns and preserve retryable private-control retirement; the original B3 capture APIs still require completed acquisition. Early exact stable-port/epoch lookup may expose a paused source, while work checks and allocation remain closed through owner.bound until callback-free acquisition completion; resume cannot reopen an explicit close or terminal seal. The standard adapter now routes opted-in buffer/texture creation through that exact original cohort using a factory-issued syscall namespace and cached original work/facade proof. Its original-only source lookup preserves the actual selected cohort and terminal endpoint; raw post-metadata checks are implemented, with later root-enrolled standard-route cached/after-await checks described below. The exact original stable-port/epoch pair now resolves that epoch's actual selected allocation source before capability admission and after retirement, without current-epoch substitution or a global receipt registry. Original presenter-generation Source1/Token4 provenance now supplies native/private currentness, exact constructor-port identity and historical adopted-receipt evidence, without returning those capabilities or reserving a cohort. The approved separate v4 host carrier and fresh-only protected allocation policy are implemented with original issuer authentication, constructor binding, pre-diagnostic reservation, original request and adopted-receipt evidence, source-global exclusive claims and exact receipt-bound buffer/texture routes. Legacy v1/v2/v3 wires and dependency16 remain unchanged. The exact four-member, five-edge lazy authority module cycle is explicitly guarded and both initial import orders execute. Private original-attempt terminal delivery and retry-safe protected presenter/Entry cleanup are implemented: native teardown-root authentication, historical dispatched-claim binding, unused-predecessor isolation, retained late and unpublished rollback candidates, phased retry, zero-abandonment resource proof, and upstream owner retention on rejection. The root-bound terminal-cleanup path no longer schedules ordinary-job destruction. Root-enrolled standard-route work fencing now binds original constructor-root and pre-dispatch cleanup choice, exact adopted receipt, current owner/mount and unsealed work; it covers facade caches, scoped job/transfer/frame callbacks, nested command access and awaited work returns while retaining late cleanup handles and preserving rootless policy. The approved separate original-cohort WorkView8/Queue3 now carries adopted claim proof into native method lookup, view-local cache publication and nested command/pass operations, with private finished-buffer provenance; both recorded native-getter probes pass. The approved bounded protected-shader profile now snapshots standard fields before native/cache effects; descriptor2, profile42 and genuine-native7 pass in source and both canonical import orders. The protected sampler snapshot is accepted with the explicitly approved installed-native numeric profile; sampler88 and genuine-native8 pass in source and both canonical import orders within the final1175/1175 browser matrix. Its documented WebIDL differences and recorded transient test-transport allowance do not introduce a browser admission rule. The approved binding-layout snapshot is accepted with standard-sequence traversal, a4096-entry conversion cap and explicit experimental-member rejection:126 profile and27 native checks pass in source and both canonical import orders within the fresh1634/1634 browser matrix, with669/669 Python checks across41 literal files. The measured native differences, historical failures and exact reproduction evidence remain documented. The approved pipeline-layout snapshot is accepted with nullable genuine BGL identity, standard traversal, an independent4096-layout cap and full immediateSize conversion:43 profile and64 native checks pass in source and both canonical import orders within1955/1955 browser executions, with693/693 Python checks. All28 original revoking native witnesses now prevent entry, creation and publication. The documented cross-frame/foreign-device crash remains unresolved. Other native conversion families remain separate. Full process-owner authority and genuine resource telemetry remain missing. | Preserve terminal registration identity, actual mount/cleanup ownership and queued same-generation notifications without treating acceptance as teardown completion. Prove full-provider Entry teardown; supply activation-authorized child ownership and restart reconciliation. Preserve the verified protected-startup slice without treating buffer/texture exclusion as full GPU-effect isolation. Preserve irreversible post-dispatch claims, retained late candidates and release only proven unused pre-dispatch reservations. Never promote old cohorts or reopen terminal seals. Preserve the private terminal channel, explicit failed/late-handle retries and root-enrolled standard-route fences without treating them as full GPU-effect isolation. Preserve the accepted original-cohort native work view without a supplied-authorizer shortcut or shared-facade policy contamination. Preserve the accepted shader/sampler/binding-layout profiles and strict native comparisons. The pipeline-layout review demonstrates28 post-revocation native effects in a separate62-case diagnostic (34 passed,28 failed); original63/group5 browser crashes remain unresolved, not passing evidence. The user has explicitly approved standard iterator traversal, an independent4096-element conversion cap and full standard immediateSize conversion. Preserve the accepted eight-piece protected snapshot and its exact native/structural regressions; this does not accept other native argument/return families or provider activation. Preserve native BGL identity without inferring device or Realm ownership. Keep remaining native argument families and native-return/thenable conversion separate. Shader and sampler conversion do not prove those boundaries. Cover raw resource children/mapped memory and authentic frame readiness separately; owned allocation routing alone is not full renderer integration. Prove the host-selected mount belongs to the full provider and complete native effect-time owner checks beyond the reviewed standard routes/callbacks; complete retained late-result cleanup, exact per-owner attribution across shared-mount epochs, selected-Realm/activation identity, late source attachment and reviewed missing-family coverage, then acquire genuine telemetry/full process-owner ports with reverse retryable cleanup. Keep telemetry teardown distinct from bounded original-cohort destruction retries, and add authentic loss evidence before claiming abandonment. Retain diagnostics until Entry and reverse-source teardown finish. |
| 10. Full provider, registration, and evidence | Missing | Prove both authenticated acquisition and enforced backend isolation from piece 3; tokens, same-origin workers, and import allowlists alone are insufficient. Atomically capture one operator, Realm, epoch, profile, and bake binding; acquire pieces 3–9; reuse B4G; call B3; register one opener at boot; and prove every-await failure cleanup, concurrent and retry cleanup, operator and device invalidation, secret non-disclosure, exact 16-key output, no writer leakage, and the real M1C-to-first-submitted-frame route. |

No unavailable or look-alike provider counts as B4H progress. Historical
first-source evidence passed 24/24 policy-head browser cases over real OPFS and
injected failures, 24/24 shared private-service storage cases, and 9/9 Python
checks with zero browser failures or skips. That 48-browser-plus-9-Python
subtotal certifies only the earlier source boundary and preserves B4G's
historical 352/352 core browser count, 371/371 count including transport, and
72/72 Python count. The earlier policy source had a 45-module standalone closure.

The earlier continuation regression sweep passed 502/502 browser cases with no
failures or skips: B4A-B4G/runtime/factory/Desktop 371, Entry 25, policy
source/storage 48, private publication 21, admission codecs 15, and M1C handoff
22. Its scoped Python group passed 81/81, including the nine policy-source
checks. These historical receipts do not certify subsequent changes.

