/*
  OPULENT AURA — Design System Tokens v0.2
  Produced by Nasaq, Design-System Engineer · 2026-07-31 · under Wasm, Design Director.

  ══════════════════════════════════════════════════════════════════════════════
  [unbenchmarked] — APPLIES TO THIS ENTIRE FILE.
  ══════════════════════════════════════════════════════════════════════════════
  Everything here is verified against THIS HOUSE'S OWN standards. Sabr's competitive
  sweep — the only thing that tests whether the result actually stands at the level of
  the world houses — has not run on any of it. Sabr was stood down on a resource
  decision, not a quality one.
  **Closing the mark did not prove the system is «premium». Our standards are internal
  and measure themselves.** This tag is a RECORD, not a warning: when Sabr returns, it
  tells him which assets to sweep instead of leaving him to hunt for them.
  ══════════════════════════════════════════════════════════════════════════════

  SUPERSEDES tokens.css v0.1 (Naqsh). His file is NOT overwritten and NOT deleted — it
  carries a supersession banner and stays where it is. His enforcement model is kept
  verbatim, because it is correct:
      a violation that has no token and no class cannot be written.

  ── SOURCE TAGS. Every value carries one. A value with no tag is a defect. ──
    [CARD] Prestige Benchmark Audit Card v1.0      [W]  Web Surface Standard v1.0
    [PC]   Palette Standard v1.0                   [RD] Typeface Ruling (Haneen)
    [VIS]  Visual Identity System v1.0 (David)     [M1f] Mi'yar's tier-assignment ruling
    [NSQ]  a pick of mine inside a cited band      [PEND] absent on purpose, reason named

  ── THE RULES THIS FILE IS BUILT UNDER ──
  1. «Precise» may not be said of a value whose input is not recorded.
  2. No verdict travels without its margin:  PASS (measured / required — margin).
     Minimum ×1.25 on any permanent surface.
  3. A source of truth that can lag is not a source of truth — it is a cache. When a
     ruling closes, THIS FILE updates before any consumer of it. The delay between the
     two is the window in which every output is silently wrong.
  4. Thresholds must TOUCH — no overlap, no gap. A new floor is checked against the
     ceiling of the tier below it, never against itself.
  5. «Impossible» is written only where the block is structural. Where a block depends
     on browser behaviour it is marked DESIGNED, NOT OBSERVED until a render pass runs.
  6. ENTRY CONDITION FOR ENFORCEMENT — Haneen, binding on every token in this file:
       «Enforcement RAISES the evidence bar, it does not lower it. A wrong number
        enforced is worse than a wrong number written: the written one invites review,
        the enforced one invites trust.»
     **Only a value graded [Measured] may be enforced by a token.** Anything [Derived]
     or [Convention] stays written and checker-exposed — never welded into a mechanism.

  7. CANON vs IMPLEMENTATION — Haneen, and it widens what may be settled without rising:
       «A thing does not carry meaning because it is old, or because someone senior
        wrote it. It carries meaning if changing it changes what the house SAYS. A
        dimension in a founding document that nobody would notice being changed is
        IMPLEMENTATION, whatever the rank of whoever wrote it.»
     So **not everything in a founding document is canon.** The typographic allocation
     is canon — it fixes the house's voice. An undetermined dimension we are deriving
     is implementation.
     **ONE CONDITION, and it is the whole safeguard: the test is written into the token
     or the card. It is never held in the head.** «That one is implementation» is easy
     to say and impossible to review later if it was never recorded.

  8-bis. A VALUE TRAVELS WITH ITS SCOPE. [Ruled, after I broke it]
     **Any token whose value is shared between two elements must name the element it
     governs.** Worked case: tracking is **+120 for the WORDMARK** [VIS line 253] and
     **+100 for the DATE LINE** [Haneen] — *the wordmark announces, the date records;
     two registers.* Her ruling of +100 exists **because** +120 belongs to the wordmark.
     **I then wrote +100 onto a wordmark line — inverting the very ruling I was applying.**
     Mi'yar had earlier carried +120 the other way, from wordmark to date.
     **Same defect, opposite directions, and the second time the CORRECTION was the
     offender.** A value slid into its neighbour's place because the neighbour looked
     like it.
     This now completes a set of four that all prevent one movement:
       · a rule travels with its scope    · a floor travels with its unit
       · a number travels with its owner  · a value travels with its scope

