Global site search

Search guides, labs, glossary, and research

Type two or more characters to search.

Start with a channel, artifact, or defense term

Examples include zero-width, metadata, tokenizer, or prompt injection.

    Public version contract

    MachineTradecraft.com is now versioned.

    The current source candidate is version 1.6.0, release 2026-08-27-claim-traceability-1. The release history tracks compatibility, stable URLs and APIs, structured content, and SHA-256-bound root-deployment packages.

    Quick answer

    How does MachineTradecraft.com identify a release?

    A semantic version communicates compatibility while an immutable release ID identifies the exact candidate. ZIP checksums and local validation prove package identity, but never by themselves prove live deployment.

    Version
    MAJOR.MINOR.PATCH communicates compatibility.
    Release ID
    A dated immutable identifier distinguishes exact candidates.
    Deployment proof
    Requires fresh production headers, routes, assets, logs, and operator evidence.
    Current release

    Claim traceability, standards currency, and citation health

    Adds a separate checksum-governed review plane across all thirty-one governed reports, connecting bounded significant claims to authority-labelled current sources, publication status, direct or partial support, conflicts, non-establishment, implementation impact, and exact follow-up without rewriting source bodies, assigning source-quality scores, or adding runtime network access.

    • Added the canonical /research/source-map/ collection with server-rendered filters for relationship, source category, publication state, report, version sensitivity, and external review.
    • Added one deterministic manifest covering thirty-one reports, thirty-nine bounded claim reviews, sixty-three reviewed sources, exact report hashes, stable claim and source identifiers, replacement relationships, review dates, and status vocabularies.
    • Added a shared current-claim-review panel to every governed report reader while preserving the exact Markdown body as a separate source layer.
    • Recorded direct support, partial support, conflict or qualification, and non-establishment without credibility scoring; documented current implementation impact and required browser, parser, model, trust, registry, DNS, legal, or organizational follow-up.
    • Updated version-sensitive guidance for Unicode 17.0, WAI-ARIA and browser drafts, RFC 9989 DMARC, C2PA 2.4, SPDX 3.0.1, SLSA 1.2, CycloneDX 1.7, PNG Third Edition, Exif 3.1, and other selected standards while retaining superseded references as labelled historical context.
    • Explicitly qualified preserved overstatements about universal NFC normalization, aria-modal background inertness, closed Shadow DOM locator reach, and superseded SLSA and CycloneDX versions.
    • Published deterministic JSON and adjacent SHA-256, stable deep links for every claim and source, visible Dataset and ItemList structured data, search and sitemap integration, contextual pathways, no-script filters, mobile containment, accessibility support, and print-useful records.
    • Added claim-smoke and focused browser checks for manifest integrity, report/source/heading routing, status vocabulary, source-currentness, filters, panel/body separation, deterministic identity, no external runtime requests, accessibility, mobile, print, memory, package, extraction, and byte reproduction.
    • Stored the complete methodology under durable documentation, routed compact current state through UAIX memory, advanced the recursive continuation prompt, and regenerated derived exports and the self-excluding manifest.
    • Preserved all thirty-one governed report bodies, eighteen attachment fixtures, fourteen evidence-review fixtures, twelve durable/public submitted-report pairs, and protected totem, taboo, and talisman records byte-for-byte.

    Release boundary: version metadata identifies the package; it does not claim that a local candidate is deployed. Production is authoritative only after a separately authorized deployment and fresh live verification.

    Semantic versioning

    Version numbers describe compatibility, not marketing size.

    The public version follows MAJOR.MINOR.PATCH. Every packaged build also retains an immutable calendar-stamped release ID for diagnostics and archive checks.

    Major

    Increment for incompatible changes to established canonical routes, public API contracts, fixture guarantees, or other published behavior.

    Example: removing or redefining a public API field without compatibility.

    Minor

    Increment for backward-compatible pages, laboratories, report collections, or capabilities that preserve existing public contracts.

    Example: adding a new clean route or allowlisted lab.

    Patch

    Increment for compatible corrections, accessibility improvements, metadata refinements, defensive hardening, or presentation fixes.

    Example: correcting structured data while preserving URLs and output contracts.
    Discovery and citation

    Stable content is easier to index, answer from, cite, and verify.

    Canonical URLs are the durable public identifiers. Page titles, descriptions, visible headings, structured data, sitemap entries, and internal links must agree on the same subject and destination. A moved route requires a one-hop permanent redirect rather than a duplicate or soft replacement.

    Answer engines and generative search systems receive the same crawlable HTML as people. MachineTradecraft.com therefore prioritizes answer-first definitions, explicit limitations, source-linked research, stable entities, meaningful internal links, and metadata that matches visible content. No special markup substitutes for useful, technically accessible pages.

    The supplemental machine-readable site guide is maintained for clients that choose to use it, while canonical HTML, robots policy, XML sitemap, JSON-LD, and response headers remain the primary public signals.

    Public history

    Release record

    Entries are newest first. Releases before 1.6.0 are retained by immutable release ID and labeled pre-version.

    Version 1.6.0 Claim traceability, standards currency, and citation health

    2026-08-27-claim-traceability-1 ·

    Adds a separate checksum-governed review plane across all thirty-one governed reports, connecting bounded significant claims to authority-labelled current sources, publication status, direct or partial support, conflicts, non-establishment, implementation impact, and exact follow-up without rewriting source bodies, assigning source-quality scores, or adding runtime network access.