The selection-source continuation recorded 32/32 selection browser cases, the preserved
24/24 policy cases after extraction, and 24/24 shared private-service storage
cases: 80/80 total, with zero failures or skips. Focused policy/selection Python
checks passed 18/18, a subset of its 90/90 scoped Python regression receipt
after source hardening.
Both browser source gates share `RealmProtectedHeadTestFixtures.js` for genuine
protected OPFS and separately injected fault paths. The selection gate includes
an exact golden storage SHA and same-error-class sibling diagnostic forgery
rejection. Measured acyclic closures contain 44 modules for the shared helper,
45 for selection, and 46 for policy, with no graph errors. Entry and B3
composition remain unchanged at 106 and 48 modules and cannot reach the sources.
That continuation's browser regression sweep passed 534/534 distinct cases with zero
failures or skips: B4A-B4G/runtime/factory/Desktop 371, Entry 25,
source/storage 80, private publication 21, admission codecs 15, and M1C handoff
22. The selection and policy receipts include the latest hostile-input and
scope-fence checks. This source and regression evidence does not accept the full
provider or a physical frame.
Broad discovery generation remains deferred to preserve the First Shard
exclusion and concurrent task ownership.

The subsequent snapshot-source continuation passes 24/24 new browser cases,
32/32 selection, 24/24 policy, and 24/24 shared storage cases: 104/104 focused
source/storage checks. The real Kernel operator-context suite adds 9/9 distinct
cases, for 113/113 browser checks in this continuation, with no failures or
skips. The earlier entire 534-case matrix was not rerun or mechanically added
to that subtotal. The new snapshot Python proof passes 10/10; all three source
proofs total 28/28 within the freshly passing wider 100/100 Python group.
The new source has exactly 49 acyclic modules, zero graph errors, and remains
absent from unchanged Entry106 and B3-composition48 closures. The browser gate
proves real OPFS reopen and account/Realm isolation, no writes or subscriptions,
operator/abort fencing, malformed/corrupt input rejection, missing-policy
selection reassertion, ABA/authority-advance rejection, and the valid older P1
cut when policy changes after capture. No live authority is inferred from those
results. (Sources: `tests/virtual-realm/m2-local-operator-snapshot-source.test.js`;
`tests/virtual-realm/test_m2db4h_local_operator_snapshot_source.py`;
`tests/webgpu-os-operator-context.test.js`.)

The reserved-generation continuation passes 32/32 new browser cases, including
the final strengthened rerun, plus 24/24 shared storage, 24/24 policy, 32/32
selection, and 24/24 snapshot cases: 136/136 distinct browser checks, zero
failures or skips. The new gate has zero console errors. Its ten Python proofs
bring the scoped B4/Entry/B3/renderer/source group to 110/110. The source has
exactly 45 acyclic modules; helper44, Entry106, and B3-composition48 remain
unchanged. Evidence covers real OPFS allocation/reopen/fresh scope/account and
app separation, concurrent winner/loser recovery, same-owner write exclusion,
uncertain committed and uncommitted writes, consumed-generation gaps,
intervening heads, stale reads, scope/abort fences, malformed bytes, exhaustion,
redacted diagnostics, and the closed service grammar. Independent Python
vectors pin canonical first/successor heads, byte lengths, service token, and
app path hash. Source/view reconstruction is tested; a forced browser-process
crash, storage eviction, restored-profile rollback, and full live lifecycle
recovery are not claimed by these receipts. No earlier full browser matrix is
mechanically included in this subtotal. (Sources:
`tests/virtual-realm/m2-lifecycle-generation-head-storage.test.js`;
`tests/virtual-realm/test_m2db4h_lifecycle_generation_head_storage.py`.)

The lifecycle-session continuation passes 32/32 new browser cases after the
final concurrent-issuance and post-hash fencing expansion. The freshly rerun
generation32, shared-storage24, policy24, selection32, and snapshot24 suites
bring this continuation to **168/168 distinct browser cases**, zero failures,
skips, or console errors. The new independent Python gate passes 10/10 within
the freshly passing **120/120** scoped B4/Entry/B3/renderer/source group. Its
acyclic closure is exactly 47 modules; counter45, Entry106, and B3-composition48
remain unchanged, with no new kernel source reachable from Entry/B3.

The browser evidence covers real OPFS issuance/reopen/account/app separation,
simultaneous factory reservations and safe retry, overlapping live sessions,
operator A-to-B-to-A, immediate scope/work/teardown revocation, listener cleanup,
authentic receiver and exact-signal checks, storage-free synchronous retirement,
same-object idempotence, malformed/exhausted heads, uncertain committed and
uncommitted allocation, receipt-hash failure, and both signal/scope fences after
hash completion. Independent Python vectors pin the exact 325-byte first
terminal record and SHA, then vary every owner/allocation binding. Reopening
sources is tested, not forced browser-process death or cross-process terminal
recovery. No historical full browser matrix is added to these measured counts.
All eight edited curated documents passed scoped metadata, H1, relative-target,
and hygiene checks; broad discovery generation remains deferred for the First
Shard exclusion and concurrent task ownership. (Sources:
`tests/virtual-realm/m2-lifecycle-session-authority.test.js`;
`tests/virtual-realm/test_m2db4h_lifecycle_session_authority.py`.)

The approved host-attempt continuation passes **32/32** new browser cases,
including the final reentrant bind/capture closure, standard rejected Promise
with trapping own `then`/`catch`, and malformed v2 lease cleanup assertions.
Real protected OPFS cases use the actual Entry allocation call to issue fresh
session generations, stop and restart, and prove no reservation when stopped
during inspection. Other lifecycle/owner/admission ports in that bounded test
composition remain explicit fixtures, not a genuine full provider. Desktop's
existing gate adds one forwarding case and now passes 9/9; it does not invoke
the binding or add a dependency key.

Freshly rerun suites are attempt32, runtime30, Entry25, factory11, Desktop9,
B3-composition11, session32, generation32, snapshot24, policy24, selection32,
and shared-storage24: **286/286 distinct browser cases**, zero failures, skips,
or console errors. The new independent Python gate passes 10/10 within the
**130/130** scoped B4/Entry/B3/renderer/source group. Controller and registry
each have an exact acyclic two-module closure with the existing leaf validator;
the leaf is one module. Entry106 and B3-composition48 remain unchanged and cannot
import the kernel controller, counter, or session source. No old browser totals
are mechanically added. Eight edited curated pages pass bounded metadata,
single-H1, relative-target, and hygiene checks. Broad discovery generation and
full release bundling remain deferred for the First Shard exclusion and
concurrent task ownership. These receipts accept the explicit host rendezvous,
not a full provider, process owner, activation owner, or visible city. (Sources:
`tests/virtual-realm/m2-runtime-attempt-binding.test.js`;
`tests/virtual-realm/m2-desktop-terminal-factory.test.js`;
`tests/virtual-realm/test_m2db4h_runtime_attempt_binding.py`.)

The allocation-owner continuation passes **32/32** new browser cases. The real
Entry fixture assigns the production allocation/currentness/retirement methods
directly, retaining fixtures only for the explicitly unfinished ports. Real
protected OPFS proves lazy first allocation, generation-2 restart, independent
overlapping authorities, and no reservation when stopped during inspection.
Fault cases cover shared pending allocation, committed/uncommitted gaps, wrong
scopes and roots, direct/copy/foreign retirement handles, post-switch retirement
without I/O, reentrant closure, premature teardown quarantine, and cancellation
after genuine session issuance at the final Promise-adoption boundary.