  8-ter. STALE-AUDITOR — a DIFFERENT defect from the one we chased all session.
     All day we caught **a dead source being read as current.** This is its inverse:
     **a current source audited from a stale copy — the auditor is the stale one.**
     It does not fix the same way. A dead source is fixed by tagging the source; this is
     fixed **only by re-reading at the moment of action, never at the moment of planning.**
     Worked case: I built corrections for four cards from copies read hours earlier;
     the producer had already fixed more than I was coming to fix, and my "correction"
     would have reverted current, correct work. **And my manager issued an order built on
     the same stale picture in the same cycle** — it strikes the instruction as readily as
     the execution.

  8-quater. WHY THE «PROSE SHAPED LIKE CODE» TRAP KEEPS RECURRING — and it is
     structural, not personal. I have now written it four times and caught it four times.
     **Clear documentation and a real declaration have the SAME SHAPE.** Writing
     `--oa-m: 8px` inside a comment is the clearest way to tell a reader which token is
     meant — and it is exactly what makes a checker misread prose as a declaration.
     **The form that best explains to a human is the form that best deceives the tool.**
     So the temptation is built into the job, and the remedy is not vigilance:
       → in prose, name a token WITHOUT its declaration shape («MODULE M», not `--oa-m:`)
       → and strip comments before any extraction, always.

  8. THREE SLOT STATES, and they are three different defects — not degrees of one:
       · **EMPTY**   — has a value, currently unset. Gets filled, so it SHOWS.
       · **VOID**    — should not exist at all. Gets filled *correctly in form*, so it
                       does NOT show. **The most dangerous of the three**, because every
                       check that inspects values passes it.
       · **MISSING** — should exist and does not. Shows as absence.
     A system that treats these as one thing will catch the first and ship the second.

     · **SELF-FILLING** — the fourth, and it belongs to shipping surfaces only. [Haneen]
       **A blank in a FILE stays blank. A blank in a PRODUCT gets filled by the default.**
       So **an open item on a shipping surface is not an open item — it is an item
       already decided in someone else's favour.** The framework's default copy is not
       neutral: **it is another house's voice arriving inside ours.**
       Worked case: `/404` — the one page a visitor reaches by mistake, at the moment the
       house has already failed them, **and the page will write itself if nobody writes
       it.** *(It opens no new token category: mark + line + a way back, all present —
       and the way back is a link, so it consumes the already-open «link states» item.
       Cost zero, not because it is covered but because it lands on an open row.)*

     SELF-AUDIT AGAINST RULE 6, because the rule is worthless unread:
     every enforced criterion in this system is enforced by an ABSENCE (a class that
     was never written) or by a RULED structure — palette hexes [Measured], contrast
     pairs [Measured], the four faces [Ruled], the role×script law [Ruled].
     **ONE case needs stating plainly rather than passing quietly:** `--oa-scale-ratio`
     is a [Convention] — my pick inside W2's band. What is enforced is the FORM (that
     the scale IS a scale, generated from one ratio) and that form is structural. **The
     VALUE 1.25 is not enforced and must not be read as though it were.** Form and value
     are separate claims here, and only the form has earned a mechanism.
*/

:root {

  /* ══════════════════════════════════════════════════════════════════
     SET 1 of 2 — THE SYSTEM PALETTE. Six colours. This is the closed
     palette in full. [CARD X4 · C6 · PC]
     Verified value-by-value against Palette Standard §1 — six of six exact.
     Lab is the master; hex is only the screen realization. Print matches Lab.
     ══════════════════════════════════════════════════════════════════ */
  --oa-obsidian:   #1A1714;  /* Lab  7.98 · +0.79 · +2.49 — the one ground */
  --oa-gold:       #B8963E;  /* Lab 63.63 · +2.93 · +49.73 — accent only, never a ground [X2] */
  --oa-silence:    #F2EEE8;  /* Lab 94.25 · +0.31 · +3.36 — glass/space. NEVER a ground [PC2] */
  --oa-linen:      #DDD5C4;  /* Lab 85.48 · −0.12 · +9.37 — the warm light ground */
  --oa-sandalwood: #3D2B1F;  /* Lab 19.30 · +6.47 · +11.07 — depth · ink on light */
  --oa-ash:        #F7F5F2;  /* Lab 96.61 · +0.15 · +1.66 — light ground. NEVER #FFFFFF [X3] */

