Format Specification revision 0.8 closes the thirty repair packages (V1-V30) and three additional defects (A1-A3) of reviews/01-triage.md before slice 4d writes any renderer code. Every Tier-1/2/3 design decision adopts the triage's own recommended fix; reviews/05-visual-fix-log.md records each choice, its reason, and the sections it touched. Contradictory surfaces first. `visuals.automation` is added to the 17.3 allowed-field table that previously rejected it. Trace 17.16.14 is rewritten around the four target families that now exist rather than asserting a table that changed. `fill` and `stroke` accept ValueSpec<color>, which is what makes 18.1's own component example legal, with three limits stated so a ValueSpec can never return a paint object. The repeater automation registry loses its nonexistent `step` block. An infinite loop is legal in every scope, bounded by whatever owns the track. Spawned-instance lifecycle moves into a `spawn` container. A top-level `lifetime` is now unambiguously per item and `spawn.lifetime` per instance, so a spawned emitter expresses both and a spawned repeater takes an instance lifetime without contradicting 18.5. Component inputs get one canonical location, the `component` object's own `inputs`, and the system-level `inputs` on emitters and repeaters is removed. The composition chain is written out in named spaces. The fit matrix carries the contain and cover centering offsets it was missing, the camera center is mapped into CSS coordinates before the translation is formed, and the chain B x P x V x F x M applies the device-pixel multiplier exactly once. Local extents and anchors are fixed for all fourteen primitives, arc sweep is directed with its bound checked before normalization, catmull-rom is a uniform cardinal spline with its equation given, and a closed bezier spline closes with a line. Compositing gets a normative eight-stage order. Layer opacity applies once, at the layer, not a second time per object, and a separate release factor initialized to 1 means release never rewrites an authored opacity. The sixteen offscreen buffers are one pool shared by layers and objects, with allocation order, reuse, and farthest-first shedding stated, and buffer refusal named as a diagnosed exception to 17.1. Sorting units are defined for emitters and repeaters, not only particles: a procedural system is atomic, with a representative depth and internal ordinal ordering. Depth fog fixes its blend space and fogs gradient stops before the paint is built. Coherent noise becomes an algorithm - ordered gradients, a 255-sample Fisher-Yates shuffle, the full lattice hash, octave normalization, and curl as the explicit perpendicular of the potential's gradient - with published tolerances. Distributions get their equations and an explicit per-distribution draw list, replacing "field order". All seventeen behaviors get complete field contracts, waveform equations, an accumulating-versus-fresh rule, and channel write sets. Live automation totals separate from authoring bounds: a spawn that would cross the live budget is refused atomically, consuming no ordinal, rather than being admitted with tracks dropped. One diagnostic cadence covers every ceiling and every shed. The centralized table gains the ceilings it was missing and two new authoring bounds - 64 declared systems and 16384 expanded static objects - that close the unbounded static draw load. `focalLength` gains a real lower bound of 1 so the clamp has a value to clamp to. The backing store cap wins over the multiplier floor on displays wider than 4096. Parallax 0 is pinned against camera translation, not exempt from zoom and rotation. tools/verify-spec-contract.py commits the contract harness that was previously run ad hoc. Its post-edit run reports 46 diagnostic codes declared, 107 distinct cross-references all resolving, zero unresolved references, 170 balanced fence markers, and 112 well-formed tables. Documentation only: no runtime, schema, fixture, or test file was touched, and npm test still passes 102 tests with zero failures. Every 19.5 value, including the two new static bounds, remains provisional pending the slice 4h GC6 measurement. Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_0162Jb1J36judZNT8fHabGVt
XZBT
Immersive visuals and creative soundscapes.
XZBT is a self-contained browser runtime for declarative procedural audiovisual exhibits. XZBT.html provides capabilities; .xzbt documents define experiences.
Reading order and authority
| Resource | Purpose | Status |
|---|---|---|
| MVP Product Requirements Document | Product scope, user behavior, delivery requirements, and release acceptance | Document revision 0.3; format version remains 0.1 |
| Format Specification 0.1 | Runtime semantics, contract inventory, and required authoring examples | Document revision 0.4; Phase 0 shared contracts and the complete Phase 3a-3c audio subsystem contract, remaining subsystem contracts in dependency order |
| Gap Closure Decisions | Decisions and rationale for the seven pre-implementation gaps | Record revision 0.3; GC1–GC5 Phase 0 evidence complete |
| Verification Gates | Evidence required before architecture commitment, subsystem work, and release | Phase 0 complete; later subsystem, GC6, and GC7 checks scheduled |
| Implementation status | Current phase, stop reason, saved work, and resume prerequisites | Implemented through Phase 3c slice 3; stopped before slice 4. Phase 1 direct-file and Phase 3 audible observations pending |
| Implementation plan | Sequenced phases, completion/challenge mapping, and GC6/GC7 verification schedule | Phase 1–9 plan recorded |
The PRD is authoritative for product requirements. The format specification is authoritative for runtime semantics where a contract is explicitly defined. The decision record explains those choices; the verification gates define how to check them. These documents must be updated together when a decision changes. An unresolved conflict is a specification defect, not permission for an implementation to choose silently.