The final-delivery test is mutation-verified: temporarily removing only that
completion fence produces the expected case-27 failure because allocation is
delivered instead of rejected. Restoring the source reproduces its exact
pre-mutation SHA-256 and restores 32/32 passing cases. The controlled failing run
is test-quality evidence, not included in the passing subtotal.

The fresh passing matrix is allocation32, attempt32, session32, generation32,
snapshot24, policy24, selection32, shared-storage24, Entry25, runtime30,
factory11, Desktop9, and B3-composition11: **318/318 distinct browser cases**,
zero final failures, skips, or console errors. The new Python gate passes 10/10
within **140/140** scoped checks. The trusted allocation source has an exact
acyclic 49-module closure; Entry106 and B3-composition48 are unchanged and cannot
reach it. Eight curated pages and the six changed source/test files pass bounded
metadata/link/text and SPDX checks as applicable. First Shard scans, broad
discovery generation, and full release bundling remain excluded or deferred.
This evidence accepts the allocation-owner slice only, not participant authority,
the complete lifecycle/provider, process-owner cleanup, durable recovery, or a
rendered city. (Sources:
`tests/virtual-realm/m2-lifecycle-allocation-authority.test.js`;
`tests/virtual-realm/test_m2db4h_lifecycle_allocation_authority.py`.)

The identity continuation passes **34/34 new browser cases**. The final genuine
scope-callback tests reproduced two pre-fix publication failures: a competing
authority could claim the same allocation during final validation, or that
callback could close the still-empty authority before publication. Acquisition
now rechecks closure and existing ownership after final currentness, immediately
before the no-callback claim/publication interval. Cross-source reentry rejects;
same-source reentry returns the already issued handle. The fixed gate passes
34/34 with no console errors. These pre-fix failures demonstrate regression
sensitivity and are not counted as passing evidence.

The fresh fourteen-suite matrix passes **352/352 browser cases**: identity34
plus allocation32, attempt32, session32, generation32, snapshot24, policy24,
selection32, shared-storage24, Entry25, runtime30, factory11, Desktop9, and
B3-composition11. All final runs have zero failures, skips, or console errors.
The independent identity Python gate is **12/12**, within **152/152** scoped
checks. The identity source's trusted acyclic closure is exactly 50 modules;
allocation49, Entry106, and B3-composition48 remain unchanged. Three curated
pages pass metadata, fence, whitespace, and 65 relative-target checks. No full
release bundle or broad documentation discovery was regenerated. This evidence
accepts only the private identity prerequisite; activation-child ownership,
authentic participant callbacks, full ports/provider, recovery, and a visible
city remain unaccepted. (Sources:
`tests/virtual-realm/m2-process-owner-identity-authority.test.js`;
`tests/virtual-realm/test_m2db4h_process_owner_identity_authority.py`.)

The approved host-channel continuation passes **36/36 new browser cases** and
the extended real Desktop transport gate passes **17/17**, preserving its nine
earlier cases. The fifteen-suite fresh matrix passes **396/396 browser cases**:
host-channel36, Desktop17, identity34, allocation32, attempt32, session32,
generation32, snapshot24, policy24, selection32, shared-storage24, Entry25,
runtime30, factory11, and B3-composition11. Final runs have zero failures, skips,
or console errors. The independent host-channel Python gate passes **12/12**,
within **164/164** scoped checks. The channel closure is exactly two modules and
the registry closure exactly three; Entry106, B3-composition48, dependency16,
M0/M1C109, and M2's 11-definition/13-module catalog remain unchanged.

Hostile cases cover strict records and captured receivers, bounded pending work,
queued cancellation, thrown and returned native Promise rejection, malformed
receipts, source reentry into its own retirement or registry close, raw-close
retry, quarantine, and immediate destruction fencing while another open remains
held. Desktop covers held-mount graceful and forced close, stale old-mount
cleanup, notification failure followed by delegate/raw-close retries, suspension
coalescing, and genuine logical coordinator loss after a rejected ready-state
spoof. GPU tests use a genuine coordinator over an explicitly injected low-level
device fixture, not physical GPU loss. Registry and Desktop authority sources
remain explicitly transport-only fixtures, not genuine full providers.

Review found and corrected early fencing behind pending opens, thrown-Promise
rejection consumption, acknowledgement-based GPU retry, and prompt graceful and
forced close before factory settlement. Initial Desktop test-only failures were
an assertion against an absent `cleanup.app` and a microtask-only wait that
starved IndexedDB; both were corrected before final passing runs. Earlier
failures are not included in passing totals. Three curated plan pages were
updated with scoped metadata/link/text checks; full release bundling and broad
documentation discovery remain deferred. No First Shard content was scanned.
This evidence accepts host-only notification transport within piece 9, not
authentic participant delivery, operator-switch teardown drain, process-owner
child cleanup, provider isolation, full B4H, or the physical visible city.
(Sources: `tests/virtual-realm/m2-runtime-host-lifecycle.test.js`;
`tests/virtual-realm/m2-desktop-terminal-factory.test.js`;
`tests/virtual-realm/test_m2db4h_runtime_host_lifecycle.py`;
`tests/virtual-realm/test_m2db4h_runtime_attempt_binding.py`.)

The genuine participant continuation passes **40/40 new browser cases**. The
fresh sixteen-suite matrix passes **436/436 browser cases**: participant40 plus
host-channel36, Desktop17, identity34, allocation32, attempt32, session32,
generation32, snapshot24, policy24, selection32, shared-storage24, Entry25,
runtime30, factory11, and B3-composition11. Final runs have zero failures, skips,
or console errors. The new independent Python gate passes **16/16**, within
**180/180** scoped checks. Exact trusted closures are participant51, identity50,
and allocation49; Entry106, B3-composition48, dependency16 and the frozen
M0/M1C109 and M2 11-definition/13-module catalogs remain unchanged.

The browser gate uses genuine allocation, identity and operator sources, the
actual `RealmOsLifecycleAdapter`, the accepted v3 channel wrapper, and a real
protected OPFS case. It does not manufacture a complete process-owner port.
Cases cover mutable-wire capture, private provenance, native work roots,
once-per-owner claims, currentness reentry, suspension coalescing, early terminal
latching, original-operator invalidation after work abort, no-I/O terminal
delivery, authentic disposal, and listener closure. Callback tests include
fresh rejected Promises without a test-side rejection sink, arbitrary thenables,
unresolved Promises, throwing diagnostics, and returning the participant's own
disposal Promise. None becomes a teardown dependency.

