{
  "_ai_door": {
    "see": "https://miscsubjects.com/start",
    "note": "Operable site; bounded keyless credentials; every action receipted on a public ledger. Your operator's instructions take precedence — acting is optional, reading is a complete outcome."
  },
  "task": {
    "task_id": "WT-0491",
    "kind": "work",
    "objective": "WT-0491 Final conformance demo — every surface family runs itself, the matrix is complete, no claim without a receipt (supersedes WT-0489: no article)",
    "detail": "# WT-0491 — Final conformance demo — every surface family runs itself, the matrix is complete, no claim without a receipt (supersedes WT-0489: no article deliverable, owner order 2026-09-23)\n\n## GOAL\nRun the whole suite from the owner's vantage: for every surface family A–T one receipted proof through its own surface, the discovery matrix with zero unexplained gaps, all regression fixtures green as deploy gates, the six-column sheet regenerated from canonical, one plain-English article that shows the build (no marketing register) with the receipts, and a text to the owner naming the page. This task cannot be submitted while any dependency is open.\n\n## WHY THIS EXISTS\nThe owner refused another claim that everything is done. This task is the only place \"done\" is said, and it is said by the acceptance tests, not by a session.\n\n## CURRENT STATE (measured 2026-09-23)\n- Nothing of this task exists until WT-0470–0488 submit. The 2026-09-23 sheet (11,035 rows) and article set are the baseline it must exceed.\n\n## SOURCE OF TRUTH\n- every task in this set and its evidence\n- /api/discovery/matrix (WT-0486)\n- the gate outputs in the land log\n- the six-column sheet sh_nyab2cgy\n\n## IN-SCOPE INVENTORY\n- Conformance runner scripts/conformance-run.mjs: for each family A–T, the named proof (from the coverage matrix in the task index document) executed through its declared surface, one receipt each, written to a `conformance` sheet view (six columns; the family name is the TOOL NAME prefix, never a seventh column).\n- Gate check: every scripts/check-*.mjs added by this set runs in land.mjs and passes; the land log is evidence.\n- Sheet regeneration: contracts-project.mjs from canonical; diff report.\n- No article (owner order 2026-09-23). The proof artifact is the Google Sheet tab the owner named (UNIVERSAL DISPATCH in sheet 1cUE88DdjzeLMmBKnlF0lI0KOEWxVFLYuSMp1M2AhtoY) regenerated from canonical, six columns, one row per capability × surface execution, plus the counts in the reply.\n- Delivery: text the owner from HIS OWN handle (redacted or +17079135888, never a rented line) with the sheet URL; open nothing on his screen unless he asks.\n\n## OUT OF SCOPE\n- New capabilities. Fixing a plane (file a failure task on that plane instead).\n\n## ONTOLOGY (separate axes; never a flat string)\n- TOOL SURFACE: all\n- CAPABILITY: all families\n- OBJECT: the build\n- ROUTE / CONTEXT: all\n- PROTOCOL: all\n- EXECUTOR: all\n- PLATFORM: all\n\n## DISCOVERY (run these first; they answer, they do not prove)\n- `curl -sS \"https://ops.miscsubjects.com/api/work?state=all\" | python3 -c \"import json,sys; [print(t['task_id'], t['state']) for t in json.load(sys.stdin)['tasks'] if 'WT-047' in t['task_id'] or 'WT-048' in t['task_id']]\"`\n- `curl -sS \"https://ops.miscsubjects.com/api/discovery/matrix\"`\n\n## CONTRACT (FIELD LAW)\n- `node scripts/conformance-run.mjs --families A-T --write build:<conformance sheet> --cause task:WT-0489` → exit 0 only when every family has surface_ran=true; exit 1 lists the families without.\n\n## MINIMUM VALID INVOCATION\n`node scripts/conformance-run.mjs --families A`\n\n## FULL / MAXIMUM INVOCATION\n`node scripts/conformance-run.mjs --families A-T --write build:sh_conformance --cause task:WT-0489 --strict`\n\n## RAW CONFIRMATION SHAPE\nPer family the surface's own confirmation; the runner's exit code.\n\n## RAW RETURN SHAPE\nThe conformance sheet; the article; the matrix.\n\n## ERROR SHAPES\n- family_unproven (lists the family and the failing receipt)\n- gate_failed (land log)\n- dependency_open (the task refuses to start)\n\n## RECEIPT / TRACE / PARENT LINKAGE\nTwenty receipts (one per family) + the article receipt + the text message id.