Read before downloading or integrating
Research alpha · MPL-2.0 · Exact-hash releaseTerms & informed use
A conformance contract is evidence about a governed process—not permission to trust, deploy, publish, or decide.
This page explains the supported purpose, data posture, authority limits, user responsibilities, license, and known limitations of the exact alpha.6 release.
Intended purpose and users
The primary users are UVLM product builders, adapter authors, integration reviewers, and exact-package reviewers.
Appropriate alpha use
- Study and test the nine-object contract.
- Replay the deterministic Web Steward reference route.
- Build a sidecar mapping for a product without changing its native logic.
- Test whether skipped checks, false hashes, altered candidates, or overbroad repairs fail closed.
- Compare conformance across materially different product modules.
Not an end-user decision product
- Not a truth or quality certification service.
- Not a clinical, legal, financial, accessibility, or security assessment.
- Not a general-purpose model runner.
- Not a production orchestration framework.
- Not authorization to merge the contract into the CoherenceLattice core.
Authority and interpretation
Candidate is not answer. Receipt is not truth. Hash is not correctness. Route is not authorization. Every shared telemetry event and contract object carries authority effect NONE unless a separate named human decision grants a narrowly defined action.
What APPROVE means inside the contract
An eligible APPROVE is candidate-review posture within a declared module scope. It does not automatically grant publication, deployment, product release, legal effect, clinical use, regulatory compliance, or scientific validity.
What HOLD and SKIPPED mean
HOLD preserves unresolved work. SKIPPED and NOT_EXECUTED remain visible and cannot be rewritten as PASS by changing totals, receipts, human rationale, or telemetry.
Privacy, network, model, and memory posture
Local and model-free
The bundled vertical slice uses deterministic fixtures. It makes no provider call and requires no model authorization.
Not required at runtime
The exact replay completed under a Python socket guard with zero network attempts. Dependency installation may contact a package index unless dependencies are supplied locally.
Not authorized
The alpha grants no persistent-memory write, model training, provider activation, or silent reuse of product or user data.
Caller-owned output paths
Alpha.6 was created because a valid contract can still be unsafe if its command surface treats caller directories as disposable.
- An output path may be used only when absent, empty, or exactly marked as this contract’s generated output.
- Unknown, missing, altered, linked, reparse, special, or nested content rejects without cleanup.
- Filesystem roots, version-control metadata, source-root self-targets, and source-root ancestors reject.
- The implementation contains no recursive deletion of caller-selected content.
- Portable code cannot prove race-free security against another local principal rewriting the same parent directory concurrently.
Backup responsibility. Preserve important files and run research software under a least-privilege account. Exact validation reduces risk; it does not replace operating-system isolation or backups.
License and rights posture
The exact source is authorized for public open-source alpha distribution under the Mozilla Public License 2.0 posture recorded in the package. The exact-hash receipt applies only to the named source bytes and evidence. It is not a legal opinion or a general license for other UVLM products, predecessor candidates, private source, or future modifications.
Modified versions receive new identities. A fork or successor must preserve MPL-2.0 obligations, identify changed files, avoid implying UVLM approval, and create new hashes. Do not reuse the exact UVLM release identity for altered bytes.
Known limitations accepted with this alpha
- Native Windows junction/reparse execution was not available; Linux symlink attacks and synthetic Windows branches passed.
- The fresh separate-pass review was produced in the same conversation as the builder and does not claim personnel independence.
- The executable reference route proves one narrow Web Steward fixture, not all product mappings.
- The installed CLI requires an explicit full source
--root. - An offline clean installation needs compatible dependencies available locally.
- Race-proof filesystem security, production hardening, accessibility conformance, and product usability certification are not claimed.
Portfolio guide boundary
“One Lattice, Many Tools” is explanatory documentation. It does not expand the MPL-2.0 license, convert proposed adapters into completed integrations, authorize a mapped product, or change any product’s own terms, rights, or release status.
Informed-use acknowledgment
By downloading, testing, modifying, or integrating the alpha, you acknowledge its research status, exact-hash identity, authority limits, known limitations, MPL-2.0 posture, and your responsibility for source permissions, environment security, backups, review, and any real-world decision.