    • Added the canonical /research/source-map/ collection with server-rendered filters for relationship, source category, publication state, report, version sensitivity, and external review.
    • Added one deterministic manifest covering thirty-one reports, thirty-nine bounded claim reviews, sixty-three reviewed sources, exact report hashes, stable claim and source identifiers, replacement relationships, review dates, and status vocabularies.
    • Added a shared current-claim-review panel to every governed report reader while preserving the exact Markdown body as a separate source layer.
    • Recorded direct support, partial support, conflict or qualification, and non-establishment without credibility scoring; documented current implementation impact and required browser, parser, model, trust, registry, DNS, legal, or organizational follow-up.
    • Updated version-sensitive guidance for Unicode 17.0, WAI-ARIA and browser drafts, RFC 9989 DMARC, C2PA 2.4, SPDX 3.0.1, SLSA 1.2, CycloneDX 1.7, PNG Third Edition, Exif 3.1, and other selected standards while retaining superseded references as labelled historical context.
    • Explicitly qualified preserved overstatements about universal NFC normalization, aria-modal background inertness, closed Shadow DOM locator reach, and superseded SLSA and CycloneDX versions.
    • Published deterministic JSON and adjacent SHA-256, stable deep links for every claim and source, visible Dataset and ItemList structured data, search and sitemap integration, contextual pathways, no-script filters, mobile containment, accessibility support, and print-useful records.
    • Added claim-smoke and focused browser checks for manifest integrity, report/source/heading routing, status vocabulary, source-currentness, filters, panel/body separation, deterministic identity, no external runtime requests, accessibility, mobile, print, memory, package, extraction, and byte reproduction.
    • Stored the complete methodology under durable documentation, routed compact current state through UAIX memory, advanced the recursive continuation prompt, and regenerated derived exports and the self-excluding manifest.
    • Preserved all thirty-one governed report bodies, eighteen attachment fixtures, fourteen evidence-review fixtures, twelve durable/public submitted-report pairs, and protected totem, taboo, and talisman records byte-for-byte.
    Version 1.5.0 Control-to-Evidence Assurance Matrix

    2026-08-27-control-evidence-matrix-1 ·

    Connects thirteen source-bound Machine Tradecraft control families and nine independent maturity dimensions to design, implementation, test, operational, local, organizational, and external evidence across seven system profiles, while preserving six non-numeric evidence states and deterministic request-local records without scores, certification, persistence, uploads, external lookups, or production authority.

    • Added the canonical /machine-tradecraft-control-evidence/ guide and the focused /labs/defense/control-evidence/ evidence-planning laboratory.
    • Added one checksum-bound registry covering thirteen source control families, nine maturity dimensions, seven system profiles, six evidence states, five review objectives, and eight exact external-verification authority classes.
    • Separated design, implementation, test, operational, local-demonstration, organizational, and external-verification evidence so declarations, fixtures, logs, signatures, owners, and production observations cannot be treated as interchangeable proof.
    • Added profile-specific applicability, conflicts, controls, tests, limitations, review cadence, existing guides/reports/labs/actions/fixtures/Casebook cases, and named authority routing without an aggregate score.
    • Added bounded no-JavaScript submissions with one evidence-state control per control family, explicit review context, prepared fictional examples, field-level correction, cancellation, result provenance, bounded copy, safe exports, and immediate corrected-run comparison.
    • Added deterministic JSON and Markdown records with exact source/profile/control/evidence/resource identities, Control Plan ID, full SHA-256, explicit non-conclusions, and no timestamp, random value, session identity, request address, or hidden history.
    • Published an independently versioned JSON Schema and adjacent checksum for the control-plan record contract.
    • Added responsive control, dimension, profile, state, authority, requirement, and record-contract guidance with search, sitemap, Quick answer, structured data, navigation, contextual pathways, stable fragments, mobile, accessibility, and print integration.
    • Stored the complete architecture under durable documentation, routed compact current findings through UAIX memory, advanced the recursive continuation prompt, and added control-evidence-specific static, loopback, browser, Apache, package, extraction, and byte-reproduction gates.
    • Closed a 320-pixel release-history overflow caused by long canonical routes and immutable release identifiers, and strengthened browser diagnostics so future document-width failures identify the contributing descendants.
    • Preserved all thirty-one governed reports, eighteen attachment fixtures, fourteen evidence-review fixtures, twelve durable/public submitted-report pairs, and protected totem, taboo, and talisman records byte-for-byte.
    Version 1.4.0 Machine Tradecraft tabletop exercise simulator and runbook builder

    2026-08-27-tabletop-runbooks-1 ·

    Adds eight source-bound fictional representation-layer exercises, eight explicit operational roles, four staged inject phases, seven non-scoring decision categories, missing-authority and verification routing, request-local no-JavaScript operation, and deterministic JSON or Markdown runbooks without live incident data, persistence, external actions, scoring, or certification.

    • Added the canonical /machine-tradecraft-tabletop/ operational guide and the focused /labs/defense/tabletop/ laboratory.
    • Added one checksum-bound tabletop registry derived from the eight fictional scenarios in the governed defense-operations report, preserving its source path, exact report SHA-256, section, and source-row identity.
    • Added explicit roles for executive ownership, engineering, security operations, AI/model operations, content/data ownership, privacy/legal, incident command, and independent observation, with scenario-specific missing-role detection.
    • Added four deterministic stages covering intake and preservation, representation comparison, containment and authorization, and recovery and learning, with staged injects, required evidence, decision prompts, dependencies, and exact external-verification classes.
    • Added seven descriptive decision categories—Preserve, Inspect, Contain, Verify, Authorize, Recover, and Defer—without converting exercise decisions into severity, probability, readiness, compliance, pass/fail, or assurance scores.
    • Added bounded no-JavaScript laboratory submissions, progressive stage visibility, three prepared fictional examples, field-level UTF-8 and byte validation, cancellation, result provenance, immediate-rerun comparison, and request-local privacy with no upload or hidden history.
    • Added deterministic JSON and Markdown records with Tabletop ID, full SHA-256, report and scenario identity, roles, staged decisions, evidence requirements, runbook steps, unanswered questions, non-conclusions, and external-verification needs.
    • Added responsive scenario, role, stage, and runbook guidance; search, sitemap, Quick answer, schema, navigation, contextual pathways, stable fragments, print output, and discovery integration.
    • Stored the complete architecture under durable documentation, routed compact current findings through UAIX memory, advanced the recursive continuation prompt, and added tabletop-specific static, loopback, browser, Apache, package, extraction, and byte-reproduction gates.
    • Preserved all thirty-one governed reports, eighteen attachment fixtures, fourteen evidence-review fixtures, and protected totem, taboo, and talisman records byte-for-byte.
    Version 1.3.0 Cross-representation differential workbench

    2026-08-26-differential-workbench-1 ·

    Adds a bounded, request-local workbench that preserves governed fixture identities, reuses existing allowlisted laboratory engines, compares explicit evidence planes under reviewed transformations, records non-scoring comparison and signal-survival states, and exports deterministic JSON and Markdown with exact unresolved verification requirements.