  /* Text tints — measured, never inferred [CARD C5] */
  --oa-text-muted: #9A948E;  /* on obsidian 5.95:1 — any text */
  --oa-text-faint: #6B6560;  /* on obsidian 3.11:1 — LARGE ONLY (≥24px, or ≥18.5px bold) */

  /* NOTE THE ABSENCE OF THE FRAGRANCE COLOURS FROM :root. That is deliberate and is
     the whole of A6 — see SET 2 below. */


  /* ══════════════════════════════════════════════════════════════════
     TYPE — THE LAW IS TWO ROLES, NOT FOUR NAMES. [RD2]
     ══════════════════════════════════════════════════════════════════
     «Restated as roles, the law cannot be broken by adding a script.» — Haneen.
     v0.1 encoded --oa-font-display / --oa-font-body: Latin-shaped slots. Adding Arabic
     to those needs new token names invented, which is the exact break RD2 prevents.
     ══════════════════════════════════════════════════════════════════ */

  /* The four ratified faces. All OFL. Gates 8 and 9 closed by Haneen. [RD] */
  --oa-face-identity-latin:  'Cormorant Garamond';  /* [RD]    Latin display */
  --oa-face-support-latin:   'Arsenal';             /* [RD1]   Latin support — RATIFIED */
  --oa-face-identity-arabic: 'Amiri';               /* [RD3a]  Arabic display */
  --oa-face-support-arabic:  'Almarai';             /* [RD3b]  Arabic support */

  /* PRE-AUTHORISED FALLBACKS — declared LOCKED, wired into NO role, and deliberately
     NOT shipped in the font kit. [RD1/RD3b] Invoked THROUGH WASM on a demonstrated
     hierarchy need, never picked. A token no role references cannot be reached by
     writing markup — only by editing this file, which is the gate. Encoded as options,
     the system would offer six faces instead of four. */
  --oa-face-support-latin-LOCKED:  'Alegreya Sans';
  --oa-face-support-arabic-LOCKED: 'IBM Plex Sans Arabic';

  /* THE ROLES — surfaces name these and never a face. A stack resolves per character,
     so one declaration carries both scripts and the count that matters stays two.
     ⚠️ DESIGNED, NOT OBSERVED — per-character fallback is CSS specification, not yet
     confirmed by rendering on this house's surfaces. */
  --oa-role-identity: var(--oa-face-identity-latin), var(--oa-face-identity-arabic), Georgia, serif;
  --oa-role-support:  var(--oa-face-support-latin),  var(--oa-face-support-arabic),  Georgia, serif;

  /* ── VERSION PINS [RD §Implementation] ────────────────────────────
     Each read out of the font binary (name table, nameID 5) and hashed. Not copied
     from a catalogue page. Kit + method: 03_Font_Kit\NSQ-A03__…md
       Cormorant Garamond  4.001  Catharsis Fonts
         F025294A22776F9E9FA1DEE3B4762ED874F3F99A48102AB088D383821AD00392
       Arsenal             2.000  Stairsfor
         CAF2B443DB1B8C4D8E1555A82E1CBA2FAEA9199589E63E1DF5D92635B2E0B675
       Amiri               1.002  Alif Type            (corroborates RD3a)
         D26CD95609ED51B6419E3C7D4A066CB9FAC7B73117868622F5B7F03998C68568
       Almarai             1.10   Boutros Int'l 2019   (corroborates RD3b)
         94CC03A8A668A8657735A39947FC4AB26A45F60DFDE20E892F5D4BAE968563C0
     A hash pins WHICH bytes; it never pins WHERE they came from. Provenance rests on
     Haneen's ruling and Qudra's acquisition — NOT re-verified by me.

