Canonical-Port Evidence Packet
Superseded — 2026-07-30
The later source and infrastructure deltas, drift gates, runtime migration, and public configuration evidence are superseded by the 2026-08-02 F-program packet. Preserved as observed for the 2026-07-30 completion pass.
Release boundary:
releaseEligible: false. This is a bench-local evidence handoff for a canonical owner; it is not a release artifact, merge-ready patch, package, signed output, or authorization to ship.
Purpose and strict non-goals
Purpose. Give the canonical release owner a bounded inventory of the 2026-07-30 bench completion pass, the decisions that must survive a port, and the evidence needed to repeat release-owned work in the canonical repository.
Strict non-goals. This packet does not port code, edit compiled build/ output or vendor/provenance material, regenerate a canonical release, run a locked build, claim compatibility, sign, package, publish, modify WordPress data, or authorize any release. It does not supply a canonical repository URL, immutable commit, canonical manifest hashes, or signatures. The attached bench-only catalog checksum manifest is evidence of its observed file set, not a canonical release manifest.
Release NO-GO: missing canonical inputs
Release is blocked, not merely deferred.
| Required gate/input | Why this bench cannot satisfy it |
|---|---|
| Canonical public maintained repository URL and immutable full commit SHA | The supplied archive did not contain them and wp/wp-content/plugins/quizwizz/SOURCE-PROVENANCE.md says they must not be inferred from a ZIP name or workspace path. |
| Protected CI workflow/run and locked deterministic toolchain | wp/wp-content/plugins/quizwizz/BUILDING.md requires the exact pinned tool versions/digests, protected job, clean immutable source commit, offline fixed graph, and empty release-output directory. |
| Canonical provenance and SBOM | The deterministic builder emits detached manifest, CycloneDX SBOM, SLSA-style provenance, dependency-scope, and coexistence evidence; provenance also requires the recorded source/tool/container/dependency inputs described in wp/wp-content/plugins/quizwizz/SOURCE-PROVENANCE.md. |
| Compatibility gates | PHP 8.3 and 8.4 are protected compatibility-matrix gates; release metadata/support claims require canonical CI evidence. |
| Protected signing context | Signing is separate from build and requires the protected release-environment key path; no key material belongs in this bench or source tree. |
| Compiled block source/toolchain | Bench policy leaves compiled build/ findings for the canonical owner; do not hand-edit compiled output. |
| Review and regeneration of bench-local 2026-07-30 sources/catalogs | Every source/catalog change from this pass needs release-owner review and canonical locked-pipeline regeneration before it can ship. |
Evidence: wp/wp-content/plugins/quizwizz/BUILDING.md:7-12,39-57,64-91,114-117; wp/wp-content/plugins/quizwizz/SOURCE-PROVENANCE.md:3-27; 2026-08-19-masterplan-narrative > release-inputs-absent-from-this-ssot-archive.
Observed source inventory for canonical review
This is a subsystem-organized review inventory of observed, present bench paths cited by the completion record—not a patch or an assertion that the files are canonical.
| Subsystem | Observed paths to review |
|---|---|
| Settings, presentation, player | wp/wp-content/plugins/quizwizz/includes/ExposureSettings.php; wp/wp-content/plugins/quizwizz/includes/PresentationDocument.php; wp/wp-content/plugins/quizwizz/includes/Admin/SettingsPage.php; wp/wp-content/plugins/quizwizz/includes/Admin/views/settings-page.php; wp/wp-content/plugins/quizwizz/assets/js/qwizz-admin-settings.js; wp/wp-content/plugins/quizwizz/assets/js/qwizz-player.js; wp/wp-content/plugins/quizwizz/assets/js/qwizz-player-renderer.js; wp/wp-content/plugins/quizwizz/assets/css/qwizz-admin-settings.css; wp/wp-content/plugins/quizwizz/assets/css/qwizz-player.css |
| Attempt, events, privacy | wp/wp-content/plugins/quizwizz/includes/Installer.php; wp/wp-content/plugins/quizwizz/includes/AttemptService.php; wp/wp-content/plugins/quizwizz/includes/PlayEvents.php; wp/wp-content/plugins/quizwizz/includes/Pdf/PdfArtifact.php; wp/wp-content/plugins/quizwizz/includes/Frontend/UserSurfaces.php; wp/wp-content/plugins/quizwizz/includes/Admin/Privacy.php |
| User surfaces, patterns, branding | wp/wp-content/plugins/quizwizz/includes/Frontend/UserSurfaces.php; wp/wp-content/plugins/quizwizz/assets/js/qwizz-user.js; wp/wp-content/plugins/quizwizz/assets/css/qwizz-user.css; wp/wp-content/plugins/quizwizz/includes/Admin/Patterns.php; wp/wp-content/plugins/quizwizz/includes/LogoSource.php; wp/wp-content/plugins/quizwizz/includes/IconPaths.php; wp/wp-content/plugins/quizwizz/includes/Icons.php; wp/wp-content/plugins/quizwizz/assets/js/qwizz-builder.js; wp/wp-content/plugins/quizwizz/assets/css/qwizz-builder.css |
| Assets, localization, cache | wp/wp-content/plugins/quizwizz/includes/Plugin.php; wp/wp-content/plugins/quizwizz/includes/UiLanguage.php; wp/wp-content/plugins/quizwizz/assets/css/qwizz-admin-responsive.css; wp/wp-content/plugins/quizwizz/assets/css/qwizz-responsive.css; wp/wp-content/plugins/quizwizz/languages/quizwizz.pot; wp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE.po; wp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE.mo; the JSON inventory below |
Completion-record evidence: 2026-07-30 feature-completion pass; direct source evidence for the event, localization, and asset boundaries: wp/wp-content/plugins/quizwizz/includes/Pdf/PdfArtifact.php:89-156, wp/wp-content/plugins/quizwizz/includes/Frontend/UserSurfaces.php:148-163, wp/wp-content/plugins/quizwizz/includes/ExposureSettings.php:24-31, wp/wp-content/plugins/quizwizz/includes/UiLanguage.php:32-38,99-117, wp/wp-content/plugins/quizwizz/includes/Plugin.php:243-267.