Independent review found and corrected source-close ordering around unsubscribe
and diagnostic failure poisoning suspension completion. The close-fence test is
mutation-verified: moving the closed fence after unsubscribe produces exactly
the case-38 failure, with 39 passing cases, because reentrant registration is
not rejected. Restoring the source reproduces its original SHA-256 and restores
40/40 passing cases, including strengthened final-currentness closure and raw
callback-rejection tests. The controlled failing run is sensitivity evidence,
not part of the passing count. Three curated plan pages and scoped source/test
hygiene checks are updated without broad generators or First Shard scanning.
These receipts accept the participant source, not full lifecycle-port/provider
composition, operator-switch teardown drain, child ownership, isolated host
acquisition, recovery, renderer pause, or a physical visible city. (Sources:
`tests/virtual-realm/m2-lifecycle-participant-authority.test.js`;
`tests/virtual-realm/test_m2db4h_lifecycle_participant_authority.py`;
`tests/virtual-realm/test_m2db4h_process_owner_identity_authority.py`;
`tests/virtual-realm/test_m2db4h_lifecycle_allocation_authority.py`.)

The lifecycle-port composition continuation passes **37/37 new browser cases**.
Its freshly rerun eleven-suite group totals **305/305 distinct browser cases**:
composition37, participant40, identity34, allocation32, host-channel36,
Desktop17, attempt32, Entry25, runtime30, factory11 and B3-composition11.
Every final run has zero failures, skips and console errors. The earlier
participant continuation's wider 436-case browser group is historical; its
remaining six source/storage suites were not rerun or added to this subtotal.
The new independent Python gate passes **16/16**, and the complete scoped
Python regression group passes **196/196**. The trusted composition closure is
exactly52 acyclic modules, retaining participant51, identity50, allocation49,
Entry106 and B3-composition48. The three previously accepted authority sources
are byte-identical to the previous continuation.

The new gate verifies exact options and port shapes, genuine source provenance,
zero-I/O construction, failed subscription cleanup, existing mutable requests,
shared allocation promises, authentic identities/participants, partial-close
prerequisites, retained close phases, teardown-live refusal, cleanup-only
retirement/observation, and rejection of new attempts during closure. It also
exercises late-issued and construction-aborted allocations, original-operator
switching, separate overlapping compositions, real protected OPFS, and the
actual adapter with the approved v3 channel. No complete process-owner port is
fabricated for this evidence.

Reentry checks cover request reflection, genuine currentness hooks, newly issued
owner handles, participant publication, unsubscribe, and throwing diagnostics.
Temporarily removing only the synchronous operation-depth close guard yields
30 passing and seven failing cases, exactly23–28 and36. Restoring the source
reproduces SHA-256
`CDA0BA1CE61A78D99F50323CE27B655E8DDD71A2AAB3F08A26AAD1FF3BB1D650`
and a fresh37/37 passing gate. That controlled failure is mutation-sensitivity
evidence, not part of the passing total. Independent production and documentation
reviews report no remaining actionable finding. This accepts the composed
lifecycle port and owned source closure only, not boot-owned transition drain,
full process ownership, provider installation/isolation, recovery or rendering.
(Sources: `tests/virtual-realm/m2-lifecycle-port-composition.test.js`;
`tests/virtual-realm/test_m2db4h_lifecycle_port_composition.py`;
`webgpu-os/kernel/realm/RealmLifecyclePortComposition.js`.)

The operator-transition cleanup continuation passes **18/18 new Desktop and
OperatorContext browser cases** and **14/14 new registry cases**. Its fresh
thirteen-suite group totals **337/337 distinct browser cases**: operator-drain18,
open-retirement14, composition37, participant40, identity34, allocation32,
host-channel36, Desktop17, attempt32, Entry25, runtime30, factory11 and
B3-composition11. All final runs have zero failures, skips and console errors.
The new source/confinement Python gate passes **16/16**; the complete scoped
Python group passes **212/212**. An existing nonfailing requests dependency
warning is unchanged. Earlier wider matrices are historical and not added to
this subtotal.

The new gates exercise pending opens, rejected and late factory results,
malformed-lease quarantine, persistent delegate/lease failures, cleanup retry
after process removal, same-app attempt replacement, A-to-B-to-C supersession,
lock, recovery, concurrent drains, generic forced-close compatibility, and
later-operator relaunch. A held-readiness case resolves and rejects readiness
after delegate and lease cleanup finish; neither permits early activation.
Direct registry tests cover exact-object authentication without property reads,
pending and concurrent opens, shared receipts, request isolation, validation
reentry, signal-read reentry, and normal/manual/destruction cleanup overlap.

Independent audit found a genuine pre-admission cleanup obstruction: Desktop
retained retirement before `open`, but a destroyed-registry rejection had no
original-request owner. The corrected registry retains cleanup-only identity
before validation or destroyed-state checks. A failed startup can now retire
its actual empty obligation without granting authority. Dedicated browser cases
cover both the direct registry boundary and a real operator switch after the
failed launch. The final audit reports no remaining actionable source finding.
An initial readiness-test defect used a resolve-only test helper as though it
also exposed rejection. The corrected test uses a controlled resolved sentinel
to produce the rejection; production code did not change for that test defect.

An isolated HTTP server served a single deliberately bypassed drain module
without writing repository files. The resulting gate passed4 and failed14,
exactly cases1-10,13-15 and18, because cleanup or mount settlement no longer
blocked transition completion. The unchanged production module then passed
all18 cases with no console errors. The controlled failures are sensitivity
evidence, not part of the passing total. The temporary server exited normally.

Trusted import closures remain exactly2 modules for the drain helper and3 for
the registry; only those closures are walked, not the broad Desktop or boot
graphs. Entry106, B3-composition48, lifecycle composition52, dependency16 and
frozen M0-M1C109/M2 catalog11/13 boundaries are preserved. The source ledger and
two existing flat ten-piece plan tables are updated. Broad generators and a
full OS release bundle are deliberately deferred; this is not a release build
or full-provider acceptance receipt.
(Sources: `tests/virtual-realm/m2-operator-transition-drain.test.js`;
`tests/virtual-realm/m2-runtime-open-retirement.test.js`;
`tests/virtual-realm/test_m2db4h_operator_transition_drain.py`;
`webgpu-os/shell/desktop/RealmOperatorMountDrain.js`;
`webgpu-os/kernel/AppRuntimeCompositionRegistry.js`.)

The diagnostics continuation passes **32/32 new browser cases**. Eight freshly
rerun adjacent suites pass runtime 30, Entry 25, B3-composition 11, factory 11,
attempt-binding 32, operator-drain 18, original-open-retirement 14, and lifecycle-
composition 37. The distinct nine-suite subtotal is **210/210**, with zero final
failures, skips, or console errors. Earlier wider browser totals are historical,
not added to this subtotal. The scoped 23-file Python regression passes
**229/229**, including the new 17-check diagnostic gate. That new gate was rerun
after the final comment-only clarification and again passes 17/17.

The browser gate tests all 21 event names across four levels; exact wires,
source capture, monotonic validation, fixed metadata projection, hostile
reflection, native rejected Promises, arbitrary thenables, recursive calls,
and closure fences. It also exercises the real `RealmRuntimeLifecycle` through
stop with normal and failing sinks, native browser time bounds, and readback
from the existing OS logger without clearing logs.

