fix: regenerate favicon.ico with a transparent ground; tick Pouya's read-through

public/favicon.ico shipped with no transparency: all three frames declared a
32-bit alpha channel and then carried alpha=255 on every one of their 256/1024/
2304 pixels, ground opaque cream rgba(250,247,242,255). Pouya's read-through
finding, confirmed by parsing the ICO container directly.

The render source carries true alpha (2,272,386 transparent px, 20,795 partial),
so this is an export, not a mask derived from the cream ground — R13's harder
branch did not fire and R13 is unchanged on its own terms.

New scripts/icons.mjs + npm run icons re-derives the icon from the committed
master: asserts the source is still the documented crop (R14), verifies a
candidate file and renames on success so a rejected build cannot replace a good
favicon, and runs a boundary-colour halo test. Composition is unchanged —
ink bbox and pixel count identical at all three sizes.

apple-touch-icon.png is byte-identical and stays opaque cream deliberately; the
reason lives in docs/reference/brand-assets.md §The icon set, with the bar and a
pointer in BaseLayout.astro, docs/06 and R13.

docs/06: the read-through is ticked, and the cutover callout drops to ONE
blocker — Q60's waiting period.

Two adversarial review rounds, 15 findings, all resolved, none declined; stopped
at two per D19. claims-auditor correctly deferred to cutover per D20. Gates on
the committed bytes, exit status read: check 0, build 0 (23 pages),
check:claims 0, check:intake 0, og:proof 0, lint 0, lighthouse 0 (worst of 23
99/100/100/100). Nothing deployed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Md3GndFqWPzK78xAoebsg5
This commit is contained in:
Pouya Lajevardi
2026-09-02 16:14:35 -04:00
co-authored by Claude Opus 5
parent 4735989f0b
commit 67847d94fa
8 changed files with 891 additions and 22 deletions
+60 -15
View File
@@ -395,8 +395,22 @@ Then invalidate `/*`.
> reversing them puts 22 of 23 pages behind a 403 for as long as a CloudFront
> deployment takes.
> 🛑 **TWO THINGS BLOCK THIS ENTIRE LIST AS AT 2026-09-02: ONE WAITING PERIOD
> AND ONE READ-THROUGH.**
> 🛑 **ONE THING BLOCKS THIS ENTIRE LIST AS AT 2026-09-02, AND IT IS A WAITING
> PERIOD RATHER THAN A TASK: Q60.**
>
> ✅ **THE READ-THROUGH IS COMPLETE — Pouya, 2026-09-02, and it returned ONE
> FINDING WHICH WAS NOT COPY.** `public/favicon.ico` shipped with no
> transparency; fixed and verified the same day (see **Favicon set complete**
> below). His read carried the approvals with it, in terms: the
> `/legal/privacy/` §Who can see it wording, the **SML Company Ltd** consent
> line, and `/med-arb/` **as shipped**. That discharges blocker 2 and every
> wording sign-off that had been routed into it.
>
> ⚠️ **THE COUNT NOW READS ONE AGAIN, AND THE EARLIER ONE WAS A DEFECT — READ
> THE REASON, NOT THE NUMBER.** It said ONE earlier on 2026-09-02 because an
> approval had gone **missing** from the list; it says ONE now because the pass
> that approval was routed into has been **done**. A tally cannot tell those
> apart, which is the point the note below has been making all day.
>
> ⚠️ *(The count has moved repeatedly in one day and the DIRECTION is the only
> part worth reading — the number of moves is deliberately not stated, because a
@@ -421,12 +435,12 @@ Then invalidate `/*`.
> record is written and it does not call failure before **7 days**, so
> **start it before anything else on this page.** It is the one blocker
> that is a waiting period rather than a task.
> 2. **Pouya has not yet read every page against `AGENTS.md` §4.** The human
> pass the other half of D20, and not delegable. **It is also where the
> §Who can see it approval now lands:** Pouya ruled on 2026-09-02 that the
> read-through *is* the approval and that nothing is to be held open waiting
> on a separate wording sign-off. The item under **Copy and claims** below
> carries what to read first and why.
> 2. ✅ **DONE 2026-09-02 — Pouya read every page against `AGENTS.md` §4.** The
> human pass, the other half of D20 and not delegable. It was also where the
> §Who can see it approval was routed, and his ruling that the read-through
> *is* the approval means that sign-off is now discharged rather than
> pending. **Sole finding: the favicon's opaque ground.** No copy finding on