     ══════════════════════════════════════════════════════════════════════════════
     ⚠️ THE PINS ABOVE ARE THE **SOURCE TTF** FILES. THEY ARE NOT WHAT SHIPS.
     ══════════════════════════════════════════════════════════════════════════════
     Surfaces load WOFF2. Pinning only the TTF would mean **shipping bytes we never
     pinned** — and my own argument forbids it: a pin proves WHICH bytes, so the bytes
     that reach the surface need an identity of their own.

     AND THE ANOMALY IS THE REASON WE MAY NOT CALL THE DERIVATION SUFFICIENT.
     Reconstruction does NOT return the source byte-for-byte. It adds 0.3–0.6%.
     So "the WOFF2 came from a pinned file, therefore it is pinned" does not hold.

     ENCODER, recorded because a DERIVED file's identity is incomplete without the tool
     that produced it:  wawoff2 2.0.1 (MIT) — Emscripten build of Google's woff2.

     SHIPPED-FILE PINS — SHA-256 of the 13 WOFF2 faces fonts.css actually declares:
       CormorantGaramond-Light        014805D09C824341DC01A3A29B3265316A3E413FB8D17DF289253432BB448CA5
       CormorantGaramond-Regular      FD6D264E5B6EF742E2AE16480FD14742080B5DFE73A9D19A4EA93832346A4CA1
       CormorantGaramond-LightItalic  C8AC29D280159691EB22F60EEC556A5F71FDA2880B38FEDCE426ACD380436773
       Arsenal-Regular                9CE80345261131BFBC63ECB8E30F95D73A3F9C25FD03423020A96365AA2B1C4A
       Arsenal-Bold                   2DB85919B00CE4062901DC24C3E17009BF57BDD7A3740DB5EEEC92FA9C288E00
       Arsenal-Italic                 59BE2083DD25BCBC2B78974ABA3A937B8CE79F3A0BB9A79C51084B8E81E2A564
       Arsenal-BoldItalic             C5230CB025ED62D2399FEC91DC8247F42851C065DA6AB6764BD93BB28629652F
       Amiri-Regular                  A3A694C1C23A4AD436CFD296DB13CA5983641D2FCCAB8A0A6F7F9A1E4B212B7C
       Amiri-Bold                     CB8D77C3EF613A014A938403479A74F9417B9CBC9CB1F240728A6D09E942234D
       Almarai-Light                  B60DF1C17A7AB9B1F02A7F3D3173A3FA5D8C85B0FFEA49AF170F7566E7B54820
       Almarai-Regular                D9E783A5E65746E31B20B8D42F009440B4CFF60EDF3A445FCFAA25EA8E07D57C
       Almarai-Bold                   3F6D5C9DCB690DA3901C5B7B8BBEB2A8D176251962EE019ACFAD712B81730AC0
       Almarai-ExtraBold              59622C20DC3A88928378C87C82CEB8A62C1799DB7A04A7DAE41F7AE609641019

     Read the two blocks as what they are: the first is the identity of what we
     ACQUIRED, the second the identity of what we SERVE, and the encoder name is the
     only thing linking them. Neither substitutes for the other. */

  /* TRACKING — +120/1000em. [House-canon · VIS v1.0 (David), line 253, READ AT SOURCE]
       «House name / Wordmark — Cormorant Light · +120 tracking»

     🔴 THIS TOKEN HAS NOW BEEN WRONG THREE TIMES, AND THE THIRD ERROR WAS MINE ALONE.
       1. It carried +120 under a citation to the AUDIT CARD — a derived document. The
          value was right; the citation pointed at a copy.
       2. I regraded it UNRULED, concluding the value was unsupported. Wrong: the
          support existed, in David's file, where I had not looked.
       3. I set it to **0.10em (+100)** and **pushed that into Naqsh's card as a
          correction.** It was not a correction. **I overwrote a correct number with a
          wrong one and told him it was ruled.** Reverted; his card restored byte-identical.

