← E2T System V1 portal

20 — PROTECTION MANIFEST

Freeze exactly which source pixels and structures SWEEP must preserve.

PARTIAL Partly built

Package sealing and hash-binding are implemented. The protection mask manifest itself is not.

Deterministic Reconstruction 0 archived step 20 of 26

Where this output sits

Source evidenceCandidate evidenceHuman decisionAudit acceptanceReleaseProduction

Source evidence, candidate evidence, human decision, audit acceptance, release and production are six separate things. This step produces the highlighted one and nothing further.

Scope

Intended to freeze exactly which pixels may be swept and which are protected, listing accepted text masks with explicit removal authorisation against protected classes — media, logo, ornament, frame, rule, box, table structure, header, footer and page furniture text — each with frozen dimensions and hash.

This role is allowed to

How it works

Inputs
CAP glyph masksAccepted header/footer/rule/table/media/ornament evidenceCompleteness ledger
Deterministic Deterministic mask compiler.

No internal sequence is documented for this step — only the contract above and below it. Nothing was invented to fill the gap.

Must pass
  • Manifest frozen before SWEEP
  • Every protected area has accepted parent evidence
passes →
Outputs
Protected-pixel maskProtection object IDs, reasons and hashesZero-change denominators
hands off to SWEEP · QA
fails →
HOLD
PROTECTION_UNBOUNDPROTECTION_OVERLAP_CONFLICTPROTECTION_MANIFEST_CHANGED

Nothing continues on a failed gate. Uncertainty becomes an explicit HOLD, and no later step may read an unanswered item as an accepted one.

Non-scope — what this role does NOT own

Explicitly forbidden

Dependencies and position

Starts
After COMPLETENESS, STYLE, ROLE, PIC and TABLE evidence.
Previous step
19 EXTRACT
Next step
21 SWEEP
Hands off to
SWEEP, QA

Exact inputs

Exact outputs

Performer and AI/ML boundary

Performer
Deterministic mask compiler.
Class
Deterministic
AI boundary
None.

Training information

Not a trained component. No model, no weights, no training corpus. Behaviour is fixed by code and configuration, and identical inputs must produce identical outputs.

Deterministic validation and acceptance gates

HOLD and failure behaviour

Failure codes this step may emit:

Uncertainty becomes an explicit HOLD. Omission never converts uncertainty into acceptance, and no downstream step may treat an unanswered item as an accepted one.

Downstream handoff

SWEEP, QA

Active tool

Status
Partial
Run / inspect
python tools/seal_package.py <package_dir>
Input
MAP/STYLE/PIC/TABLE evidence + CAP masks
Output
PACKAGE_SHA256.txt — freeze only; the mask manifest is missing

Dependencies

Why this is the active version

seal_package.py provides hash-binding and freezing, reused unchanged from V47 through V114. But hash-sealing a package is not the artifact the V10 closure defines as the protection manifest: a set of accepted TEXT and TABLE_TEXT masks with explicit removal authorisation, against protected classes MEDIA, LOGO, ORNAMENT, FRAME, RULE, BOX, TABLE_STRUCTURE, HEADER, FOOTER and PAGE_FURNITURE_TEXT, each with frozen width, height, encoded size and SHA-256. No implementation emits that manifest. Marked PARTIAL with the gap stated rather than papered over.

Copied files — source receipt

FileOriginal SHA-256BytesCopy
seal_package.py 775e4fd674a6457f… 1,580 verified
ARCHITECTURE_DELTA_V10.md 691ecfabc8d0e2ad… 1,832 verified

2 file(s), all hash-verified against the original. Full detail in tool/SOURCE_RECEIPT.json. Copy-only: the historical source is never modified.

Archived versions

No superseded versions recorded for this role.

Known limitations

Security and privacy

Operates on frozen local artifacts. No credentials required. No data leaves the machine.

Cost behaviour

No provider calls. No metered cost. Compute is local.

Copying a tool into this repository does not authorise running it, retraining it, calling a model, or processing a new issue. No paid call may be made without the owner's explicit authorisation and a hard cost cap.

Provenance

Registry
registry/roles.json (schema marsoom.e2t.roles.v1)
Derivation
28 legacy roles - VER - HUMAN + REV = 27 active steps
Legacy role id
PROTECTION
Legacy source SHA-256
6f5d5d7ed8869e45307424c2193f95ffab84abc44a6a188f5c7f98c2a48ec64d
Generated
2026-09-04T22:13:12.433Z

Feedback and decisions

Feedback is recorded per source and never merged into an invented consensus. Where sources disagree, both positions stand and the owner decides.

SourceEvents
Naser / owner
Final authority. Overrides every other source.
none recorded
Codex / orchestrator
Architecture and sequencing.
none recorded
Builder / designer
Implementation reality and constraints.
none recorded
Independent reviewer
Adversarial review of claims.
none recorded
Auditor
Evidence verification against artifacts.
none recorded
Human REV reviewer
Page-level truth from the review site.
none recorded

Recorded events

No feedback events recorded yet. The ledger exists and is append-only: feedback/FEEDBACK_LEDGER.jsonl.

Editing feedback is not possible: a change is a new event whose supersedes names the one it replaces, and the original stays exactly as written.


Generated from registry/roles.json by tools/build-reports.mjs. Do not hand-edit — edit the registry and rebuild.
Original page pixels are the visual authority. CAP owns the exact captured text.