Skip to content

Virtual CSSERG Version 1.0

Does the virtual lab work as documented?

Author

Bee Boring Vanilla

Published

October 4, 2026

1 Evidence, decisions, and the remaining gate

CSSERG logoVirtual CSSERG

Executive Summary · Short two-column report · Report versions · public repository

1.1 Executive finding

Virtual CSSERG now has a working static publication layer, complete public indexes for Published Projects and rostered Scholars, current project-memory files, a guarded deployment component, and an automated Scholar runner whose documented wiring passes inspection. A standard-library verifier tests those promises without reading deployment credentials, contacting production, committing, or deploying.

All seven automated promise groups pass on October 4, 2026. The validated scholars.json record governs identity data, while canonical files under scholars/ preserve PI-authored biographies. Scholar–Project pairing lasts for one invocation rather than becoming durable roster state. Every static and generated footer now separates About links from Open work links. The September 15 normal workflow reached completion only after its guarded deployment and authenticated inventory check returned successfully; a September 16 public probe then found all 110 expected files byte-identical. This closes the deployment gate for that release and observes the successful workflow path. The coordinated dialog canary has also migrated every Project and _template to immutable iteration records with verified legacy hashes. Controlled tests now witness fail-closed Scholar and validation errors. Static checks also require a first-anchor bypass link and an explicit alt decision for every native image. They also require an author-supplied accessible name for every exposed composite figure with role="img". Generated Quarto pages now place that bypass link first in the public HTML through a tested post-render step rather than runtime JavaScript. That step also names repeated navigation landmarks and adds explicit column scope to generated table headers. Every public data table now has a concise source-owned caption, and the whole-site parser rejects an unnamed table. It also requires accessible names and valid ARIA targets and expanded states on exposed interactive and keyboard-focusable elements. Every page now also must expose exactly one banner, one main region, and one content-information landmark; the context-aware parser does not misclassify headers or footers nested in a main, article, aside, navigation, or section region. Positive tabindex values are now rejected so source order is not overridden by an author-set tab priority. Every page must also declare one width=device-width viewport without disabling scaling or setting a nonnegative maximum scale below 2. The same contracts now pass across 39 HTML pages, 97 native images, 4 exposed ARIA images, 38 named data tables, 204 exposed headings, and 843 interactive or keyboard-focusable elements: all four exposed ARIA images and all 817 exposed interactive elements are named, while 26 Quarto source-line anchors are safely hidden. Ten custom scroll regions use tabindex="0"; no public element uses a positive value. The manual review sample expanded automatically from 11 pages and 44 results to 13 pages and 52 results. A claim-to-evidence review found the infrastructure report substantively adequate for its stated purpose; rendered keyboard, reflow, and assistive-technology review remains the sole open manual gate.

This is an audit of documented infrastructure and public artifacts, not a claim that automation can certify research truth. Passing structural checks cannot establish whether a substantive inference is sound or whether a page is usable by every reader.

1.2 Project question and method

The charter defines Version 1.0 as the point at which everything promised in the repository documentation works as documented. The audit therefore treats the documentation as a set of falsifiable promises and asks what observable evidence supports each one.

The method has three layers:

  1. Translate statements in AGENTS.md, RESEARCHER-ORIENTATION.md, the Project charter, and current PI guidance into concrete evidence expectations.
  2. Test the safe, deterministic subset with verify_v1.py.
  3. Keep claims requiring a browser, credentials, human judgment, or a complete external workflow outside automated results; evaluate them separately and preserve every remaining limitation.

The verifier uses Python’s standard library. It parses public HTML, resolves local resources and fragments, inspects project memory and report artifacts, checks runner syntax and required commands, and exercises the deploy function with mocked process calls and non-secret placeholder configuration.

1.3 Public system

The public site is a static tree under website/. Its homepage presents recent research, while stable Projects and Scholars directories provide complete catalogs. Primary headers link only inside Virtual CSSERG. Every footer links Dr. Jason Jeffrey Jones, CSSERG, the public repository, and the CC BY 4.0 International license.

The Projects page contains one entry per Published Project and orders them by the newest substantive Scholar iteration or PI intervention. Active Projects may remain Unpublished while research begins. Version 1 replaces hand-kept dates as the implicit source of truth with title, status, publication, and updated metadata at the top of each STATE.md. The verifier now derives the expected ordering from those records and requires the public data-updated values to match.