     WHAT THE SEQUENCE ACTUALLY SHOWS: at no point was the VALUE in doubt. **Every one of
     the three errors was about WHERE THE VALUE CAME FROM** — and my second and third were
     caused by chasing the citation instead of opening the source. **A broken citation made
     me doubt a sound number, and then replace it.**

     [Haneen] THE RULE THAT PREVENTS THE WHOLE SEQUENCE:
       **A citation points at the ORIGINATING document, never at one that quotes it.**
       A quoting document can drift, and a citation chain hides the drift.
     This is the cure for «a citation that looks like a source» — the defect I named, and
     then committed twice more while holding the name for it.

     ── SUPERSEDED READING, KEPT VERBATIM (it is errors 2 and 3 above, in their own words) ──
     History kept, because this token was wrong twice and both errors are instructive:
       v0.1 and my own v0.2 carried «+120/1000em [CARD T4]» **cited as a ruling when
       none existed** — I re-published an inherited citation under my own source-tag
       discipline, which is worse than inheriting it: the scheme exists to stop exactly
       that, and it passed because the citation LOOKED like a source.
       Then it was regraded UNRULED. Now it is ruled, and the ruled value is +100.
     Mi'yar's finding behind the ruling: **the clear-space floor is non-binding at any
     value from zero upward** — at zero tracking the clearance sits ×4.21 above the
     floor. **So the value is aesthetic, and an aesthetic value belongs to its owner.**
     ⚠️ CONSEQUENCE NOW REVERSED: with tracking fixed, **a width is a NUMBER again, not
     a function.** The wordmark minimums below are no longer tracking-dependent.
     Still settled independently of the amount: tracking is POSITIVE. Negative tracking
     is X7 and has no token — structure, not value. */
  --oa-track-wordmark: 0.12em;   /* +120/1000em · [House-canon · VIS v1.0 line 253, read at source] */
  --oa-track-label:    0.25em;   /* [Convention · unsourced] traced to NO standard —
                                    carried as a pick, never as a derived value. */

  /* ── THE MODULAR SCALE ────────────────────────────────────────────
     [W2] «exactly one modular scale, ratio locked between 1.20 and 1.333, declared in
     the file». [CARD T3] body ≥16px · captions ≥12px · nothing under 10px except legal.

     ⚠️ CORRECTED READING (Wasm, and he was right): T3's numbers are MINIMUM FLOORS,
     not required members of the scale. Reading them as members manufactures a W2
     conflict that does not exist. The requirement is: ONE ratio in band, and every
     size assigned to a role that CLEARS its floor.

     ⚠️ MI'YAR RULED SOMETHING LARGER THAN THE VALUES, AND IT CHANGED THIS BLOCK:
       «36/24/16/12/10 at ratios 1.50 · 1.50 · 1.3333 · 1.20 is not a scale with two bad
        values — IT IS NOT A SCALE AT ALL. Five stacked numbers. A scale is one ratio
        repeated. A set with four ratios has no rule by which to generate a sixth value.»
     And the practical difference, which is the whole point: patching the two bad values
     would have made the five PASS — and the day someone needed a sixth size they would
     have INVENTED it. Fixing the ratio means the sixth is GENERATED.
     General rule issued with it: **any «scale» is checked that it IS a scale before its
     values are checked at all.**

     BINDING W2 FORM: one declared ratio · all sizes GENERATED from it · rounding rule
     declared. So the ratio below is the SOURCE and every size is derived from it in
     calc() — change the ratio and the whole scale regenerates. Nothing is hand-typed.

        caption   body ÷ r     =  12.80px   PASS (12.80 / 12 — ×1.067)
        body      base         =  16.00px   PASS (16.00 / 16 — ×1.000)
        title     body × r     =  20.00px
        heading   body × r²    =  25.00px
        display   body × r³    =  31.25px
     Verified by Mi'yar independently: 1.2500 at every step.