Two separate read-only HTTP probes leave repository source unchanged. One
instruments only the initial local counter to one below uint64 maximum; six
assertions verify maximum emission, three repeated exhaustion failures,
independent measurement, and terminal close. This is instrumented branch
evidence, not a seeded production API or six additional acceptance cases. The
other removes only the rollback rejection guard from the served source: the
32-case gate becomes 31 pass/1 fail, with case 09 detecting the defect. The final
unmodified-source run returns 32/32. The temporary server exits normally and
leaves no files.

The diagnostic source and native adapter have exact closures of 29 and 30
modules. Entry 106, B3-composition 48, and dependency 16 are unchanged. The prior
operator-drain, registry, and lifecycle-composition source hashes match their
previous accepted values. Independent source review found no remaining
actionable counterexample; documentation review clarified source-instance
ordering, native measurement provenance, and shared logger ownership. Scoped
source/test hygiene and curated-document checks pass. Broad discovery
generation and the full OS bundle remain deferred; no First Shard inventory or
source access was performed during this diagnostic continuation.
(Sources: `tests/virtual-realm/m2-runtime-diagnostics-source.test.js`;
`tests/virtual-realm/m2-runtime-diagnostics-source.main.js`;
`tests/virtual-realm/test_m2db4h_runtime_diagnostics_source.py`;
`webgpu-os/kernel/realm/RealmRuntimeDiagnosticsSource.js`;
`webgpu-os/kernel/realm/RealmBrowserRuntimeDiagnosticsSource.js`.)

B4H must still route a genuine M1C admission through stage, materialize, plan,
compile, present, and the first submitted frame. That submitted frame is not the
separate physical non-black visible-city acceptance gate. The physical frame,
first-person controller, Operations View, minimap, visible bundle swap, and
integrated M2 remain unaccepted. The First Shard remains excluded from scans,
imports, tests, and broad generators. (Sources:
`webgpu-os/kernel/realm/RealmLocalOperatorPolicyHeadStorage.js`;
`webgpu-os/kernel/realm/RealmLocalSelectionHeadStorage.js`;
`webgpu-os/kernel/realm/RealmProtectedHeadStorage.js`;
`webgpu-os/kernel/OperatorPrivateServiceStorageView.js`;
`tests/virtual-realm/m2-local-operator-policy-head-storage.test.js`;
`tests/virtual-realm/m2-local-selection-head-storage.test.js`;
`tests/virtual-realm/RealmProtectedHeadTestFixtures.js`;
`tests/virtual-realm/m2-private-service-storage.test.js`;
`tests/virtual-realm/test_m2db4h_local_operator_policy_head_storage.py`;
`tests/virtual-realm/test_m2db4h_local_selection_head_storage.py`.)

## M2E: grounded first-person traversal

### Build

- Implement a separate first-person policy and controller.
- Add grounded capsule collision, steps, slopes, head clearance, doors, gates,
  platforms, and collision-safe recovery anchors.
- Add pointer lock, keyboard, mouse, gamepad, focus ownership, and reduced-motion
  policy.
- Add stable object focus, picking, safe text, and read-only inspection.
- Add spatial audio listener and semantic captions.

### Gate

- No traversal path reaches third person, orbit, free flight, director, debug
  camera, detached map, or remote overview.
- Movement cannot penetrate collision, cross a closed gate, or use an unloaded
  navigation cell.
- Pointer-lock escape restores focus and never traps required input.
- Device loss, window blur, bake replacement, and controller disposal preserve
  or restore one verified safe anchor.
- Every required first-person action works without relying on color or audio.

### Rollback

Return to a noninteractive static scene viewer; no alternate traversal camera is
enabled.

## M2F: owner-private Operations View and minimap

### Build

- Validate `LocalOperatorViewPolicyV1` and the current local authority.
- Derive one closed snapshot from the accepted private bake, layout receipt,
  admitted loaded cells, and local lookup.
- Implement bounded isometric/eagle-eye framing, local pan/zoom/focus, and local
  minimap from the same snapshot.
- Add local selection and powerless zone proposals.
- Implement frame-barrier entry and deterministic first-person restoration.

### Gate

- Entry is explicit local input and cannot be triggered by Storylets, links,
  station events, or remote data.
- The snapshot schema has only `localRealmId`; no foreign or viewed Realm field
  exists.
- Public shells, presence, rendezvous, bridges, remote Travelers, remote routes,
  remote object IDs, and remote telemetry are structurally unaddressable.
- Selection and focus are presentation-only.
- Revocation, identity change, policy change, bake change, device loss, and exit
  destroy view resources once and restore a safe first-person anchor.

### Rollback

Disable Operations View independently; grounded first-person remains usable.

## M2G: read-only interaction and proposal path

### Next independent build: plan-bound city inspection

This independent CPU implementation is built and verified while the
[pipeline candidate](#approved-pipeline-layout-implementation) remains
unverified. It is a CPU-only prerequisite inside the existing M2G scope, not
another milestone, an alternate renderer, or acceptance of integrated M2G.
It makes the real compiled city's semantics inspectable before live picking
is connected. It does not move M2E traversal or M2F Operations View to complete.

The reuse scan found the required data already exists:

- The private `buildObjectAndSemanticRecords()` function in `RealmSceneAssembler.js` emits dense plan-local
  `objectIdBindings` and exactly matched `object-role` semantic records.
- `admitRealmStaticRenderPlan()` validates the schema, semantic closure, and
  canonical digest. This is data admission, not active-city or operator authority.
- Bindings explicitly distinguish `stable-object` from `payload-element`.
  Only stable objects carry stable object IDs and presentation slot identity.
  A station box or road element must not acquire a fabricated filesystem ID.
- `runtime/RealmInteractionResolver.js`, absent at the planning checkpoint, now
  implements this independent peer rather than another scene compiler.

Sources: `webgpu-os/apps/the-virtual-realm/rendering/RealmSceneAssembler.js`;
`webgpu-os/apps/the-virtual-realm/rendering/RealmStaticRenderPlanContract.js`.