    • Added the canonical /representation-differential-workbench/ route with two-to-four-case, six-plane, and five-transformation request limits.
    • Added one reviewed differential registry covering fourteen governed cases, seven transformation families, five exact comparison states, four signal-survival states, representation domains, selectors, and bounded control variations.
    • Reused the existing Unicode, web, document, image, message, tokenization, linguistic, browser, agent, supply-chain, and defense engines without adding an unrestricted parser, model, OCR service, trust lookup, registry lookup, or execution path.
    • Added deterministic source, component, method, representation, Differential ID, and full SHA-256 identities while limiting public previews and keeping governed source files separate.
    • Added pairwise comparison records that use Same or Different only when domain and local method match; all other relationships remain conditionally comparable, not comparable, or not evaluated locally.
    • Added reviewed Survived, Changed, Removed, and Not evaluated signal states without converting them into robustness, severity, probability, trust, or risk scores.
    • Added deterministic no-store/noindex JSON and Markdown exports, an independently versioned JSON Schema with checksum, explicit non-conclusions, exact external-verification requirements, and links to each guide, report, evidence review, fixture, laboratory, and allowlisted action.
    • Added no-JavaScript operation, progressive selection guidance, keyboard and accessibility support, 320-pixel containment, wide-matrix scrolling, print output, and request-local privacy with no persistence or hidden history.
    • Stored the complete architecture and authority boundary under durable documentation, routed compact accepted findings through UAIX memory, advanced the next recursive prompt, and added differential-specific validation to the release harness.
    • Preserved all thirty-one governed reports, eighteen attachment fixtures, fourteen evidence-review fixtures, and protected totem, taboo, and talisman records byte-for-byte.
    Version 1.2.1 UAIX memory integrity and durable-knowledge housekeeping

    2026-08-26-memory-integrity-1 ·

    Reconciles current UAIX records, durable documentation, release proof, research routing, source identities, and operational commands; removes stale current-state claims; adds a repository-owned memory consistency gate; and preserves all governed research bodies, public routes, laboratory contracts, and protected records.

    • Audited every current hot-memory record, durable report index, research route, release-proof pointer, source-package identity, and derived UAIX export against the current implementation.
    • Removed stale current-state wording that still described completed browser, Apache, archive, and reproduction work as pending and replaced obsolete v1.1.3 package evidence in active architecture and decision records.
    • Updated the File Handoff ledger, credential inventory, report synthesis, memory-maintenance policy, progress, startup, operations, testing, architecture, identity, context, and receiver records to one coherent current release identity.
    • Added a durable memory-housekeeping report and indexed every durable report, including the research-expansion and submitted-intake records that were missing from the reports index.
    • Expanded the durable research index so the original nineteen reports and twelve submitted reports are both individually routed rather than summarizing the submitted expansion only as one block.
    • Added a memory-smoke harness command that validates UAI metadata, stable IDs, evidence pointers and anchors, current source-package hashes, protected record hashes, current release/inventory claims, complete durable indexing, export-manifest coverage, and prohibited stale-state phrases.
    • Made memory-smoke part of static, portable, package, extended, and extracted-repository validation while keeping repository memory and tooling outside the public runtime archive.
    • Regenerated all derived UAIX exports and the self-excluding manifest after accepted write-back.
    • Preserved all thirty-one governed research reports, twelve durable/public submitted pairs, eighteen attachment fixtures, fourteen evidence fixtures, and protected totem, taboo, and talisman records byte-for-byte.
    Version 1.2.0 Context-specific representation policy builder

    2026-08-26-representation-policy-1 ·

    Adds a bounded request-local Representation Policy Builder with fourteen application profiles, fifteen independent control decisions, deterministic JSON and Markdown, profile conflict visibility, implementation checklists, test plans, schema-governed exports, and exact external-verification requirements without a universal preset, aggregate score, certification, upload, parser, model call, persistence, or external lookup.

    • Added fourteen allowlisted policy profiles covering names and prose, identifiers, passwords and secrets, source code, HTML and web content, documents, images, messages, search and indexing, RAG ingestion, model prompt construction, agent tool input, supply-chain manifests, and provenance-bearing media.
    • Kept fifteen decisions separate for source-byte preservation, type and encoding validation, Unicode policy, identifier restrictions, container inspection, representation comparison, active-content isolation, metadata, provenance, model-input construction, capability boundaries, human confirmation, output validation, evidence retention, and external verification.
    • Added five explicit statuses—Required, Recommended, Context-dependent, Prohibited, and Externally verified—with profile-specific rationale, do-not-apply warnings, control tasks, and deterministic tests.
    • Added a five-profile selection boundary and visible conflict records so incompatible normalization, metadata, retention, capability, and trust rules cannot be flattened into one universal secure preset.
    • Linked every selected profile to existing canonical guides, governed reports, glossary concepts, evidence fixtures, Casebook cases, focused laboratories, allowlisted actions, and the Analyst Handoff Worksheet.
    • Added deterministic no-store/noindex JSON and Markdown policy exports with a compact Policy ID, full SHA-256, control checklist, profile-specific test plan, exact unresolved external-verification requirements, and explicit non-conclusions.
    • Published independently versioned JSON Schema 1.0.0 with an adjacent SHA-256 sidecar for validating exported policy records.
    • Added progressive selection guidance without fetches, cookies, accounts, analytics, browser storage, automatic analysis, hidden history, or authority over server validation.
    • Added responsive, keyboard, accessibility, print, no-JavaScript, deterministic-export, schema, route, Apache, package, extraction, and byte-reproduction validation while preserving every governed report and protected record byte-for-byte.
    • Stored the full implementation and authority boundary in durable documentation and advanced concise UAIX pointer memory and the next recursive continuation prompt.
    Version 1.1.3 Analyst handoff worksheet and deterministic evidence bundle

    2026-08-26-analyst-handoff-1 ·

    Extends the Representation Casebook with a bounded request-local analyst worksheet that keeps observed facts, derived observations, hypotheses, exact verification requirements, and decision constraints separate, then exports deterministic JSON and Markdown records without persistence, uploads, arbitrary fixture content, scoring, intent inference, or external execution.