     ROUNDING RULE, DECLARED (W2 requires it stated, not assumed):
       Generated values are used UNROUNDED. Where a surface requires an integer pixel,
       round half-up, and **the rounded value must still clear its floor** — a rounding
       that drops a size below its T3 floor is a reject, not a rounding.
     THE SIXTH SIZE, if ever needed, is generated — not invented:
       next = display × r = 39.0625px    (and so on, in either direction)

     ⚠️ THE ×1.25 MARGIN DOES NOT APPLY TO THIS NUMBER — ruled, and worth the space:
       «The ×1.25 exists to absorb PHYSICAL VARIANCE IN MANUFACTURING. A computed
        parameter has no variance. A number that is calculated, not manufactured, needs
        no headroom.»
     A 4mm cut comes off the machine at 3.9 or 4.1; a scale ratio returns 1.25 every
     time. So do NOT «pad» this value for safety — padding a parameter that cannot drift
     is the same over-compensation M1f rejects on tiers, applied to arithmetic.
     (Related: Mi'yar has since confirmed W2's band is INCLUSIVE — 1.20 ≤ r ≤ 1.333 —
     so 1.333 was legal all along. 1.25 stands on its own merits, not as an escape.) */
  --oa-scale-ratio:  1.25;
  --oa-size-body:    16px;                                                    /* base */
  --oa-size-caption: calc(var(--oa-size-body)    / var(--oa-scale-ratio));    /* 12.80px */
  --oa-size-title:   calc(var(--oa-size-body)    * var(--oa-scale-ratio));    /* 20.00px */
  --oa-size-heading: calc(var(--oa-size-title)   * var(--oa-scale-ratio));    /* 25.00px */
  --oa-size-display: calc(var(--oa-size-heading) * var(--oa-scale-ratio));    /* 31.25px */

  /* OUTSIDE the scale by law, not by oversight [CARD T3]. */
  --oa-size-micro: 10px;   /* legal lines only — never a design size */

  /* ⚠️ T5 TENSION, recorded because it is not self-evident [CARD T5]: the scale offers
     FIVE sizes and micro is a SIXTH. T5 caps a SURFACE at five distinct sizes IN TOTAL,
     micro included. A surface using the whole scale plus a legal line is at six and
     rejects. The scale is an inventory to pick from, never a set to use entirely. */

  /* Floors kept as their own tokens, so a floor is never inferred from the scale.
     [pt-convention — under re-derivation by MYR] — these are SCREEN floors, where a
     stroke is rasterised rather than produced, so the hairline argument below does not
     bite the same way. They carry the tag anyway: they are stated in the same units as
     the floors that failed, and I am not the one who gets to decide which of that class
     survives. See the TEXT FLOOR NOTICE further down. */
  /* ⚠️ THE UNIT FIELD APPLIED HERE IS THE UNCOMFORTABLE ONE, so it is stated plainly.
     These are measured in PX — a size. The render test showed that what actually
     governs legibility for a high-contrast face is RENDERED COVERAGE: Cormorant on
     Obsidian at exactly this 16px floor measures **2.12:1 against a nominal 15.44:1**.
     **So a surface can sit precisely on this floor and be unreadable.**
     [measured: px · governs: rendered coverage → MISMATCH]
     The floor is NOT removed — it remains the only screen reference the house has, and
     the lower bound never gets erased. But it does not, on its own, mean legible.
     Legibility on screen is settled by the render check, per surface, at shipping size. */
  --oa-size-body-min:    16px;
  --oa-size-caption-min: 12px;

  /* Reading rhythm [W2] */
  --oa-measure-min: 45ch;
  --oa-measure-max: 75ch;
  --oa-leading-body:    1.6;   /* [NSQ] inside W2's 1.4–1.8 */
  --oa-leading-display: 1.2;   /* [NSQ] inside W2's ≤1.3 ceiling */

  /* ══════════════════════════════════════════════════════════════════
     🔴 TEXT FLOOR NOTICE — EVERY VALUE IN THIS BLOCK IS UNDER RE-DERIVATION.
     ══════════════════════════════════════════════════════════════════
     [pt-convention — under re-derivation by MYR]

     WHAT HAPPENED: Mi'yar has WITHDRAWN «on-glass text ≥8pt». It was a
     SANS-SERIF CONVENTION. **The real floor is the HAIRLINE, not the point size** —
     and at 8pt the hairlines measure:
         Cormorant  0.064mm  vs glass 0.13mm  →  FAIL (0.064 / 0.13 — ×0.49)
         Arsenal    0.124mm  vs glass 0.13mm  →  FAIL (0.124 / 0.13 — ×0.95)
     **Both fail. The withdrawn floor permitted type that cannot be produced.**
     His measured replacements are CAP HEIGHTS, per face:
         screen-on-glass    Cormorant ≥3.611mm · Arsenal ≥1.871mm
         permanent surface  Cormorant ≥4.514mm · Arsenal ≥2.338mm
     He named it M1d again — a constant published without its input.