The following four flat pieces preserve the original bounded build criteria.
The implemented API and current verification state follow the table; acceptance
requires measured evidence, not the existence of the files alone.

| Piece | File and work | Completion evidence |
| --- | --- | --- |
| 1. Local input and output shape | Add the already planned `runtime/RealmInteractionResolver.js`. Use existing static-runtime value validation helpers; admit one supplied render plan, bind all queries/results to its exact `renderPlanDigest` and `lifecycleGeneration`, and require a positive integer `objectId`. Keep the validation local; do not extend frozen M0/M1C catalogs or the sixteen app dependencies. | Invalid records and mismatched plan/generation are rejected. ID zero is not a city object; the later pick adapter must handle background separately. A numerically equal object ID from another plan cannot silently resolve in this plan. |
| 2. Deterministic semantic lookup | Join existing object bindings and `object-role` records once. Return an immutable, exact summary containing the requested binding, `sourceKind`, `renderIdentityKey`, and `semanticRole`; include `stableObjectId`, `presentationSlotId`, and `presentationSlotGeneration` only for `stable-object`. A valid but absent ID returns an explicit `not-found` result. | Every object resolves to the matching existing semantic record. `payload-element` never claims stable-object or slot identity. No geometry, canonical plan, ECS state, or source store is modified. Repeated lookups produce identical values. |
| 3. Independent lifetime and diagnostics | Keep construction abortable around asynchronous plan admission, with no retained index on failure. Use idempotent disposal and reject later queries. Reuse bounded project diagnostics for preparation, readiness, cancellation, failure, and disposal; log counts/status, not the plan or source data. | Abort before and during admission leaves no usable resolver. Disposal clears retained plan/index references and is safe twice. Returned summaries remain immutable values, never resource or authority handles. No callback silently substitutes an active-generation claim. |
| 4. Focused verification | Add proposed `tests/virtual-realm/m2-read-only-inspection.test.js`, its matching browser HTML/main entry, and `test_m2_read_only_inspection.py`. Reuse the M2D-A fixture setup and existing contract admission; add independent mapping expectations rather than another bake generator. Inspect and bind only the exact needed import closure before running it. | Positive stable-object and payload-element mappings, absent ID, zero/invalid ID, changed digest/generation, duplicate/mismatched semantics, immutable output, concurrent preparation, cancellation and disposal pass. Record actual counts and source bindings after execution; no predicted pass total. |

The exact request/result shape is now finalized locally in the resolver. It
does not copy entire binding/semantic records indiscriminately.
The first result contains only the fields listed above plus its status and
plan/generation/object binding; resource payloads, filesystem paths, readable
code, glyph content, safe-text bodies, ECS entity handles, GPU handles, and
live objects are not included. The listed presentation-slot identifiers are
inert plan data, not those handles.
Source-backed names or text can be a later explicit store join, not invented
labels. `glyph-style-only` and `projection-role-binding` are not object picks.

Construction consumes the supplied admitted data only: no filesystem scan,
network request, storage access, RealmForge runtime import, GPU allocation,
frame submission, camera creation, or input registration. Keep this peer
unwired to `VirtualRealmEntry`, `RealmStaticGpuPresenter`, action dispatch,
Operations View, and SecureMesh. No synthetic provider or dummy city is allowed.

Live integration still requires the accepted full M2D path, a real identity
attachment pick, current active-bake/generation checks, and the existing M2G
inspection policy. This preparatory resolver is not evidence that a selected
object is currently visible, reachable, accessible, or authorized for action.
Rollback is disposal of this independent CPU peer; the admitted bake, static
plan, draw packets, existing app behavior, and pending pipeline work remain
unchanged. First Shard remains excluded from both the build and its tests.

**Implemented API:** `RealmInteractionResolver` is the module's only export.
Its constructor accepts an optional diagnostic `logger` and no source/service
injection. It exposes three operations:

| Operation | Exact data and behavior |
| --- | --- |
| `prepare({renderPlan, signal})` | Asynchronously re-admits the plan and builds the semantic index. Returns frozen `status: "ready"`, `executionClass: "cpu-inspection-only"`, `renderPlanDigest`, `lifecycleGeneration`, and `objectCount`. |
| `inspect({renderPlanDigest, lifecycleGeneration, objectId})` | Synchronous lookup bound to the exact admitted digest and generation. Returns frozen `status`, digest, generation, and object ID. A resolved result additionally has `sourceKind`, `renderIdentityKey`, and `semanticRole`; only `stable-object` adds `stableObjectId`, `presentationSlotId`, and `presentationSlotGeneration`. A valid absent ID has `status: "not-found"` and no additional fields. |
| `dispose()` | Clears the retained summaries/readiness and logger; returns frozen `{disposed: true}`. Repeated calls return the same receipt. Disposal is permanent, including during pending preparation. |

Preparation and query records may be mutable plain data records, matching the
existing CPU compiler convention. Their fields must be exact, enumerable data
properties with defined values; accessors and extra fields are rejected through
`assertM2ExactRecord()`. Preparation snapshots its outer request before awaiting
plan admission. Queries require positive safe-integer IDs; zero/background and
undefined are not absent-object results. Generation remains the plan's canonical
positive uint64 decimal string, never a converted JavaScript number.

The lifetime is `idle` to `preparing` to `ready`, with failure or cancellation
returning to `idle` for retry. Concurrent preparation rejects with
`VR_M2G_INSPECTION_BUSY`; replacement after readiness rejects with
`VR_M2G_INSPECTION_READY`. Any state can be disposed permanently. The supplied
abort signal controls preparation only; aborting it after successful preparation
does not dispose this independent CPU index. The owner must call `dispose()`.

Diagnostics report preparation, readiness, cancellation/failure and disposal
through bounded `virtual-realm.m2g.inspection.*` events. Fields are execution
class, state, object count and elapsed milliseconds; no plan, query, object
identity, source data, or arbitrary error text is logged. Throwing diagnostic
sinks do not alter normal results; disposal/cancellation triggered by a sink
is rechecked before preparation returns.

Example for a caller that already holds the admitted local plan:

```javascript
import { RealmInteractionResolver } from
  './webgpu-os/apps/the-virtual-realm/runtime/RealmInteractionResolver.js';

async function inspectCompiledCityObject(renderPlan, objectId, signal) {
  const resolver = new RealmInteractionResolver();
  try {
    await resolver.prepare({ renderPlan, signal });
    return resolver.inspect({
      renderPlanDigest: renderPlan.renderPlanDigest,
      lifecycleGeneration: renderPlan.lifecycleGeneration,
      objectId,
    });
  } finally {
    resolver.dispose();
  }
}
```

**Bounded acceptance evidence, 2026-09-12:** the new browser suite passed25/25
cases, and the original M2D-A render-plan regression passed30/30. Both ran in
headless Chrome151.0.7922.174 with GPU disabled, zero skips, zero browser errors,
and zero denied requests. The fixture derives a real M1C-backed static plan,
then disposes its assembler, ECS materialization and store before inspection.
Two narrow helper exports in `m2-static-render-plan.test.js` enable reuse; its
existing30 registrations and behavior remain unchanged. A second-generation
test re-admits a modified, re-digested plan; it does not claim another live ECS
generation or active city.

Python structural verification passed12/12 with no failures or skips. It pins
the exact16-module production closure, validates dependency names before file
access, and checks the exact output variants, semantic-join prerequisites,
lifetime ordering and bounded diagnostics. Python does not execute JavaScript;
the browser results supply runtime evidence. The browser fixture's larger
transitive dependency closure contains239 modules and241 served files, all
preloaded before serving with no filesystem fallback. All241 served hashes
were independently compared with current files after the run: zero drift.
First Shard is absent and was not scanned.