    • Added a shared handoff registry with five explicit entry categories, eight allowlisted verification-authority types, six entries per selected case, and UTF-8 byte plus visible-character limits.
    • Bound every handoff to the server-rebuilt Casebook Plan ID and SHA-256, governed fixture names/bytes/digests, selected evidence planes, existing guide/report routes, and current allowlisted laboratory slugs, paths, and actions.
    • Added request-local no-JavaScript worksheet submission with owned validation for unknown cases, layers, categories, laboratories, actions, authorities, malformed UTF-8, duplicate entries, empty submissions, and per-case limits.
    • Added deterministic no-store/noindex JSON and Markdown exports with a compact Handoff ID, full SHA-256, categorized case records, exact unresolved verification requirements, bounded next actions, and explicit non-conclusions; repeated identical inputs produce byte-identical exports.
    • Added progressive client-side category, authority-field, character, UTF-8 byte, case-count, and empty-submission guidance without fetches, cookies, browser storage, automatic analysis, hidden history, or authority over server validation.
    • Added mobile-safe and print-useful handoff previews with focusable correction guidance, 44-pixel-class actions, contained long identities, and a result view that separates request-local notes from the preserved source evidence.
    • Added handoff-smoke and real-Chromium handoff-browser-smoke release gates covering determinism, no persistence, malformed input, five-category output, fixture/laboratory identity, mobile containment, accessibility, target sizing, screenshot paint, and substantive PDF output.
    • Stored the complete architecture and authority boundary in durable documentation and routed concise current findings through UAIX pointer memory while preserving all submitted reports, previous governed reports, and protected records byte-for-byte.
    Version 1.1.2 Representation casebook and cross-topic investigation workflow

    2026-08-26-representation-casebook-1 ·

    Adds one bounded local representation casebook that turns the governed evidence-review fixtures into a reproducible, non-scoring investigation plan, compares twelve independent evidence planes, routes unresolved questions into existing focused laboratory engines, and exports deterministic JSON without adding persistence, external fetches, duplicate parsers, or intent verdicts.

    • Added a canonical Representation Casebook route backed by one reviewed registry of fourteen checksum-bound fixture cases, four planning objectives, and twelve byte-through-operational evidence planes.
    • Added server-owned plan generation with a six-case limit, allowlisted selections, source fixture bytes and SHA-256, present/conditional/not-declared layer states, existing guide/report/lab routes, focused investigation questions, and explicit external-verification needs.
    • Added a deterministic, no-store, noindex JSON plan export whose plan ID and SHA-256 are stable for the same release and selection and which contains no timestamp, universal risk score, probability, certification, malicious-intent verdict, or production-assurance field.
    • Added progressive client enhancement for selected-case counts and the six-case limit without automatic submission, network requests, cookies, localStorage, sessionStorage, IndexedDB, analytics, or hidden plan history.
    • Added a complete fixture-by-layer catalog, mobile-safe and print-useful planning output, visible method boundaries, descriptive search and navigation paths, Quick answer and schema parity, and fixed horizontal containment for the wide comparison matrix.
    • Added static, loopback, deterministic-export, focused Chromium, no-JavaScript, accessibility-tree, complete-route, Apache, package, extraction, and byte-reproduction checks for the casebook while preserving every prior report, fixture, action, route, and protected record.
    • Stored the accepted architecture and limitations in durable documentation and routed compact current findings through UAIX pointer memory rather than duplicating the full implementation record in hot memory.
    Version 1.1.1 Evidence quality, implementation depth, and visitor decision support

    2026-08-26-evidence-depth-1 ·

    Reviews every v1.1.0 research expansion without rewriting submitted bodies, distinguishes directly computed evidence from bounded approximation and external verification, strengthens deterministic laboratory implementations and fixtures, and adds visitor-facing decision paths plus durable UAIX-routed correction records.

    • Added a separate twelve-topic evidence-review registry with reviewed implementation modes, directly computed output, bounded approximations, external verification requirements, corrections, source-authority checkpoints, and three decision-support rows per topic.
    • Added visible evidence-boundary and decision-support sections to every expansion guide, implementation-review framing to every submitted report reader, and prepared governed fixture downloads plus interpretation boundaries to every expansion laboratory.
    • Added a deterministic 14-fixture evidence-review pack covering Unicode, HTML, PDF, OOXML, tokenization, fixed-marker steganalysis, provenance, agent policy, multimodal metadata, MIME, iCalendar, browser-agent states, CycloneDX references, and defense planning.
    • Strengthened the Unicode laboratory with exact PCRE2 grapheme matches and an explicit non-conformance boundary while preserving the original text and bounded normalization/confusable maps.
    • Strengthened tokenization, MIME/calendar, supply-chain graph, browser-agent, fixed-marker linguistic, agent-policy, provenance, and defense-planning outputs while correcting implementation-owned overstatements about risk scoring, modality, cryptographic verification, schema conformance, and observed maturity.
    • Added an evidence-smoke release gate that renders all 36 expansion guide/report/lab pages and exercises twelve deterministic evidence submissions without external runtime lookups.
    • Recorded corrections and version-sensitive checkpoints in durable documentation and UAIX pointer memory while preserving all submitted and previously governed report bodies plus protected totem/taboo/talisman records byte-for-byte.
    Version 1.1.0 Twelve-report research, guide, laboratory, and memory expansion

    2026-08-25-research-expansion-1 ·

    Integrates twelve user-supplied research reports as hash-governed public sources and exact durable documentation, adds twelve canonical guides and twelve bounded laboratories, expands the glossary and reciprocal evidence graph, and routes the resulting architecture through UAIX pointer memory without weakening existing runtime, safety, accessibility, discovery, or packaging contracts.