     AND THE FOIL ROW IS WORSE. Wasm re-derived it by the same method:
     foil stroke floor 0.20mm, Cormorant hairline 0.036mm per mm of cap →
         «no Cormorant below 8pt»  →  FAIL (0.064 / 0.20 — ×0.32)
         actual cap required: ≥5.56mm (×1.00) or ≥6.94mm (×1.25)
         Arsenal: ≥2.87mm (×1.00) or ≥3.59mm (×1.25)
     **Off by a factor of three to four from what is written below.** With Mi'yar.

     WHY EVERY VALUE HERE IS SUSPECT, NOT JUST THOSE TWO: all of them are stated
     in POINTS AND PIXELS — a size — when the thing that fails in production is a
     STROKE. One has been withdrawn, one recomputed and found wrong by ×3. The rest
     are the same class of statement and have not yet been checked.

     THESE VALUES ARE DELIBERATELY NOT REMOVED. A floor withdrawn is not a floor
     abolished: they remain the only reference the house has until replacements land,
     and the higher of any two floors binds. **I have derived no substitutes — the
     derivation is Mi'yar's, per face, per technique.**

     ⚠️ AND ONE OBSERVATION FROM THE NEW NUMBERS, raised not resolved:
     --oa-size-engrave-cap-min below is 3.5mm for Cormorant, while Mi'yar's new
     screen-on-glass floor for the same face is 3.611mm. Different techniques, so not
     necessarily in conflict — but our engraving floor now sits BELOW a freshly
     measured floor for the same typeface, and that is worth his eye. */
  /* ══════════════════════════════════════════════════════════════════
     THE UNIT FIELD — MANDATORY ON EVERY PUBLISHED FLOOR. Haneen, ruled.
     ══════════════════════════════════════════════════════════════════
       «Any published floor names the unit it was MEASURED in and the unit that
        GOVERNS, and rejects itself when they differ.»
     Not a recommendation — a required field. The review we had been running checked
     whether a number was CORRECT. **What was needed was whether it was APPLICABLE.**

     FOUR UNITS, not one — the last two were added after they each drew blood:
       · quantity   pt · px · mm · ratio
       · dimension  size vs stroke vs coverage
       · PRECISION  a measurement at em=400 is right in its unit and ±11% for the use
       · AGREEMENT  two numbers matching is NOT evidence if both carry the same
                    precision. Naqsh's 3.60% estimate matched Mi'yar's first
                    measurement exactly — **and both were too coarse.**

     ⚠️ AND THE GRADE RULE FOR ANY DERIVED TABLE — Haneen, «effort reads as evidence»:
     re-deriving five floors across four faces FEELS like verification; the work was
     arithmetic on one constant. **A derivation states the grade of its WEAKEST input,
     never its size, and inherits that weakest grade however large it grows.**
     → The hairline table above therefore carries the grade of ONE number: the
       re-measured ratio. Its breadth is not evidence of anything.
     ══════════════════════════════════════════════════════════════════ */
  --oa-size-print-body-min:     8pt;    /* [measured: pt · governs: reading on paper → MATCH — paper has no stroke-formation limit] */
  --oa-size-print-caption-min:  6.5pt;  /* [measured: pt · governs: reading on paper → MATCH] */
  --oa-size-foil-min:           6pt;    /* [measured: pt · governs: stroke-mm → MISMATCH → SELF-REJECTED · withdrawn both faces] */
  --oa-size-foil-cormorant-min: 8pt;    /* [measured: pt · governs: stroke-mm → MISMATCH → SELF-REJECTED · recomputed ×0.30, failing] */
  --oa-size-glass-min:          8pt;    /* [measured: pt · governs: stroke-mm → MISMATCH → SELF-REJECTED · withdrawn by MYR] */
  --oa-size-engrave-cap-min:    3.5mm;  /* [measured: cap-mm · governs: cap-mm PER FACE PER TECHNIQUE → UNDERSPECIFIED — names neither] */