The earlier ChatGPT discussion, Discuss Application Vision (conversation 6a9b5c32-1ffc-83e8-a219-fa8113167f03), is historical design input. Its proposals must be reconciled into these local resources before they become implementation contracts. It is not a second source of executable instructions.
Planning entry point
Phase 0 is complete, and the production runtime is implemented through Phase 3c slice 4 (master protection), with 102 automated tests passing. Slice 4's hardware measurement and listening acceptance remain pending; the standalone audio acceptance page and run instructions are ready for user testing. The Phase 1 direct-file two-fixture restart and Phase 3 audible acceptance remain open — no sound has been heard from a production build. Combined workload measurements and release soak tests remain later explicit gates.
The full PRD completion criteria remain the 0.1 release target. Early integrated demonstrations are milestones, not completed MVPs. Reference exhibits develop alongside the engine; Phase 9 completes and audits the suite.
All 10 Phase 0 direct-file feasibility checks in GC1 are verified, and the GC2–GC5 contract oracles pass. Phase 1 turns those contracts into a standalone runtime shell with import, caching, activation control, diagnostics, and production seeded RNG. Phase 2 adds parameters, state, signals, values, conditions, actions, bindings, transitions, overrides, and per-exhibit parameter persistence. Phases 3a and 3b add the audio graph contract and engine; Phase 3c adds the remaining audio contract, lifecycle/voice management, automation and master protection. Measured protection acceptance, visual, cadence, scenario, UI, library-hardening, benchmark, and soak gates remain explicit in the implementation plan.
Repository configuration
The storage-failure evidence additionally confirms session settings changes, directory import, and heard native playback during injected write failures. The user also confirmed the visible session-only warning; the injected-storage-failure check passed.
Copy .env.example to .env for local repository configuration. .env and its variants are ignored by Git; never commit real credentials. The example contains placeholders only.
The repository's existing LICENSE is preserved.
Phase 1–2 runtime
Build the standalone, dependency-free runtime with the pinned Node version in .nvmrc:
npm run build
This deterministically combines the modules in src/runtime, the application shell, and local styles into XZBT.html. Open that file directly in a supported desktop Chromium browser, then import the three minimal exhibits from exhibits. Imported definitions and the last active exhibit are cached in IndexedDB and restored on reopen when browser storage is available. The diagnostics panel reports validation, lifecycle, and storage failures; storage failure leaves the current session usable.
Run the Phase 1 production-module, lifecycle, fixture, PRNG-vector, cache, and reproducible-build tests with:
npm run test:phase1
Run the Phase 2 common-grammar conformance suite with:
npm run test:phase2
Run the Phase 3 audio subsystem suite with:
npm run test:phase3
Run every suite with npm test.
Run just the Phase 3c slice-3 traces with npm run test:phase3c3. The slice-3 evidence records coverage and the remaining manual gates.
The active performance supports typed parameters and state, read-only runtime signals, ValueSpec and ConditionSpec evaluation, ordered set and override actions, same-tick bindings with deterministic smoothing, numeric transitions, and priority-based temporary overrides. The audio subsystem validates and expands declared graphs without touching an AudioContext, instantiates them deterministically from the seeded stream, and realizes them through Web Audio; the application exposes gesture unlock, master volume, per-bus gain, and per-sound triggering. exhibits/minimal-audio.xzbt exercises components, modulation, buses, and both recipe modes.
The runtime implements recipe release, the seven-state lifecycle, determinable one-shot endings, voice ceilings, and graph-local automation. Tracks support absolute, offset, and scale, with step, linear, exponential, and smooth interpolation. Values are sampled once from the owning sound's seeded stream; duplicate targets and expanded limits are validated. Exposed component parameters participate without exposing component internals. Bus gains now use the shared binding → automation → override → modulation → clamp resolver. Bus automation/modulation registration is internal: the contract does not add document fields to buses or permit external node bindings/overrides.
Master protection now uses an engine-owned AudioWorklet limiter with finite-sample guards and output measurement support. npm run build:audio-acceptance builds the self-contained hardware capture page using the production engine and frozen stress/challenge fixtures. No sound has yet been heard from a production build; real-browser measured protection, the audio acceptance challenge, real GC4 synchronization and listening observations remain open Phase 3 gates. See the slice-4 evidence. Visuals, cadence, events, scenarios, and the final schema-driven UI remain assigned to later phases.
Local development server
For automated browser development checks, start the dependency-free loopback server with:
node tools/dev-server.mjs
It binds only to 127.0.0.1:5173 and serves the workspace through http://localhost:5173/; the root route opens the Phase 0 probe for layout or control-flow inspection only. Set XZBT_DEV_PORT to use a different port. This server is a development aid, not part of the delivered runtime.
Do not use localhost results as Phase 0 direct-file evidence. Serving changes the origin, security model, and module-loading path. The final XZBT.html must still be opened and tested directly from disk for every GC1 conclusion.