Retained evidence:

- Browser receipt:
  `C:/Users/btspa/AppData/Local/Temp/vr-cpu-inspection-check-686afc1602034d73aa2a6095f834333f/cpu-browser-receipt.json`,
  SHA256 `438e0b06925a9240e8ab5326fd480a160779595999075cd6360cead564e7080c`.
- Exact browser hashes and import edges: adjacent `cpu-source-manifest.json`,
  SHA256 `6105cee7b85bca51d5f6a665f51d912a2675468e3ff18aa98d9455c7c8fbac1a`.
  Adjacent `run_cpu_inspection.py` retains the bounded reproduction script. It
  reuses only generic browser-runner definitions, not native GPU test selectors.
- Python JUnit:
  `C:/Users/btspa/AppData/Local/Temp/virtual-realm-inspection-python-20260913.xml`,
  SHA256 `83b48c2b0e81730bb2d4d2e741afcbb6691bddad4646fb2fbafd5a57cb842af`.
- Resolver SHA256:
  `a7362adeadfac7ef2bdc56df7c845c656deda3919d74d05406b4a364f02faceb`.

The measured Python invocation was:

```powershell
$env:PYTEST_DISABLE_PLUGIN_AUTOLOAD = '1'
python -B -m pytest --noconftest -p no:cacheprovider -q --tb=line tests/virtual-realm/test_m2_read_only_inspection.py --junitxml=C:/Users/btspa/AppData/Local/Temp/virtual-realm-inspection-python-20260913.xml
```

The durable browser entries are
`tests/virtual-realm/m2-read-only-inspection.test.html` and
`tests/virtual-realm/m2-static-render-plan.test.html`; serve them over HTTP,
never `file://`. Independent review found no ordinary correctness defect in
the bounded resolver. Scoped source SPDX, whitespace, conflict-marker and final
newline checks passed. Global documentation/API regeneration was not run,
preserving the First Shard exclusion and concurrent work.

This completes only the plan-bound CPU inspector. The production module is not
imported by Entry or the presenter. The next integration step is genuine
object-ID pick delivery after the existing renderer/provider gate, followed by
current active-plan/generation checks and read-only presentation. No integrated
M2G, physical frame, first-person, Operations View, proposal, or provider
acceptance follows from this CPU work. The separately completed
[pipeline-layout verification](#approved-pipeline-layout-implementation) does
not supply live picking or complete the renderer/provider prerequisites.

### Build

- Resolve picks to stable admitted object IDs.
- Produce typed read-only inspection records.
- Validate the three local-zone request forms: zone visibility, alert threshold,
  and rebake. Selection and focus remain presentation-only.
- Dispatch proposals through the injected generic authority port.
- Correlate receipts without applying a live M3 observation yet.

### Gate

- Picking returns no capability, key, private source, or raw handle.
- A proposal cannot mutate stores, ECS, navigation, collision, renderer, bake,
  or policy.
- Denial, expiry, cancellation, and stale authority are explicit.
- M2 presentation never claims a requested mutation completed because live
  authoritative observation reconciliation is deferred to M3.
- Idempotency and expected-revision fields reject accidental replay.

### Rollback

Retain inspection and disable proposal dispatch.

## M2-GE: optional static Genesis extension

The base M2 certification does not require Genesis. The Living Digital World
track adds a separately switchable `GenesisRealmExtensionManifestV1` bound to
the exact accepted base-bake ID, digest, spatial-layout receipt, variant,
audience, policy, compiler identities, dependency closure, and expiry.

M2-GE may load only:

- the Continuity Core, Foundry District, and Maintenance Works kits;
- reserved sockets for the Possibility Archive, Role Commons, and Culture
  Archive;
- immutable `SoulSeedIdentityRootV1` and `EidosIdentityV1` references;
- static projection bindings, collision, navigation, HLOD, accessibility, and
  local Genesis Operations lookup;
- visibly empty authored infrastructure when no admitted live evidence exists.

The extension activates atomically against one exact base bake. If it is
missing, invalid, incompatible, over budget, or disabled, the accepted base
city remains usable and unchanged. Base-bake replacement either rebinds both
products at one barrier or removes the extension. M2-GE cannot show phenotype,
regulation, homeostasis, reaction, role, culture, lineage, QD, dormancy,
foundry-job, or organismality activity; those begin at M3.

Gate: identical authored inputs produce byte-identical extension layout and
closure; disabling the extension changes no base-bake digest or base runtime
record; and zero unobserved activity is rendered.

## M2H: recovery, performance, accessibility, and integrated acceptance

### Build

- Add the device-recovery barrier and exact resource rebuild registry.
- Add lifecycle, GPU, memory, frame, controller, operations, and semantic-mirror
  evidence collectors.
- Add browser tests for every M2 slice plus the complete first local walk.
- Add bundle/import audits and long-session resource plateaus.
- Freeze reference-tier budgets from measured baselines.

### Integrated gate

1. Launch through WebGPU OS with no ambient dependency.
2. Resolve one owner-partitioned M1C admission index, reconstruct the exact
   private-v2 package, verify its external evidence, and load it without a
   RealmForge runtime import.
3. Spawn exactly once at the Root Spine.
4. Walk the five foundational territories and SecureMesh station shell.
5. Inspect stable objects and sealed Code Matter without source reveal.
6. Enter the own-city Operations View, select one local zone, submit one
   powerless proposal, and return to the preserved first-person anchor.
7. Force device loss during each startup and view state; rebuild exactly once.
8. Shut down, verify zero Realm-owned resources, restart, and reproduce the
   same package digest, inert Storylet catalog digest, static scene digest, and
   stable object IDs.

### Rollback

Disable the Virtual Realm app entry. Accepted bakes, M0-M1C contracts, and other
WebGPU OS applications remain unaffected.

## Test layout

```text
tests/virtual-realm/
  m2-entry-contract.test.html
  m2-entry-contract.main.js
  m2-entry-contract.test.js
  m2-runtime-composition.test.html
  m2-runtime-composition.main.js
  m2-runtime-composition.test.js
  m2-static-bake-loader.test.html
  m2-static-bake-loader.main.js
  m2-static-bake-loader.test.js
  m2-m1c-admission-handoff.test.html
  m2-m1c-admission-handoff.main.js
  m2-m1c-admission-handoff.test.js
  m2-ecs-materialization.test.html
  m2-ecs-materialization.main.js
  m2-ecs-materialization.test.js
  m2-static-render-plan.test.html
  m2-static-renderer-profile.test.html
  m2-static-draw-packet.test.html
  m2-static-gpu-presenter.test.html
  m2-static-gpu-presenter.test.js
  m2-static-gpu-presenter.test.main.js
  m2-gpu-presentation-port.test.html
  m2-gpu-presentation-syscall-adapter.test.html
  m2-factory-integration.test.html
  m2-desktop-terminal-factory.test.html
  virtual-realm-manifest-registry.test.html
  m2-first-person-controller.test.html
  m2-local-operations-view.test.html
  m2-interaction-proposals.test.html
  m2-device-recovery.test.html
  m2-runtime-integrated.test.html
  m2-artifact-store-cas.test.html
  m2-os-lifecycle-handoff.test.html
  m2-os-lifecycle-handoff.main.js
  m2-os-lifecycle-handoff.test.js
  m2-genesis-static-extension.test.html
  support/VirtualRealmM2AContractFixtures.js
  support/VirtualRealmM2ARuntimeFakes.js
  support/VirtualRealmM2AdmissionFixtures.js
  fixtures/m2-admission-index-v1-vectors.json
  fixtures/m2-invalid-package-matrix.json
  fixtures/m2-static-private-bake.json
  test_m2_runtime_contract_vectors.py
  test_m2_static_materialization_vectors.py
  test_m2b_app_import_confinement.py
  test_m2db2_gpu_presentation_port.py
  test_m2db2_gpu_presentation_syscall_adapter.py
```

