Live baseline
- Zotero Local API
http://127.0.0.1:23119/api/ remains read-only for the recorded Zotero 9.0.6 / API v3 local campaign; last recorded immutable read-only snapshot is library version 12341, 8,326 observed records.
- Query/classifier output is discovery/proposal evidence, never authoritative classification.
- Zotero 10+ reviewed write paths remain separately gated by user authorization, exact server/item/library preconditions, reversible receipts and the provider transport boundary.
- Provider-defined Local API write transport is loopback HTTP.
Zotero-Server-ID is database-instance continuity/precondition evidence, not cryptographic peer authentication; same-host API-key confidentiality remains a release boundary unless protected transport appears or governance explicitly narrows the supported threat model.
Current successor authority — 2026-09-05
The full Draft chain was non-force restacked after the Foundation product/technical gap baseline refresh. Every successor retains its previous semantic head as first parent and adopts the current direct parent as second parent; no force-push/destructive rebase or predecessor-evidence transfer occurred.
#9 256076d -> #10 b821b0f -> #11 cb365fb -> #12 5ce1a18 -> #13 821b04c -> #15 64cb10f -> #16 d02d0f9 -> #17 47e86b5 -> #18 bb8ef8c -> #19 b6c11b2 -> #20 53a91d3 -> #21 d51762d -> #22 2c8ee56 -> #23 17a0407 -> #24 005826d -> #25 8a239ee -> #26 0f5002e -> #27 9d89805 -> #28 2de9254 -> #29 98204ff -> #30 ddd0e4c -> #31 e5a1e52 -> #32 0ac89b6 -> #33 4feb387 -> #34 062a0d9
Foundation is #1 b538470c963e6524ddc0c3f652a46a4fc8265150. All Zotero successors remain Draft and require their own unchanged exact-head protected evidence after the restack.
Preserved contracts and unresolved release boundary
#15 retains receipt binding to review/authority/server/Zotero-version/library/rule/snapshot coordinates, complete DryRun not-attempted enumeration, and conditional inverse evidence only when server/item identity remains proven. #18 keeps the loopback-HTTP provider threat explicit and does not authorize an enterprise-secure live-write claim. #30's private-input boundary rebuilds metadata/open paths from an authorized canonical parent plus filename and keeps O_NOFOLLOW, exact 0600, single-link and bounded-input checks. #33 provides deterministic non-reserving steward batches. #34 reconstructs and compares the exact human-visible batch context before converting decisions to the atomic patch, and its production output validator rebuilds the output path from the authorized canonical parent plus final filename before create-new writing.
These are source contracts, not inherited hosted GREEN. The complete steward-review denominator remains 3,715 proposals; unverified worksheet decisions remain 0/3,715, and externally approved steward labels independently remain 0/3,715. No live steward decision, Zotero write/rollback, governed publication or immutable release is claimed.
Acceptance boundary
Acceptance still requires one immutable top-level bibliographic snapshot, one proposal per paper, complete item/library/rule/snapshot provenance, reversible duplicate review, default dry-run, Zotero 10+ reviewed-authority/precondition/transport gates, reversible write evidence, 100% owned production coverage, complete steward review rather than sampling, exact-head required workflows and review, and code-current PRD/TRD/ADR/security/threat-model/gap documentation. Descendant evidence never back-proves an unresolved predecessor.
Issue #8 remains open.
Live baseline
http://127.0.0.1:23119/api/remains read-only for the recorded Zotero 9.0.6 / API v3 local campaign; last recorded immutable read-only snapshot is library version12341, 8,326 observed records.Zotero-Server-IDis database-instance continuity/precondition evidence, not cryptographic peer authentication; same-host API-key confidentiality remains a release boundary unless protected transport appears or governance explicitly narrows the supported threat model.Current successor authority — 2026-09-05
The full Draft chain was non-force restacked after the Foundation product/technical gap baseline refresh. Every successor retains its previous semantic head as first parent and adopts the current direct parent as second parent; no force-push/destructive rebase or predecessor-evidence transfer occurred.
#9 256076d -> #10 b821b0f -> #11 cb365fb -> #12 5ce1a18 -> #13 821b04c -> #15 64cb10f -> #16 d02d0f9 -> #17 47e86b5 -> #18 bb8ef8c -> #19 b6c11b2 -> #20 53a91d3 -> #21 d51762d -> #22 2c8ee56 -> #23 17a0407 -> #24 005826d -> #25 8a239ee -> #26 0f5002e -> #27 9d89805 -> #28 2de9254 -> #29 98204ff -> #30 ddd0e4c -> #31 e5a1e52 -> #32 0ac89b6 -> #33 4feb387 -> #34 062a0d9Foundation is #1
b538470c963e6524ddc0c3f652a46a4fc8265150. All Zotero successors remain Draft and require their own unchanged exact-head protected evidence after the restack.Preserved contracts and unresolved release boundary
#15 retains receipt binding to review/authority/server/Zotero-version/library/rule/snapshot coordinates, complete DryRun not-attempted enumeration, and conditional inverse evidence only when server/item identity remains proven. #18 keeps the loopback-HTTP provider threat explicit and does not authorize an enterprise-secure live-write claim. #30's private-input boundary rebuilds metadata/open paths from an authorized canonical parent plus filename and keeps
O_NOFOLLOW, exact0600, single-link and bounded-input checks. #33 provides deterministic non-reserving steward batches. #34 reconstructs and compares the exact human-visible batch context before converting decisions to the atomic patch, and its production output validator rebuilds the output path from the authorized canonical parent plus final filename before create-new writing.These are source contracts, not inherited hosted GREEN. The complete steward-review denominator remains 3,715 proposals; unverified worksheet decisions remain
0/3,715, and externally approved steward labels independently remain0/3,715. No live steward decision, Zotero write/rollback, governed publication or immutable release is claimed.Acceptance boundary
Acceptance still requires one immutable top-level bibliographic snapshot, one proposal per paper, complete item/library/rule/snapshot provenance, reversible duplicate review, default dry-run, Zotero 10+ reviewed-authority/precondition/transport gates, reversible write evidence, 100% owned production coverage, complete steward review rather than sampling, exact-head required workflows and review, and code-current PRD/TRD/ADR/security/threat-model/gap documentation. Descendant evidence never back-proves an unresolved predecessor.
Issue #8 remains open.