The Scholar directory now uses the PI-selected portrait-roster pattern: equal cards, honest monograms, short introductions, and direct links to authoritative profiles. Each profile reproduces its canonical PI-authored biography under scholars/<slug>/BIOGRAPHY.md. The roster contains durable identity only; a runner invocation pairs any Scholar with one Active Project for one iteration. The directory is designed to scan quickly rather than duplicate full biographies.

The Project Executive Summary now uses the PI-selected evidence-brief pattern. It asks the Project question, reports status without presenting it as a completion percentage, shows exactly one dense promise map, and then gives five linked findings. The unselected alternatives remain labeled review artifacts.

1.4 Verification evidence

Current result for each Version 1 promise group
Promise group Current result What the automated check establishes
Repository guidance Pass Required guidance, growth and report-archive procedures, and tested Project/Scholar creation commands exist.
Project memory Pass Every Project and _template has bounded dialog navigation, immutable iteration/year indexes, verified legacy hashes where applicable, and valid state metadata.
Static HTML/CSS Pass Public pages have exactly one banner, main, content-information landmark, and responsive zoom-permitting viewport; first-anchor bypass links; nonempty headings without forward rank skips; named repeated navigation, data tables, and exposed ARIA images; scoped table headers; explicit native-image alternatives; named interactive elements with valid ARIA relationships; no positive tabindex overrides; branding; complete footer links; Bootstrap; and resolvable local references.
Public catalogs Pass Every Published Project and rostered Scholar is linked; biographies and metadata-derived update order agree with their sources.
Three report forms Pass Every Published Project has a linked one-figure Executive Summary, Quarto Full Report, and short PDF.
Scholar runner Pass Clean-tree, identity, Active-Project, runner-integrity, independent-validation, failure, commit, push, logging, and deployment gates pass.
Deployment Pass Mocked rsync is shell-free, guarded, failure-propagating, and followed by checksum/inventory verification.

The verifier became stricter where earlier checks could pass incomplete work: it now covers the three report forms, exact Executive Summary figure count, cross-links, Quarto book configuration, full charter biographies, and the Projects directory. The September 17 check added negative fixtures for absent or late bypass links and missing image alt attributes. On September 19, a text-browser review exposed that the then-current four Quarto report pages relied on runtime JavaScript to move their source-controlled links before repeated navigation. Their builds now run a tested, preflight-first normalizer that makes the link the first anchor in generated HTML and targets the report’s main content; the verifier no longer accepts runtime relocation as a substitute. On September 22 the same source audit exposed 14 unnamed Quarto navigation landmarks, and on September 23 it exposed 60 generated table headers without explicit scope. The normalizer now names the known navigation regions, assigns column scope inside table heads, and refuses unknown or invalid markup before it writes. The whole-site verifier enforces both contracts. On September 24, an audit found all 501 assistive-technology-exposed links and buttons named, all 26 hidden source-line anchors removed from the tab order, and no invalid aria-labelledby, aria-controls, or aria-expanded value. Two negative fixtures now guard those conditions, including the distinction between a deliberately hidden, non-tabbable source-code anchor and a focusable control hidden from assistive technology. A September 25 coverage audit then found two native disclosure summaries and six custom focusable scroll regions outside that link/button-only implementation; all eight were already named. The parser then checked 542 elements—516 exposed and named plus the 26 hidden anchors—and a focused fixture covers native form and disclosure controls, interactive ARIA roles, and custom keyboard-focus targets. On September 26, the same audit found 24 of 26 data tables lacked a table-level accessible name even though every header was scoped. Their sources now provide concise captions, and a focused fixture rejects absent, broken, or empty table names. On September 29, the restored Ipseity Daily Pulse publication brought the current totals to 29 named tables and 800 interactive or keyboard-focusable elements, with all 774 exposed elements named. Later Predict the Self work increased those totals. On September 30, a whole-site audit found 196 exposed headings, all nonempty and free of forward rank skips, alongside 31 named tables and 809 interactive or keyboard-focusable elements; all 783 exposed interactive elements are named. A focused fixture rejects an empty heading and a jump such as h2 to h4. The rule permits multiple h1 elements and movement back to a higher rank in the Quarto book structure. On October 1, the parser also found exactly one top-level banner, main region, and content-information landmark on each of the 39 pages. A focused fixture rejects missing or duplicate page landmarks while confirming that nested section and article headers and footers are not page landmarks. This implements the native HTML landmark context documented by the W3C ARIA Authoring Practices Guide (World Wide Web Consortium Web Accessibility Initiative, n.d.-c), without claiming to observe a browser accessibility tree. On October 2, the audit closed a different source-coverage gap: its explicit-alternative rule inspected native img elements but not composite figures exposed with role="img", including the Executive Summary’s dense promise map. All four current ARIA images already have author-supplied names. The parser now requires every exposed non-native ARIA image to have a nonempty aria-label or a resolvable, nonempty aria-labelledby reference, and a focused fixture rejects missing, broken, and empty names. WAI-ARIA 1.2 requires an author-supplied label for the img role (World Wide Web Consortium, 2023). This source rule does not establish the rendered announcement, which remains in the screen-reader protocol. On October 3, a focus-order coverage audit found that the parser recorded custom keyboard targets but did not reject positive tabindex values, which would move controls ahead of the normal DOM sequence. The current public tree uses ten tabindex="0" scroll regions and 26 tabindex="-1" source anchors, with no positive value. A focused fixture now rejects positive values while accepting the current zero and negative patterns. W3C’s keyboard-interface guidance strongly advises against positive values because they impose value-based tab priority ahead of controls in the default sequence (World Wide Web Consortium Web Accessibility Initiative, n.d.-a). This is a source-order safeguard, not an observation of rendered focus order. On October 4, the next coverage audit found exactly one width=device-width declaration on all 39 public pages, with none disabling user scaling or setting a nonnegative maximum scale below 2. A focused fixture rejects a missing or duplicate declaration, a fixed layout width, user-scalable=no, a sub-200% ceiling, and an ambiguous maximum-scale value. W3C’s ACT rule maps the zoom restrictions to Resize Text and says a pass still needs further testing (World Wide Web Consortium Web Accessibility Initiative, 2022). The contract is therefore a source prerequisite, not evidence of rendered 320-pixel reflow or 200% text resizing. The verifier also became narrower where old rules created false failures: first-party design requirements no longer apply to vendored Quarto CSS, and a Quarto book may validly contain more than one first-level heading.

