# Immutable adoption candidate 0.3.7

Read CONTRACT-0.3.md and unit-content-manifest.json. Use only the exact published-to-parent private archive and its outer/file manifest hashes; this local directory is a development workspace. The frozen recovery-consent-v3.zip is a separate small compatibility patch and does not enable this engine.

This unit implements bounded local browser ZIP intake, exact sidecar planning, explicit hash/policy-bound approval, source-built bounded-memory metadata writing, separate independent four-format verifiers, consent-aware hash-bound checkpoint/reselection, and verified result ZIP delivery with originals/every-input accounting. It has real Chrome synthetic proof; it is not a public beta completion or universal media support claim.

Run python3 server.py for the loopback static harness, then python3 run_frozen_tests.py with installed Chrome and the retained pinned test-only playwright-core. No browser installation needed. Never substitute personal files: main.js/index.html use a fixed synthetic fixture policy and must not be deployed as product UI. Source-build reproduction inputs/patches/logs/notices are included; official compiler binaries/.deb packages are retained locally, omitted from this review payload and identified by exact fetch receipts.

Independent exact-unit adoption review is required before canonical integration. Documented component-specific license/source/notice materials must be publicly available through the webowner release arrangement before public beta. Hosted privacy/network audit, Safari/Edge and realistic HEIC/video remain unproven. Do not imply native filesystem no-clobber/crash guarantees. Canonical and native build9 remain unchanged; no Library replacement or public deployment occurred.