> any of the 23 pages.
>
> ✅ **CLOSED 2026-09-02 — Q64, MOOT.** It asked whether anyone else holds the
> AWS root password or its MFA device, because the page published *"has no
@@ -650,12 +664,25 @@ the decision is re-readable rather than re-litigated.
count has been wrong twice, and this line carried "eight" for a round after
the comment itself had been corrected to nine (`adversarial-reviewer`,
round 2). Read the list, not a number
- [ ] **Pouya has read every page against `AGENTS.md` §4.** The human pass. It is
the other half of D20 and it is not delegable — his reading is what the
per-step audit was traded for.
⚠️ **START WITH `/legal/privacy/` §Who can see it. IT IS BLOCKER 2 IN THE
CALLOUT ABOVE, AND THIS READ *IS* THE APPROVAL** — Pouya ruled on
2026-09-02 that nothing waits on a separate wording sign-off. Every
- [x] **DONE 2026-09-02 — Pouya has read every page against `AGENTS.md` §4.**
The human pass, the other half of D20 and not delegable — his reading is
what the per-step audit was traded for. **It returned one finding across 23
pages and that finding was not copy:** the favicon shipped with an opaque
cream ground. **The `/legal/privacy/` §Who can see it wording, the
SML Company Ltd consent line and `/med-arb/` as shipped are approved by
this read**, per his ruling that the read-through *is* the approval.
⚠️ **This does NOT discharge `claims-auditor`'s cutover pass**, which is a
separate item on this list: D20 traded the per-step machine audit for the
human pass **plus** one machine pass over the finished site, and one of
those two has now happened.
~~⚠️ **START WITH `/legal/privacy/` §Who can see it. IT IS BLOCKER 2 IN THE
CALLOUT ABOVE, AND THIS READ *IS* THE APPROVAL**~~ — **struck 2026-09-02:
the pass is DONE, and an unstruck imperative on a ticked item told an
operator to begin a read this page also records as finished, pointing at a
blocker that no longer exists** (`adversarial-reviewer`, round 2). What it
said remains true of what happened: Pouya ruled on
2026-09-02 that nothing waits on a separate wording sign-off, and he read
§Who can see it first. Every
sentence in it changed three times that day — Q62's ruling, Q63's, then the
ruling that cut it to **four plain statements** — and it is the only
section on the site whose subject lives entirely outside this repository.
@@ -972,7 +999,25 @@ the decision is re-readable rather than re-litigated.
instead. A `Disallow` will not do it: a blocked URL can still be listed.
Found by `adversarial-reviewer`, 2026-08-31
- [ ] Booking link works, including the no-JavaScript fallback — **conditional on R6**; booking is parked and `CONTACT.bookingUrl` is `null`, so nothing renders and this passes vacuously until a tool is chosen. **Nothing on `/contact/` mentions booking**, deliberately
- [ ] Favicon set complete
- [x] ✅ **Favicon set complete, and REGENERATED 2026-09-02 — it had shipped with
no transparency at all.** Pouya's read-through finding. All three frames
(16/32/48) declared a 32-bit alpha channel and then carried `alpha = 255`
on every pixel, the ground opaque cream — so the tab icon showed as a cream
rectangle on any dark tab strip. `public/favicon.ico` is now transparent,
regenerated by `npm run icons` from the committed master and verified
programmatically and by eye, on dark grounds and light.
⚠️ **`public/apple-touch-icon.png` STAYS OPAQUE CREAM AND MUST NOT BE
"FIXED" TO MATCH.** The reason is a platform behaviour — iOS composites a
transparent touch icon onto black — **stated by Pouya on 2026-09-02 and not
re-tested on a handset**; the item directly below is where it would be. The
touch icon is byte-identical across this change.
⚠️ **AND THE CHANGE IS NOT FREE ON DARK.** The maroon half of the ribbon
effectively drops out against a dark tab strip; the champagne half carries
the mark. **The figures are deliberately NOT repeated here** — they live in
`docs/reference/brand-assets.md` §The icon set, with the method, and a copy
on this page had already gone stale within a day by quoting the 32 px row
as if it were the general case (`adversarial-reviewer`, round 2). Read them
there.
- [ ] Tested on iOS Safari, Android Chrome, desktop Safari/Chrome/Firefox
- [ ] Tested at 320 px and at 200% zoom
- [x] ✅ **THE 200%-TEXT NAV OVERFLOW IS FIXED, 2026-09-01 — THIS ITEM IS