← Files Canonical Memory VerifierARCHIVED FILE

PUBLIC_BOUNDARY.md

1.32 KB · Sep 30, 2026 · 23:13 UTC

↓ Download file

# Public clean-room boundary

This candidate is built from a fresh schema, fresh code, and deterministic
synthetic fixtures. A future public archive must use an explicit allowlist.

Never include:

- private vault files, runtime snapshots, manifests, packages, or query output;
- real conversation, task, snapshot, source, artifact, or app identifiers;
- share links, local absolute paths, user names, cookies, tokens, or Tunnel logs;
- private hashes, because a hash can fingerprint undisclosed content;
- real repository state, customer data, commercial rankings, authority incidents,
  or distinctive event timelines;
- a copied private verifier whose routes or constants reveal private systems.

Before publication, run the boundary scanner, compare against a private deny-set
outside the candidate tree, inspect the final archive member allowlist, and
revalidate every external release or submission gate from live state. The
selected public license is Apache-2.0.

`PUBLIC_MANIFEST.json` is the candidate allowlist. It binds every other file's
relative path, byte count, SHA-256, and clean-room origin. The manifest excludes
its own bytes to avoid a recursive self-hash. Git control data under `.git/` is
not a distributable plugin member and is excluded; unexpected caches or build
outputs remain a failure rather than an implicit exclusion.

SHA-256: df5cd9ea2a9c7a07b287a1a4ac308ff3eacd4ac9ea31499527506033c5fa2721