    • Preserved all twelve submitted Markdown reports byte-for-byte under docs/long-term-memory/research/submitted-reports and published byte-identical governed copies through the research reader.
    • Added canonical guides and focused laboratories for Unicode integrity, web representation layers, document containers, tokenization, linguistic steganalysis, content provenance, retrieval-agent trust boundaries, multimodal perception, message channels, browser-agent views, software and AI supply chains, and defense operations.
    • Expanded the public registry to 98 canonical sitemap pages, 38 laboratories, 54 native actions, 31 governed reports, 108 glossary terms, 167 reciprocal report relationships, and 955 stable report/glossary fragments.
    • Added deterministic, dependency-free educational analyzers for the nine text or structured-data topics and inert bounded file inspection for document-container, provenance, and multimodal image topics.
    • Added exact submitted-source manifests, durable synthesis and intake records, and deep UAIX links so hot memory routes to docs rather than duplicating long research bodies.
    • Extended answer architecture, contextual pathways, search, sitemap, TechArticle, DefinedTerm, SoftwareApplication, LearningResource, source-transparency, print, no-JavaScript, and responsive UI coverage to every new route.
    • Preserved the original 19 governed report bodies, 18 fixtures, established endpoints, fixed-marker safety boundaries, strict CSP, non-retention, no external runtime calls, and deterministic packaging.
    Version 1.0.16 Result provenance, completion, and corrected-rerun comparison

    2026-08-25-result-provenance-1 ·

    Makes the action and bounded input context behind every laboratory result directly verifiable, turns copy and generated-fixture actions into explicit completion outcomes, and compares one corrected rerun with the immediately preceding completed result without adding persistence, tracking, arbitrary history, runtime dependencies, or successful API fields.

    • Added a result-context panel that identifies the completed action, prepared/custom input state, execution path, safe input snapshot, and a deterministic SHA-256 Context ID.
    • Kept free-form input values out of the visible provenance summary while reporting byte counts, selected option labels, numeric values, or local filename and size as appropriate.
    • Added an explicit task-completion region with context verification, finding review, input-adjustment, bounded summary-copy, generated-fixture download, and same-action rerun paths.
    • Changed copy behavior from an ambiguous first-view copy to a structured result summary containing version/release, action, Context ID, safe input snapshot, summary, metrics, findings, and evidence inventory without automatically adding machine-view bodies or uploaded files.
    • Renamed and clarified generated output as Download safe fixture, including exact filename/byte feedback and a no-JavaScript disclosure of the generated bounded content.
    • Added page-local comparison of the immediately preceding completed result against one corrected rerun across action, input context, outcome, and evidence inventory; the prior result is discarded on reset or navigation.
    • Added a deterministic pure-JavaScript SHA-256 fallback so Context IDs agree with the server even when Web Crypto is unavailable in a self-contained or non-secure test document.
    • Expanded portable and Chromium gates across representative text, PDF, image, and controlled-AI laboratories at desktop and 320 pixels, including copy wording, download availability, target sizing, containment, and changed-input rerun comparison.
    Version 1.0.15 Laboratory orientation, action hierarchy, and result scanning

    2026-08-25-lab-orientation-1 ·

    Makes the first laboratory run explicit, separates the recommended action from alternate analyses, clarifies prepared versus custom input state, and turns dense results into a summary-first evidence map while preserving native form submissions, no-JavaScript operation, safety boundaries, routes, APIs, governed content, and the dependency-free runtime.

    • Added a consistent three-step first-run orientation to all 26 focused laboratories and explicitly stopped automatic analysis on initial page load.
    • Promoted exactly one registry-owned recommended action per laboratory while moving alternate actions into reversible progressive disclosure without removing native submit semantics.
    • Moved prepared examples into an optional disclosure, exposed the active prepared or custom input state, and kept all form values directly reviewable before execution.
    • Added a result map that reports available summaries, metrics, findings, machine views, table rows, and generated safe fixtures before visitors expand dense evidence.
    • Reordered findings ahead of expandable machine views, added visible severity labels, opened only the first result view initially, and added an explicit expand/collapse-all control.
    • Added responsive first-run, action, preset, and result-section layouts that remain contained at 320 pixels and retain 44-pixel-class interactive targets.
    • Expanded portable form coverage across text, PDF, image, and controlled-AI full-page fallbacks and strengthened focused/full Chromium checks for zero-fetch initial state, samples, alternate actions, cancellation, result navigation, and evidence expansion.
    Version 1.0.14 Form guidance, validation, and recovery

    2026-08-25-form-recovery-1 ·

    Makes laboratory and search forms easier to understand, validates bounded inputs next to their owning fields, exposes explicit loading, cancellation, empty, stale, and recovery states, and adds complete no-JavaScript laboratory submissions while preserving routes, successful APIs, governed report bodies, discovery contracts, strict CSP, and the dependency-free runtime.

    • Added visible helper text, local constraints, byte counters, error ownership, and native submit semantics to all 26 focused laboratory forms.
    • Added same-page no-JavaScript POST fallbacks for text and multipart laboratories, including preserved non-file values, field-bound errors, server-rendered results, and bounded recovery guidance.
    • Added explicit laboratory loading, cancellation, stale-result, completion, and error states while retaining request ownership so aborted or superseded work cannot overwrite newer input.
    • Strengthened page and dialog search with visible guidance, native 2–120-character constraints, inline errors, cancellable loading, explicit empty/error/cancelled states, query preservation, and server-rendered recovery links.
    • Added UTF-8 byte-aware client validation that mirrors server boundaries without replacing authoritative server validation.
    • Added a portable form-smoke command covering all 46 laboratory controls, all 42 actions, representative no-script text/file runs, and search error/results/empty states.
    • Expanded focused Chromium coverage to 16 desktop/mobile states and 15 interactions, including invalid input, loading, cancellation, recovery, mobile containment, and required-file behavior.
    • Extended the full Chromium suite with form-guidance audits and a submitted no-JavaScript laboratory state at 320 pixels.
    Version 1.0.13 Answer architecture, entity graph, and snippet hygiene

    2026-08-25-answer-architecture-1 ·

    Adds one concise visible answer to every canonical page, aligns contextual pathways with machine-readable relationships, strengthens laboratory, glossary, and research entities, and applies bounded snippet and social-preview controls while preserving routes, successful APIs, governed report bodies, strict CSP, and the dependency-free runtime contract.