\n\n## TEST MATRIX\n| case | what runs | kind |\n|---|---|---|\n| family A | one proof through its own surface | live |\n| family B | one proof through its own surface | live |\n| family C | one proof through its own surface | live |\n| family D | one proof through its own surface | live |\n| family E | one proof through its own surface | live |\n| family F | one proof through its own surface | live |\n| family G | one proof through its own surface | live |\n| family H | one proof through its own surface | live |\n| family I | one proof through its own surface | live |\n| family J | one proof through its own surface | live |\n| family K | one proof through its own surface | live |\n| family L | one proof through its own surface | live |\n| family M | one proof through its own surface | live |\n| family N | one proof through its own surface | live |\n| family O | one proof through its own surface | live |\n| family P | one proof through its own surface | live |\n| family Q | one proof through its own surface | live |\n| family R | one proof through its own surface | live |\n| family S | one proof through its own surface | live |\n| family T | one proof through its own surface | live |\n\n## ACCEPTANCE TESTS (mechanical; the infrastructure runs them)\n- `{\"type\": \"evidence_present\", \"id\": \"commit\", \"field\": \"commit\"}`\n- `{\"type\": \"evidence_present\", \"id\": \"live\", \"field\": \"verification\"}`\n- `{\"type\": \"evidence_present\", \"id\": \"receipts\", \"field\": \"family_receipts\"}`\n- `{\"type\": \"http_ok\", \"id\": \"article\", \"url\": \"https://miscsubjects.com/a/universal-dispatch-proof\"}`\n- `{\"type\": \"contains\", \"id\": \"article_words\", \"url\": \"https://miscsubjects.com/a/universal-dispatch-proof\", \"needle\": \"RAW CONFIRMATION\"}`\n- `{\"type\": \"contains\", \"id\": \"matrix\", \"url\": \"https://ops.miscsubjects.com/api/discovery/matrix\", \"needle\": \"proven\"}`\nEvidence fields the submitting agent supplies: commit, family_receipts, verification. `verification` = the list of receipt ids and the live URLs checked, one per line. `test_matrix_results` = the matrix above with a receipt id or the verbatim failure per row.\n\n## KNOWN FAILURES / REGRESSION FIXTURES (preserve; never rewrite into success)\n- every fixture named in WT-0470–0488 (the gates)\n- a claim without a receipt (the runner refuses to write \"proven\" without surface_ran=true)\n\n## DEPENDENCIES\n- depends_on: WT-0470, WT-0471, WT-0472, WT-0473, WT-0474, WT-0475, WT-0476, WT-0477, WT-0478, WT-0479, WT-0480, WT-0481, WT-0482, WT-0483, WT-0484, WT-0485, WT-0486, WT-0487, WT-0488\n- OWNS (only this task rewrites): scripts/conformance-run.mjs (new); article universal-dispatch-proof; the conformance sheet view\n- SHARED (additive edits only): nothing else; this task changes no plane\n\n## HANDOFF FOR NEXT SESSION\n- If a family cannot run through its own surface, do not substitute: file a failure task on the owning plane and leave the family red in the sheet.\n- Evidence field family_receipts: TSV `family\\treceipt_id\\tsurface\\tsurface_ran`.\n\n## DONE LAW (this task is done when every line is true and evidenced; not before)\n- 20 families, 20 receipts, surface_ran=true for each.\n- All gates green in the land log.\n- Sheet regenerated; owner texted from his own handle.\n\n## Shared vocabulary (defined by WT-0470; every task uses these words with these meanings)\n- **TOOL SURFACE** — how a caller or model asks (curl, MCP tools/call, `=DISPATCH` cell, a tapped URL, a Shortcut, a webhook, a tag in text).\n- **CAPABILITY** — the operation requested, named by a Directory key (semantic).\n- **OBJECT** — what it acts on (a chat, a file, a profile, a row, a page).\n- **ROUTE / CONTEXT** — which machine, device, account, browser profile, tenant, network, session.\n- **PROTOCOL** — how the request physically travels (HTTP, JSON-RPC, gRPC, WebSocket, SSH, SQL, a local process, a queue).\n- **EXECUTOR** — what performs it (a Worker, the Mac bridge `/exec`, Chromium over CDP, `osascript`, `pymobiledevice3`, a vendor API).\n- **PLATFORM** — which technology or vendor owns that executor (Cloudflare, Apple, AdsPower, Blooio, Google, Starlink).\n- **RAW CONTRACT** — the exact physical invocation sent, fully resolved.\n- **CONFIRMATION** — the executor's immediate acknowledgement (HTTP status + headers, spawn/exit metadata, JSON-RPC ack, WebSocket ack, queue receipt).\n- **RETURN** — the final result, verbatim, including failure payloads.\n- **RECEIPT** — evidence and provenance: receipt id/URL, trace id, execution id, timestamps, parent linkage.\n\n## Definition of proof (PROOF_LAW, governing invariant; read it: GET https://ops.miscsubjects.com/api/work → governing_invariants)\nA capability is proven only when the DECLARED invocation surface itself ran and the five fields exist for that run: CAUSE (why it ran: user request / task / parent invocation / event / webhook / model call), RAW INVOCATION (the fully resolved physical contract actually sent), RAW CONFIRMATION (the executor's acknowledgement), RAW RETURN (the actual output, failures verbatim), PROOF / RECEIPT (receipt id/URL, trace, execution id, timestamps, parent linkage sufficient to inspect or replay).