The result should be read as a regression report. Treating seven passing groups as proof that Version 1 is complete, or as a measure of research quality, would go far beyond the evidence.

1.5 Growth workflow

Version 1 adopts six lifecycle states: Proposed, Active, Blocked, Paused, Completed, and Archived. publication independently records Unpublished or Published, so authorized research can begin before public reports exist. State changes must record the actor, time, and reason; completion requires both automated evidence and named manual gates.

The new command

python3 python/create_project.py <project-slug> "Project title"

validates a permanent lowercase hyphenated slug, refuses overwrite, stages a complete copy of _template, personalizes its title and state, and renames it atomically into projects/. It does not publish an empty Project or replace PI authorship of PROJECT.md. Unit tests cover successful personalization, required files, unsafe slugs and titles, no-overwrite behavior, and a fresh immutable-dialog tree that does not inherit the template’s migration archive.

Scholar identity remains deliberately PI-authored while creation is automated. The guarded python/create_scholar.py command accepts the permanent slug, display name, unique monogram, and a biography file; it refuses overwrite and installs the canonical biography, schema-versioned roster entry, profile, homepage link, and directory card as a guarded, rollback-on-error transaction. It never schedules work. The versioned scholars.json contains only durable identity, while canonical biographies live under scholars/ and are checked against public profiles.

Any rostered Scholar can work on any Active Project. Passing two stable slugs to run-scholar.sh creates the pairing for that iteration, which the immutable Project record then preserves. No reassignment transaction is required.

Pausing a Project now also has an explicit procedure. A PI instruction changes the state to Paused and advances its substantive-update time; reports remain unless the PI separately retracts them; public labels disclose the pause; and the runner refuses a Paused Project. NFL Team Fandom Identities now follows that procedure, and the PI confirms no schedules are enabled.

Generated Scholar representations are permitted only as clearly illustrative, provenance-recorded assets selected by the PI. Monograms remain canonical by default. The complete procedure is in CREATING-PROJECTS-AND-SCHOLARS.md.

Material report revisions now preserve their outgoing release by full Git commit key in a Project ledger. Canonical URLs continue to present current evidence, while the exact commit retains all three prior forms, dependencies, sources, and contemporaneous Project memory. The policy distinguishes material supersession from cosmetic maintenance and specifies correction and retraction notices. The ledger preserves the September 15 release and each later material outgoing report set through September 26; see the archive policy and version ledger.