    • Added a page-specific Quick answer region to all 62 canonical pages, using one shared server-side answer owner for visible copy and each WebPage abstract.
    • Added three descriptive same-origin Continue exploring paths per canonical page and generated matching relatedLink and ItemList relationships from the same data.
    • Bound WebPage nodes to the visible main landmark, publication principles, audience, stable Machine Tradecraft term entity, and locally relevant keyword and related-page context.
    • Published all 37 glossary definitions through one DefinedTermSet and represented all 26 focused laboratories as both SoftwareApplication and LearningResource entities.
    • Represented all 19 governed report readers as TechArticle entities whose citation arrays are derived exactly from unique external links in the unchanged Markdown source.
    • Removed the retired SearchAction sitelinks-search-box markup while retaining a useful human-facing local search route and shared server/JSON search owner.
    • Protected navigation, search chrome, footer diagnostics, contextual navigation, and control glyphs from snippet extraction with supported data-nosnippet wrappers.
    • Added a loopback-only discovery-smoke gate covering visible answers, 186 contextual links, entity and citation graphs, robots preview directives, social-preview metadata, rel=home, language, and snippet controls across the complete sitemap.
    Version 1.0.12 Discovery pathways and preview controls

    2026-08-24-discovery-pathways-1 ·

    Introduced page-aware next-step navigation, matching contextual ItemList data, complete snippet-preview directives, secure Open Graph image parity, and descriptive Twitter image alternatives while preserving canonical routes and governed content.

    • Added three page-aware Continue exploring cards to canonical pages so long-form journeys end with clear guide, evidence, defense, or workbench choices.
    • Generated contextual ItemList data from the same server-side mapping as the visible cards to prevent human/machine relationship drift.
    • Added max-image-preview, max-snippet, and max-video-preview controls to indexable pages without changing noindex utility and API boundaries.
    • Added secure Open Graph image parity, descriptive Twitter image alternative text, and an explicit rel=home brand relationship.
    Version 1.0.11 Fixed desktop navigation and coherent theme state

    2026-08-24-navigation-shell-1 ·

    Makes the complete site identity a dependable home target, locks the navigation shell for non-mobile visitors, turns the theme control into a clear current-state indicator, gives the homepage a real light representation, and uses the research hero’s secondary column more effectively without changing routes, APIs, governed reports, or the dependency-free runtime contract.

    • Made the full logo-and-wordmark area one explicit home link, protected its hit target from child-element interception, and added visible hover and keyboard-focus feedback.
    • Fixed the desktop header to the viewport with a matching document offset while retaining sticky, space-efficient behavior on mobile and a zero-offset print representation.
    • Redesigned the theme control as a labelled desktop pill and compact mobile icon whose visible icon and text describe the active theme while its accessible name describes the available action.
    • Added one resolved-theme state shared by initial paint, runtime toggling, browser theme-color metadata, icon state, and the homepage’s first-view presentation.
    • Added a complete light-mode cinematic homepage treatment so switching themes changes the hero, channel rail, text, and controls immediately instead of leaving the first viewport visually dark.
    • Rebalanced the research hero with a provenance snapshot, governed-report count, linked glossary count, explicit cross-link count, and direct library shortcut in the previously underused right column.
    • Expanded focused Chromium checks to ten desktop/mobile states and nine interactions covering brand hit testing, fixed-header persistence, theme parity, homepage representation, research-hero use, skip links, navigation, code tools, and tables.
    Version 1.0.10 Responsive reading tools and interface clarity

    2026-08-24-reading-tools-1 ·

    Improves header and mobile-navigation clarity, turns code samples into unobstructed keyboard-friendly reading tools, makes wide tables discoverable and keyboard-scrollable, and exposes unique versus repeated research-link destinations without changing governed report bodies, public routes, or successful API contracts.

    • Added a mobile navigation backdrop, animated open/close affordance, visible Menu/Close state, bounded viewport sheet, body scroll containment, and focus-return behavior while preserving the no-JavaScript navigation fallback.
    • Made pages with multiple skip links reveal only the focused shortcut, then move focus, update the fragment, and visibly identify the destination without crowding the header.
    • Rebalanced the Machine View and search affordances, replaced ambiguous theme glyphs with resolved sun/moon icons, synchronized browser theme color, and retained full brand wording on narrow screens.
    • Replaced code-block overlay buttons with a dedicated toolbar that labels the sample, reports line count, copies text, toggles line wrapping, and keeps the first line unobstructed.
    • Made overflowing tables focusable labelled regions with visible horizontal-scroll instructions, start/end edge feedback, responsive cell sizing, and clearer spacing.
    • Raised compact controls, inspector samples, tabs, section links, and theme controls to a 44-pixel-class target and added a mobile signal-family browse cue plus bottom-sheet search presentation.
    • Expanded source transparency with unique-destination and repeated-link-mention counts derived from the unchanged governed Markdown.
    • Expanded focused Chromium UI coverage to eight desktop/mobile states and six skip, header, navigation, theme, code, and table interactions.
    Version 1.0.9 Skip-link usability and mobile control sizing

    2026-08-24-navigation-usability-1 ·

    Removes always-visible skip-link overlap from the header, makes skip actions feel intentional and visible, and enlarges compact header controls for touch without changing canonical routes, successful APIs, governed report bodies, or the dependency-free runtime contract.

    • Changed skip links from space-taking header elements into off-canvas keyboard shortcuts that appear only on focus and no longer crowd the navigation bar.
    • Made skip-link activation scroll to the target, move focus there, and add a brief visible highlight so the destination is obvious instead of appearing to do nothing.
    • Added shared scroll-margin handling for main content and anchored sections so skip targets land clear of the sticky header.
    • Increased compact navigation and theme-toggle hit areas to a minimum 44-pixel-class touch target and tightened tiny-screen menu-button behavior.
    • Kept reduced-motion-safe behavior, section navigation, and progressive enhancement intact while refreshing repository-owned UI validation around the updated skip-link flow.
    Version 1.0.8 Reading clarity, source context, and motion resilience

    2026-08-24-reading-clarity-1 ·

    Improves long-form report readability, turns numbered source blocks into structured references, exposes bounded source context, raises deterministic light and dark theme contrast, and strengthens reduced-motion behavior while preserving canonical routes, successful APIs, deep-link contracts, governed report bodies, strict CSP, and the dependency-free runtime contract.

