# Bounded source-controlled rebuild execution plan

Authorized normal installed Docker Desktop launch succeeded. No helper, terms, settings, security, autostart or resource changes. Existing Docker memory8,217,575,424B/10CPUs; host free97,137,372KiB. Task container only: photo-wasm-build-v1, two CPUs, 4GiB memory (swap also4GiB),512 PIDs, no privileged mode, no Docker socket/user-library mount, no published ports, no-new-privileges. Only this runtime-build directory is mounted. Stop compilation below30GiB host free or after30minutes; no unrelated cleanup/system prune.

Base image pinned Linuxarm64 Debian digest da496358bd6934d2bd6a563a33176a2e50eff5490c54b4ac6fb051b69fef4071. Official base image fetched. Source snapshot and inputs pinned in JSON receipts; WASI SDK27.0 and Binaryen124 publisher digests enforced. Compressed official toolchain downloads total226,632,110B. New runtime source provenance is distinct from old npm WASM.

Preparation network: official Debian apt only, snapshot/package closure captured as exact .deb files + SHA256 and dpkg package inventory. No CPAN package installer or floating third-party executable. Remove perltidy/cpanminus steps; retain unminified ExifTool text and license notices. Upstream source downloads replaced by locally hashed archive reads. Source extraction validates traversal, link escapes and special files. No user files enter container.

Compile offline after disconnecting task container from bridge: native Perl, WASI zlib/bzip2, ExifTool13.42, patched WASI Perl, prefix assembly, reactor link and asyncify. NPROC2. Add max-memory268435456, initial-memory33554432, stack8388608. Required ExifTool installation/prefix copy must fail loudly. No suppressed mandatory errors. Keep all source patches, source archives, licenses and complete logs. Record SHA256 and WASM memory declarations; deterministic rebuild equality is a separate verification, not assumed.

Acceptance: runtime compiles; writer wrapper can load it; four synthetic fixtures produce candidates, independent browser/native structural proofs and resource failures meet contract. Initially8MiB/file,32MiB selected total,32MiB staged outputs,45s perwrite. Maxlinear memory does not cap JS heap; independent resource tests must also bound retained buffers. If blocked, report exact failing step and keep earlier npm runtime experimental, never silently use it in beta.

Redistribution inventory: exact Perl and ExifTool Artistic/GPL texts and modifications/source; zeroperl MIT; zlib, bzip2, WASI SDK/libc/LLVM compiler runtime and Perl extension component licenses/notices. Build tools versus linked runtime components distinguished. A proposed license route is not a completed license review.