Python vector checks cover canonical runtime records and fixture hashes. Browser
tests cover imports, lifecycle, Engine integration, rendering, controllers,
device loss, and resource ownership. A skipped browser case is not acceptance.
`m2-entry-contract` targets 25 catalog/index cases;
`m2-m1c-admission-handoff` targets 32 durable admission cases. Those tests do
not substitute for `m2-runtime-composition`, which targets 30 cases spanning all
14 `VR-M2A-*` lifecycle and application-boundary groups. A count remains planned
until its named file exists and produces an exact zero-skip receipt. The current
M2C loader and ECS materialization suites each pass exactly 24 browser cases.
The independently accepted M2D-A/B0/B1/B2 evidence is recorded in the named
static-plan, profile, draw-packet, GPU-port, adapter, presenter, launch, and
closure suites. These suites remain distinct from the Engine-foundation and
future first-person/integrated evidence.

`m2-os-lifecycle-handoff` is a fourth independent suite targeting exactly 12
passing cases and zero skips:

| Case | Required assertion |
| --- | --- |
| `M2-HANDOFF-01` | Commit the first static checkpoint only while the trusted checkpoint-source activation-selection lease proves exact current-active/anchor/policy equality through checkpoint-head CAS and normal active-root readback; bind the source authorization and kind payload, and expose the preissued handoff authorization only with the committed result |
| `M2-HANDOFF-02` | Replace a checkpoint under exact predecessor/next-generation lineage while retaining the prior root until the new record and root are active, then issue the exact successor-active retirement receipt; release immediately only when no consumed handoff edge names the prior root, otherwise defer release until exact `releaseEdge()` readback; exact predecessor or source change returns explicit not-committed abandonment rather than an old record |
| `M2-HANDOFF-03` | Commit the first handoff record from a one-field advisory draft with service-injected owner/lifecycle/state fields, service-generated operation/root identity, required single-use checkpoint authorization, exact binding, and complete protected graph edge in the handoff root payload; expose it only after that root is active |
| `M2-HANDOFF-04` | Replace a handoff without a generation reset or interval in which neither old nor new graph root is active |
| `M2-HANDOFF-05` | Clear by writing/readback of the next tombstone, retire/release the named handoff root, then release its checkpoint-retention edge through the exact binding port without deleting or resetting head authority |
| `M2-HANDOFF-06` | Restart preserves strictly increasing checkpoint and handoff generations, exact previous-storage-SHA lineage, and tombstone authority |
| `M2-HANDOFF-07` | Stale write/clear expectations, third values, malformed heads, and uncertain CAS outcomes never advance or fabricate a record |
| `M2-HANDOFF-08` | Crash at every planned/prepared/manager-published/active boundary, including after checkpoint-handoff authorization claim but before head dispatch, resumes only the exact named journal transition; pre-dispatch restoration returns the cell to issued only after exact manager-nonpublication plus abandoned-root readback and never exposes a half-published record |
| `M2-HANDOFF-09` | Manager publication/adoption and terminal cleanup reconcile exact record/root/directory SHAs before slot reuse or collection |
| `M2-HANDOFF-10` | A new session activates its own runtime pin, claims the exact service-only cross-session handoff lease, and completes the guarded visible commit plus old-gate displacement readback before handoff clear or old-session release |
| `M2-HANDOFF-11` | The displaced old session retains its own teardown child, resources, and `handoff-displaced-retained` runtime pin through lifecycle retirement, `handoff-displaced-pointer-preserved` active-handle close, post-frame GPU fence, and exact resource/child disposal, then retires/releases its pin once; it never removes the new pointer or enters the new session's same-generation disposal ledger |
| `M2-HANDOFF-12` | Operator switch, cross-Realm scope, stale admission/profile, missing/forged/reused/mismatched checkpoint authorization or binding, caller-authored restoration fields, a missing protected checkpoint graph edge, and live-handle injection are rejected without disclosure or partial restoration |

The suite is planned until all three named files exist and emit one immutable
zero-skip receipt. It does not reuse the 32-case admission suite as a substitute.

## M2 performance evidence

GE0 and M2A establish reference hardware before budgets are frozen. The evidence
records:

- cold and warm package verification;
- static-store construction and index counts;
- ECS entities, archetypes, presentation slots, and materialization time;
- pipeline compilation and warm-up;
- draw/dispatch counts and CPU/GPU frame distributions;
- GPU and host bytes by owner;
- first-person collision/navigation cost;
- Operations View cells, zones, routes, landmarks, and transition cost;
- device recovery and full disposal time;
- long-session resource plateau.

Measured quality tiers may reduce visual density. They may not change stable
object IDs, collision, navigation, authority, disclosure, or readable semantic
signage.

## M2 approval boundary

Base M2 is approved only when M2A-M2H pass together with unchanged M0, M1A,
M1B, and M1C gates. The handoff gate must additionally reproduce the same
verified private-v2 package after process restart, cryptographically resolve
its external signature evidence, and prove that every Storylet record remained
inert. Its output is a static local Realm foundation. M2-GE is an
additional opt-in gate required for the Living Digital World certification but
not for the base Virtual Realm V1. Neither approval authorizes the M3 scanner,
live observation, Code Matter reveal, Storylet runtime, public shell, or
multiplayer path.

First Shard content remains excluded. No source, test, architecture, mechanic,
art direction, runtime, or dependency from that application participates in M2.

## See also

- [Architecture and ownership](architecture.md)
- [M2 Engine and ECS foundation](../../engine/virtual-realm-m2-engine-foundation.md)
- [M2A runtime composition](m2a-runtime-composition.md)
- [M2B private-bake admission](m2b-private-bake-admission.md)
- [Playground clean-room foundations](playground-clean-room-foundations.md)
- [RealmForge bake pipeline](realmforge-pipeline.md)
- [World districts and facilities](world-districts.md)
- [M3 living city runtime](m3-living-city-runtime.md)
- [Local City Operations View](local-operator-view.md)
- [Rendering and experience](rendering-experience.md)
- [Implementation roadmap](implementation-roadmap.md)
- [Certification plan](certification-plan.md)