    • Rendered numbered governed source blocks as semantic ordered citation lists while leaving the underlying Markdown bytes unchanged.
    • Added a source-transparency summary to every report reader with external-link, source-host, structured-reference, and retained-citation-marker counts derived from the governed source.
    • Made every external report link identify its source host, announce new-tab behavior to assistive technology, and show a restrained visible external-link marker.
    • Bound long-form prose to a readable measure, increased report line spacing, and added citation-specific layout and print treatment without altering existing fragments or routes.
    • Raised low-emphasis and primary-control color contrast across dark, explicit-light, and system-light themes, backed by a deterministic 22-pair contrast gate.
    • Made reveal state respond to live reduced-motion preference changes and expanded Chromium checks for suppressed motion, readable measure, source context, and accessible link labeling.
    • Expanded portable report-reader checks across all 19 governed reports while preserving all 516 contracted fragments, 95 report/glossary relationships, and 19 governed report hashes.
    Version 1.0.7 Reference links, landmarks, and print integrity

    2026-08-24-reference-integrity-1 ·

    Makes glossary and research references reciprocal and deep-linkable, names page landmarks consistently, and gives long-form content a source-preserving print representation while preserving canonical routes, shared search ownership, strict CSP, governed source bodies, no-script usefulness, and the dependency-free runtime contract.

    • Assigned explicit stable identifiers to all glossary terms and governed a repository-owned continuity contract for glossary, research-card, report table-of-contents, and report-heading fragments.
    • Added one shared report-to-glossary relation map that renders reciprocal glossary links on research cards and report readers plus related-report links on each glossary definition.
    • Named main, search, navigation, article, and aside landmarks so repeated regions remain distinguishable in accessibility trees and landmark navigation.
    • Added visible, keyboard-accessible report-heading self-links and made filtered collections reveal and focus a requested fragment instead of leaving a deep link hidden.
    • Added print-only canonical/version mastheads, visible source URLs, one-column long-form layouts, page-break controls, and removal of interactive-only controls from printed output.
    • Expanded portable and Chromium checks for reciprocal references, duplicate IDs, landmark names, contracted fragments, filtered deep-link recovery, print media states, and substantive PDF generation.
    Version 1.0.6 Search context and long-page wayfinding

    2026-08-24-search-wayfinding-1 ·

    Makes local search results explain why they matched, establishes deterministic ranking and short-token boundaries, and adds keyboard-visible, focus-correct section navigation across long guides and research pages while preserving one shared search owner, no-script usefulness, strict dynamic CSP, canonical routes, governed bodies, and the dependency-free runtime contract.

    • Added bounded result excerpts and explicit title, summary, topic, and content-type match labels to server-rendered and JavaScript search results.
    • Strengthened deterministic ranking with exact-token and token-prefix quality, phrase bonuses, punctuation-equivalent ordering, and a short-token rule that prevents AI from matching inside machine.
    • Added a shared semantic section-navigation renderer, a second keyboard-visible skip link, active-section state, and focus transfer for core guides, topic guides, examples, labs, research, releases, and report readers.
    • Assigned stable anchors to previously anonymous synthesis and worked-example sections so deep links and section maps have durable targets.
    • Aligned Markdown table-of-contents extraction with rendering by ignoring fenced-code headings, eliminating links to source-code comments that never become document headings.
    • Expanded portable and Chromium regression checks for search-result contracts, server/JSON ranking parity, stale-result clearing, fragment integrity, section target ownership, skip-link relationships, active-location semantics, and mobile/desktop focus behavior.
    Version 1.0.5 Progressive search and interface integrity

    2026-08-24-search-integrity-1 ·

    Makes the dedicated search experience useful without JavaScript, unifies server and API matching, strengthens navigation focus ownership and filtered-collection feedback, and removes the dynamic-site inline-style exception while preserving canonical routes, successful API fields, laboratory actions, governed content, and the dependency-free runtime contract.

    • Added a shared dependency-free search catalog and normalized all-term matcher used by both the HTML fallback and JSON endpoint.
    • Rendered bounded search results and validation messages on the server so submitted queries remain useful when JavaScript is unavailable or fails.
    • Expanded the local catalog to include the homepage, scope and ethics, professional profile, release history, guides, labs, reports, and glossary terms with semantic ordered result lists.
    • Made hyphen, punctuation, separator, case, and multi-term query handling consistent across the search page, dialog, API, research filter, and glossary filter.
    • Marked the closed compact navigation inert, trapped focus within the open menu, restored focus after Escape, closed desktop disclosure menus on Escape or outside click, and made opening search dismiss competing navigation state.
    • Added live visible-item counts and explicit empty states to research and glossary filtering.
    • Replaced runtime inline style mutations with native progress elements and CSS classes, allowing dynamic HTML to enforce style-src self without unsafe-inline.
    • Expanded portable, browser, no-script, and Apache regression checks for server-rendered search, search parity, filter semantics, navigation focus integrity, and the stricter content-security policy.
    Version 1.0.4 Progressive enhancement and parser-differential resilience

    2026-08-23-resilience-1 ·

    Restores complete mobile navigation without JavaScript, removes hidden keyboard focus targets, normalizes generated heading hierarchies, makes manual requests authoritative over delayed automation, and rejects ambiguous OOXML ZIP structures and unsafe UTF-8 truncation while preserving successful public routes, APIs, governed report bodies, discovery signals, and the dependency-free runtime contract.