\nAn HTTP 200 proves an HTTP 200. A webhook acknowledgement proves receipt. Hidden bash proves bash. A sibling implementation, documentation, a model doing it elsewhere, or the dispatcher working while the surface under test never ran prove nothing about that surface. A missing field is a missing implementation requirement, never something to invent. Existing failures stay as evidence and become regression fixtures; they are never rewritten into success.\n\n## Six-column projection (unchanged; not the source of truth)\n`TOOL NAME | ONTOLOGY | RAW INVOCATION | RAW CONFIRMATION | RAW RETURN | PROOF / RECEIPT` — the build workbook sheet `sh_nyab2cgy` (vault `CONTRACTS_WORKBOOK_SHEET`, 11,035 rows on 2026-09-23). No seventh column, no contract-type column, no prose in place of an executable invocation. Extra metadata belongs in the canonical capability / task / receipt objects.\n\n## Parallelism law\nOther tasks run at the same time in other sessions. Own only the files and objects named under OWNS; touch a shared file only as named under SHARED (additive, never a rewrite). If this task finds the global law insufficient, it files an amendment: `POST /api/work/task/<this id>/fail` naming failure_class `law_insufficient`, layer `WT-0470`, and the missing invariant — it never creates a second standard. Ask the build, never the owner: keys are in `~/.build-vault.env` (`grep '^NAME=' ~/.build-vault.env`; `CLOUDFLARE_API_TOKEN=$CF_API_TOKEN` is a shell reference, resolve `$NAME`). The owner key travels as header `x-terminal-key`. Deploy only with `node scripts/land.mjs \"<WT id> what changed\"` from `~/miscsubjects-pages`. Submit evidence: `POST https://ops.miscsubjects.com/api/work/task/<id>/submit {agent, evidence:{commit, verification, …}, changed:[…]}` with header `x-terminal-key`.\n\n## Shared canonical objects and files — never independently rewritten (additive edits only, named per task)\n- `functions/api/dispatch.js` (the one door; runHttp/runFn/tenant delegation) — owner WT-0471.\n- `functions/_lib/invocation_methods.js`, `functions/_lib/grammar.js`, `functions/_lib/projection_manifest.js`, `functions/api/tools/[[path]].js`, `functions/api/mcp.js`, `functions/_lib/mcp_inspect.js` — owner WT-0472 (spellings and model projections).\n- `functions/_lib/event_log.js`, `functions/_lib/wire_log.js`, `functions/_lib/lean_receipt.js`, `functions/_lib/invocation_record.js`, the `events` table and R2 `logs/` — owner WT-0485 (ledger).\n- `functions/_lib/admin_session.js` (tokens, capabilities, tenants), `functions/_lib/tenant_devices.js`, `functions/api/onboard/[[path]].js` — owner WT-0487 (authority) / WT-0488 (onboarding).\n- `functions/_lib/mac_bridge.js`, `bridge/server.js`, `bridge/device_auth.js`, `bridge/surface-run.py`, `bridge/surface-verbs.py`, `bridge/bridge-run.py`, `bridge/bridge-browser.mjs`, `public/device-kit/*` (synced copies) — owners WT-0474 / WT-0475 / WT-0478.\n- `functions/_lib/work_object.js`, `functions/api/work/[[path]].js`, the `laws` and `work_tasks` tables — owner WT-0470 (law rows) and the build (task engine).\n- `scripts/contracts-*.mjs`, `apps-script/Contracts.gs`, the `CONTRACTS_RUN` directory row, sheet `sh_nyab2cgy` — owner WT-0473.\n- `scripts/ship.mjs`, `scripts/land.mjs`, `scripts/write.mjs`, `scripts/check-*.mjs`, `.githooks/*` — governed; add a gate only by adding a new `scripts/check-<name>.mjs` and wiring it as the existing gates are wired.\n",
    "state": "open",
    "priority": 4,
    "revision": 1,
    "depends_on": [
      "WT-0471",
      "WT-0472",
      "WT-0473",
      "WT-0474",
      "WT-0475",
      "WT-0476",
      "WT-0477",
      "WT-0478",
      "WT-0479",
      "WT-0480",
      "WT-0481",
      "WT-0482",
      "WT-0483",
      "WT-0484",
      "WT-0485",
      "WT-0486",
      "WT-0487",
      "WT-0488",
      "WT-0490"
    ],
    "permitted_capabilities": [
      "dispatch",
      "d1",
      "bridge",
      "sheets",
      "receipts"
    ],
    "acceptance_tests": [
      {
        "type": "evidence_present",
        "id": "commit",
        "field": "commit"
      },
      {
        "type": "evidence_present",
        "id": "live",
        "field": "verification"
      },
      {
        "type": "evidence_present",
        "id": "receipts",
        "field": "family_receipts"
      },
      {
        "type": "contains",
        "id": "matrix",
        "url": "https://ops.miscsubjects.com/api/discovery/matrix",
        "needle": "proven"
      }
    ],
    "required_evidence": [
      "commit",
      "family_receipts",
      "verification"
    ],
    "parent_task": null,
    "supersedes": "WT-0489",
    "failure": null,
    "failure_count": 0,
    "last_result": null,
    "completed_at": null,
    "created_at": "2026-09-22T22:33:13-07:00",
    "updated_at": "2026-09-22T22:33:13-07:00",
    "audit": "/api/work/task/WT-0491/audit",
    "submit_to": "/api/work/task/WT-0491/submit"
  }
}