Preserved decision record
- Printable sheets: count every successful non-inline attachment download.
PdfArtifact::stream()callsPlayEvents::increment()after a successful non-inline stream; repeated GETs to a still-valid artifact URL therefore each count. - Share only: remains idempotent through
PlayEvents::increment_once()and its seven-day event guard. - Decision authority: the bench owner chose this behavior after BBQ evidence; it is not an inferred metric change. See 2026-07-30-release-readiness > decisions.
German catalog inventory and reproducibility boundary
Observed inventory:
- POT:
wp/wp-content/plugins/quizwizz/languages/quizwizz.pot - German PHP catalogs:
wp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE.po,wp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE.mo - Nine required named handle JSON catalogs:
wp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE-qwizz-player.json,wp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE-qwizz-builder.json,wp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE-qwizz-finetune.json,wp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE-qwizz-admin-settings.json,wp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE-quizwizz-admin-import.json,wp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE-qwizz-admin-subjects.json,wp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE-qwizz-admin-shortcode-copy.json,wp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE-quizwizz-admin-editor.json, andwp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE-qwizz-user.json. - Two additional hashed artifacts:
wp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE-520b882d5a62045c160d0dc56eabc58c.jsonandwp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE-949f8136c01f699e9f8fbc8c66d5f965.json.
The observed bench catalog bytes are recorded in q5vault/audits/qwizz/2026-07-30-catalog-manifest.sha256 (POT, PO, MO, nine named handle catalogs, and two hashed catalogs). Run sha256sum --check q5vault/audits/qwizz/2026-07-30-catalog-manifest.sha256 from /home/loca/dev/wrdp to check that finite inventory. It is an evidence snapshot, not a canonical manifest or signing input.
Reproducibility recipe (review aid, not release authorization): in a disposable writable directory, copy the shipped quizwizz-de_DE.po; use the bench’s containerized WP-CLI i18n make-mo command to compile it into that directory; compare the generated .mo with wp/wp-content/plugins/quizwizz/languages/quizwizz-de_DE.mo. Then, in the canonical repository, regenerate POT/PO/MO/JSON using the locked pipeline and review the resulting canonical diff. Do not treat a local comparison as canonical provenance, a release build, or permission to ship.
The runtime gate has the German .mo plus the nine required named handle catalogs. fr and es remain dormant. This proves file-set gating, not exhaustive forced-German rendering or release authorization. Current PO evidence includes the interface/category strings previously described as uncataloged; this packet makes no contrary claim.
Verification evidence and limits
| Item | Observed evidence | Limit |
|---|---|---|
| Schema marker | The stored marker read is 1.6.5, matching Installer::SCHEMA_VERSION. | BBQ did not re-inspect the physical user_id column or index. |
| Historical probe run | The completion record reports assertions=30 failures=0 after ./scripts/quizwizz-probe.sh --wave all. | The harness is mutating and does not cover the new localization, event, pattern, or cache surfaces. It is historical evidence, not a release gate. |
| Event semantics | Direct source trace: non-inline PDF attachment path increments print; share route uses increment_once(). | No claim is made about a release build or external analytics semantics. |
| Asset versioning | Source scope is 24 enqueue calls using asset_version(), six current Dashboard/MetaBoxes calls using QUIZWIZZ_VERSION directly, and one player enqueue inheriting a registered version. A fresh public response at https://wrdp.loca.zone/?page_id=57 emitted mtime-derived ?ver= URLs for observed asset-versioned CSS/JS. | No universal coverage, response-cache headers, warm browser transition, effective cache invalidation, or direct/inherited-path claim is made. |
| Quartz | /home/loca/dev/wikis/build.sh wrdp --check-only completed successfully after parsing 32 Markdown inputs and emitting 284 files. | It was validation only; no publication occurred. |
Evidence: 2026-07-30-release-readiness > confirmed-truth; probes > current-bench-result; wp/wp-content/plugins/quizwizz/includes/Installer.php:15,53-55; wp/wp-content/plugins/quizwizz/includes/Plugin.php:243-255; wp/wp-content/plugins/quizwizz/includes/Admin/DashboardPage.php:38-40; wp/wp-content/plugins/quizwizz/includes/Admin/MetaBoxes.php:105-123.
Canonical-owner checklist (future external actions)
After obtaining the canonical repository and immutable commit, the canonical owner can:
- Review this evidence against canonical source and port the approved source changes; review every bench-local 2026-07-30 catalog/source change.
- Regenerate POT, PO, MO, and all script JSON catalogs in the locked canonical pipeline; generate a manifest only from the final verified file set.
- Run the locked deterministic build and protected CI compatibility gates.
- Produce and review the required manifest, SBOM, provenance, dependency-scope/coexistence evidence, and source/tool approvals.
- Execute protected signing in its authorized release context and perform release-owner review of the resulting outputs.
These are external future actions. None is completed or authorized by this packet.
Narrow rollback
Rollback for this handoff phase is limited to reverting bench documentation and this packet. No runtime change occurs in this handoff phase.