    • Made the complete compact navigation visible and static at narrow widths when JavaScript is unavailable, while hiding controls that require scripting.
    • Removed the hidden back-to-top control from the tab order until it is visible, synchronized its accessibility state, honored reduced motion, and returned focus to the main landmark after activation.
    • Normalized rendered Markdown heading jumps and corrected generated laboratory result headings so the main content hierarchy no longer skips levels.
    • Added explicit request ownership to homepage inspection, local search, and laboratory automation so stale, cancelled, delayed, or superseded responses cannot overwrite current user intent.
    • Bound display filenames by valid UTF-8 bytes without splitting a code point or introducing replacement characters.
    • Required exact EOCD, central-directory, local-header, filename, method, flag, CRC, size, data-boundary, and non-overlap agreement before extracting an OOXML ZIP entry.
    • Expanded Chromium coverage with all-page no-JavaScript mobile checks, hidden-focus and heading-order assertions, search-dialog state checks, back-to-top focus checks, and request-race regression tests.
    • Added adversarial local/central OOXML mutations and UTF-8 filename boundaries to multipart smoke coverage while retaining valid PDF, DOCX, and PNG inspection.
    Version 1.0.3 Accessibility, rendering, and API boundary hardening

    2026-08-23-accessibility-1 ·

    Closes 320-pixel navigation, grid, and governed-report rendering defects; centralizes strict JSON/multipart endpoint boundaries; and expands real-browser and API regression coverage while preserving successful public routes, response fields, laboratory actions, governed source bodies, discovery signals, and the dependency-free runtime contract.

    • Gave the compact navigation toggle an explicit state-synchronized accessible name when its visible label is hidden at the narrowest breakpoint.
    • Allowed generic responsive grid children and collapsed tracks to shrink below intrinsic min-content width at 320 CSS pixels.
    • Compacted embedded base64 image reference definitions during Markdown rendering without changing any hash-governed research source body.
    • Expanded Chromium checks to all 62 sitemap pages plus the noindex search utility at desktop and 320-pixel mobile sizes.
    • Added smoke assertions that reject raw embedded-image data-reference leakage from public research pages.
    • Centralized JSON and multipart response policy, method/origin/media-type/body-size checks, bounded error objects, and UTF-8 validation in a dependency-free shared API helper.
    • Aligned client maxlength attributes with the 4,096-byte inspector and 120-character search boundaries, and expanded smoke coverage across utility, laboratory, multipart, origin, shape, and size failures.
    Version 1.0.2 Browser and Apache conformance hardening

    2026-08-23-conformance-1 ·

    Corrects narrow-viewport overflow and adds locally reproducible real-browser and Apache policy checks while preserving stable routes, APIs, content, discovery signals, and the dependency-free runtime contract.

    • Allowed responsive grid children and long source links or headings to shrink and wrap instead of widening the mobile document.
    • Added a Python-standard-library Chromium DevTools smoke command covering desktop/mobile layout, accessibility trees, paint output, and key interactions without external navigation.
    • Added an isolated self-signed HTTPS Apache smoke command that executes PHP and verifies packaged .htaccess redirects, headers, caching, compression, denials, raw-resource policy, and custom errors.
    • Added an extended non-deploying release path that runs portable, browser, Apache, package, extraction, and reproducibility gates together.
    Version 1.0.1 Reproducible package hardening

    2026-08-23-reproducible-1 ·

    Makes root-deployment ZIPs byte-reproducible across clean extractions while preserving stable routes, APIs, content, discovery signals, and the dependency-free runtime contract.

    • Normalized runtime ZIP member timestamps instead of copying source filesystem mtimes.
    • Added independent same-source and clean-extraction rebuild proofs that require byte-identical archives and SHA-256 values.
    • Enforced deterministic member ordering, canonical Unix ZIP metadata, compression, bytes, modes, and repository-only exclusions.
    • Published compatible patch version 1.0.1 without changing canonical route or API contracts.
    Version 1.0.0 Versioning and discovery baseline

    2026-08-22-discovery-1 ·

    Begins formal semantic versioning and strengthens crawl, entity, answer, and generative-search signals without changing the dependency-free runtime contract.

    • Published a canonical release-notes and version-history page.
    • Added version metadata to HTML, JSON-LD, PHP responses, APIs, and Apache headers.
    • Linked page entities explicitly in structured data and tightened discovery validation.
    • Added noindex response policy to utility JSON APIs while preserving crawlable HTML content.
    • Expanded the repository harness to verify technical SEO, answer-readiness, and generative-search fundamentals.
    Pre-version Michael Kappel profile and contact

    2026-08-22-profile-1 ·

    Added the canonical professional profile/contact route and connected it to MikeKappel.com.

    • Added /michael-kappel/ with ProfilePage and Person structured data.
    • Integrated the profile into navigation, search, sitemap, and the machine-readable site guide.
    Pre-version Dedicated laboratory release

    2026-08-22-labs-1 ·

    Expanded the site into 26 focused laboratories with 42 allowlisted actions and bounded local APIs.

    • Added the dedicated lab catalog, clean routes, local JSON actions, and multipart file inspection.
    • Preserved fixed-marker, no-external-effects safety boundaries.
    Pre-version Cinematic public-site baseline

    2026-08-21-cinematic-1 ·

    Established the current responsive visual system, task-first homepage, local search, and asset-versioned dependency-free shell.

    • Introduced the current cinematic homepage and progressive-enhancement navigation.
    • Added content-derived asset hashes and the X-MT-Release diagnostic header.
    VerificationTwo public headers
    Use the semantic version to understand compatibility and the release ID to identify one exact build.
    X-MT-Version: 1.6.0X-MT-Release: 2026-08-27-claim-traceability-1

    The same values are exposed in HTML metadata, WebSite/WebPage JSON-LD, and the global footer. Runtime ZIPs are separately bound to a SHA-256 sidecar by the repository harness.

    Versioning FAQ

    Questions about releases and compatibility

    What is the difference between the site version and the release ID?

    The semantic version communicates compatibility: major for breaking public contracts, minor for backward-compatible features, and patch for compatible corrections. The calendar-stamped release ID identifies one exact packaged release.

    Will published MachineTradecraft.com URLs remain stable?

    Yes. Existing canonical routes should remain stable. An intentional move requires a one-hop permanent redirect, updated internal links and sitemap entries, and validation before release.

    How can a client confirm which release it received?

    Read the X-MT-Version and X-MT-Release response headers. The same values appear in HTML metadata, structured data, the footer, and this page.