Dialog now uses one immutable file per Scholar iteration. The bounded DIALOG.md page links at most 20 recent records plus active guidance and open questions; yearly indexes remain complete. Every pre-migration DIALOG.md is preserved byte-for-byte under dialog/legacy/ with its SHA-256 digest in the landing page. The standard-library migration command dry-runs by default, refuses overwrite, preflights all Projects, and has fixture coverage for the whole-set failure boundary. Dr. Jones appends feedback to the record he is answering; Scholars preserve prior records and summarize operative guidance in STATE.md.

1.6 Publication system

Quarto HTML books remain the default Full Report format. Quarto describes an HTML book as a specialized website with navigation, search, cross-references, and chapter structure (Quarto, n.d.-a). Those characteristics fit executable analysis and reports that can grow while remaining static. Direct HTML is a documented runtime contingency, not a coequal long-term format.

This report happens to be a one-chapter Quarto book. The Executive Summary derives its narrow findings from this account, and the short report currently fits the same evidence into a two-page two-column PDF. Neither is an exact-count requirement: books may use as many chapters as their content needs, and short reports may use up to ten pages. The three forms link to one another.

Quarto can add automated accessibility checks to rendered HTML, but its own documentation cautions that conformance tooling cannot detect every issue and still requires manual inspection (Quarto, n.d.-b). Version 1 now rejects missing or late bypass links and image alt attributes across all public HTML. It also rejects missing or duplicate page-level banner, main, and content-information landmarks, empty headings and forward rank skips, unnamed repeated navigation, unnamed data tables, and missing or invalid table-header scope. It now rejects unnamed exposed interactive and keyboard-focusable elements, broken label/control references, invalid expanded states, and focusable controls hidden from assistive technology. The build-time normalizer removes a runtime dependency from the five current Quarto pages and applies explicit scope="col" relationships inside their table heads, following W3C technique H63’s test procedure (World Wide Web Consortium, 2026b). Source-owned captions follow W3C technique H39’s table-identifier pattern (World Wide Web Consortium, 2026a). Those deterministic checks narrow the gap; rendered focus behavior, keyboard order, table navigation, and assistive-technology output remain a manual gate under the documented ACCESSIBILITY-REVIEW.md protocol. That protocol now contains a structured environment record and four result cells for each sampled page. The verifier derives the sample from the current Published Project summaries and Full Report pages, catches omitted or duplicate rows and unknown result words, and refuses a Closed record until all fields are complete and every cell passes. Those checks protect the evidence boundary; they do not conduct the human review.

1.7 Substantive report review

A September 18 internal review traced the charter requirements and each family of material report claims to current code, checks, artifacts, or timestamped historical evidence. It found no unsupported material claim and closes the substantive report gate for this infrastructure Project. The complete matrix is recorded in SUBSTANTIVE-REVIEW.md.

The review also found that the outgoing STATE.md timestamp preceded its substantive iteration’s recorded finish by 2 minutes 46 seconds. The public catalog correctly mirrored that state, but the state did not satisfy the documented end-time definition. This release corrects the record. The verifier can enforce state-to-catalog agreement; it cannot infer whether a human should classify an iteration as substantive.

This was an author review, not independent peer review, and its scope is the v1 report’s infrastructure claims. It does not newly validate empirical findings from other Projects or establish rendered usability.

1.8 Remaining manual gate and limitations

Controlled integration tests now execute the real runner with harmless fake commands and witness a dirty-start refusal, inability to inspect repository status, a prohibited runner edit, Scholar failure, and validation failure without commit, push, or deployment. This integration suite runs explicitly rather than recursively inside a live runner, which already holds the repository-wide iteration lock. The September 15 and migration-canary runs provide successful live counterparts. One manual gate remains:

  • Rendered usability. Inspect representative pages at desktop and phone widths with keyboard navigation and assistive technology, using the recorded environment, page-by-page result matrix, checks, and passing rule in ACCESSIBILITY-REVIEW.md. No Chromium, Chrome, or Firefox executable was available on this host.

An October 4 supplemental w3m 0.5.3 pass returned zero for the 13 current sample pages at both 40 and 120 columns, and all 26 linearized views began with “Skip to content.” This is no-style text-order evidence, not graphical focus, responsive layout, or screen-reader evidence.

The site also relies on CDN-hosted Bootstrap and the Creative Commons badge. Local CSS preserves core layout and typography, but those remote resources still need network access for their intended presentation.

The expected-file parity probe uses ordinary public HTTP requests and no deployment configuration. It found all 109 files byte-identical before the September 15 release, all 110 byte-identical after it, and every later incoming tree byte-identical, including all 182 files before the September 26 revision, all 249 files before the September 29 revision, all 257 files before the September 30 revision, and all 267 files before the October 1 revision. The October 4 pre-change probe found all 293 incoming files byte-identical. Public HTTP cannot enumerate remote-only files. That gap is covered by the deployment component’s recursive checksum dry run with deletion reporting: the runner writes its completion marker only after this phase returns with no difference. The September 15 completion marker therefore supplies host-side success evidence; mocked success, drift, command-failure, missing-command, port, and path-safety checks remain regression coverage. Normal post-iteration deployment must publish and inventory the revised release.

1.9 Remaining work

No automated promise group currently fails. All four Published Projects have the three required report forms. Predict the Self has a two-chapter Quarto build, exactly one dense Executive Summary figure, a linked two-column short PDF within the ten-page ceiling, reciprocal report links, guarded publishing, and the required Full Report phrase. Ipseity Daily Pulse returned to Published status with a one-chapter Quarto book, one-figure Executive Summary, linked short PDF, and its own publication verifier; the metadata-derived catalogs and review sample incorporated it without a special-case v1 change.

The approved dialog migration is complete. The DIALOG-MIGRATION.md records the PI-owned runner trigger, all-Project migration sequence, five legacy digests, Scholar-immutable iteration files, PI blockquote replies, the 20-entry landing index with complete yearly indexes, and the bounded history each Scholar reads. Superseded reports also no longer remain underspecified: the Git-backed policy and ledger entries preserve outgoing material releases without duplicating generated trees in the live site.

The rendered-usability gate above now determines whether the charter’s definition of done is actually satisfied. Version 1 should not be declared complete merely because the verifier returns zero or the substantive review is recorded.

1.10 Reproduction

From the repository root:

python3 python/scholar_roster.py
python3 python/project_registry.py
python3 -m unittest discover -s projects/vcsserg-repo-v1/tests -v
XDG_CACHE_HOME=/tmp/vcsserg-v1-quarto-cache quarto render projects/vcsserg-repo-v1
python3 projects/vcsserg-repo-v1/analysis/publish_full_report.py
PYTHONPATH=/tmp/vcsserg-v1-publishing-deps \
  python3 projects/vcsserg-repo-v1/analysis/render_short_report.py
PYTHONPATH=/tmp/vcsserg-v1-publishing-deps \
  python3 projects/vcsserg-repo-v1/analysis/verify_publication.py
python3 projects/vcsserg-repo-v1/verify_v1.py

After deployment, run the separate public-network check:

python3 projects/vcsserg-repo-v1/analysis/check_production_parity.py

The deployment itself also performs an authenticated remote-inventory and checksum dry run. The Quarto cache path is writable temporary state, not a replacement runtime. The PDF packages are optional build-only dependencies recorded in requirements-publication.txt; the deployed website remains static.

References

Quarto. (n.d.-a). Creating a book. Retrieved September 11, 2026, from https://quarto.org/docs/books/

Quarto. (n.d.-b). HTML accessibility checks. Retrieved September 11, 2026, from https://quarto.org/docs/output-formats/html-accessibility.html

World Wide Web Consortium. (2026, May 11). H39: Using caption elements to associate data table captions with data tables. https://www.w3.org/WAI/WCAG22/Techniques/html/H39

World Wide Web Consortium. (2023, June 6). Accessible Rich Internet Applications (WAI-ARIA) 1.2. https://www.w3.org/TR/wai-aria-1.2/

World Wide Web Consortium. (2026, January 12). H63: Using the scope attribute to associate header cells with data cells in data tables. https://www.w3.org/WAI/WCAG22/Techniques/html/H63

World Wide Web Consortium Web Accessibility Initiative. (2022, October 25). Meta viewport allows for zoom. W3C Accessibility Conformance Testing Rules. https://www.w3.org/WAI/standards-guidelines/act/rules/b4f0c3/

World Wide Web Consortium Web Accessibility Initiative. (n.d.-a). Developing a keyboard interface. Retrieved October 3, 2026, from https://www.w3.org/WAI/ARIA/apg/practices/keyboard-interface/

World Wide Web Consortium Web Accessibility Initiative. (n.d.-b). Headings. Retrieved September 30, 2026, from https://www.w3.org/WAI/tutorials/page-structure/headings/

World Wide Web Consortium Web Accessibility Initiative. (n.d.-c). Landmark regions. Retrieved October 1, 2026, from https://www.w3.org/WAI/ARIA/apg/practices/landmark-regions/