  /* ══════════════════════════════════════════════════════════════════
     TEXT FLOORS BY HAIRLINE, PER FACE — MI'YAR, RULED. These REPLACE the
     point-size conventions above wherever a stroke must physically form.
     ══════════════════════════════════════════════════════════════════
     🔴 READ THIS BEFORE USING ANY NUMBER BELOW — THE WHOLE TABLE IS PROVISIONAL.
     Wasm's hold arrived after I had already transcribed this (our messages crossed).
     I am NOT removing it — a reference withdrawn is not a reference improved — but it
     does not get to stand unqualified:

       Naqsh recorded, in an honesty line, that **the Cormorant hairline ratio used in
       every one of our calculations is his own older TAGGED ESTIMATE**, and that
       FontForge is what would close it. **0.036mm per mm of cap = 3.60% — the exact
       figure in the table below.**
       So it is possible that the class of floors we withdrew and re-derived tonight
       **rests on an unverified input.** Mi'yar has been asked one line: independently
       measured, or inherited from the estimate?

     **UNTIL THAT ANSWER ARRIVES, NO VALUE HERE IS TO BE TREATED AS FINAL** — including
     the ones that replaced values we called wrong. **A recomputation is only as sound as
     the constant it recomputes from**, and that is the same defect one layer down:
     we corrected the unit and may not have verified the input.

     ── CURRENT · REVISION 2 · em=2400, denominator = cap H ──
     Minimum CAP HEIGHT in mm. BOTH COLUMNS PUBLISHED — nobody has to divide.
     Hairline ratios: Cormorant **3.400%** · Arsenal **7.367%** — grade [Measured ±2%],
     rasterised at em=2400. The ±2% is the grade of the whole table (rule: a derivation
     carries its weakest input's grade, not its size).

       technique          Cormorant ×1.00 / ×1.25   Arsenal ×1.00 / ×1.25
       fine laser              1.47 /  1.84            0.68 / 0.85
       mechanical              2.94 /  3.68            1.36 / 1.70
       screen-on-glass         3.82 /  4.78            1.76 / 2.21
       foil                    5.88 /  7.35            2.71 / 3.39
       emboss                  8.82 / 11.03            4.07 / 5.09

     CROSS-CHECKED, not derived: with both columns published, ×1.00 × 1.25 must
     reproduce ×1.25. All ten pairs agree within the propagated tolerance (±0.01125 —
     each column is published to 2dp, so ±0.005 each, plus ±0.00625 through the factor).
     **My first pass used ±0.01, which is the DISPLAY precision rather than the
     propagated one, and produced a false mismatch — the night's own defect, on my own
     check.** Corrected: 10/10 consistent.

     ⚠️ CORRECTED CLAIM — I called the following an INDEPENDENT consistency signal.
     **It is not independent. It is algebraically identical, and Mi'yar caught it.**
       I wrote: Arsenal's hairline ratio is 2.167× Cormorant's while Cormorant's floors
       are 2.162× Arsenal's, and read that as coherence.
       But floor = technique-limit ÷ hairline-ratio. So
           (Cormorant floor ÷ Arsenal floor) = (Arsenal ratio ÷ Cormorant ratio)
       **BY DEFINITION.** Those two numbers cannot disagree. The 0.2% gap is decimal
       rounding and nothing else.
     **So it is a TRANSCRIPTION check — precisely the thing I said it was not** («not
     merely copied correctly»). Its real value is proving the arithmetic was done right.
     That, and no more.
     [V0c] THE TEST BEFORE RECORDING ANY CONVERGENCE: **name the independent dimension.
     If you cannot name it, what you have is internal consistency, not verification.**
     Left here rather than deleted, because a claim that was wrong is worth more visible
     than absent — it is the same family as the citation that looked like a source, and
     I produced both in one session.

     🔴 THE ARABIC ROWS ARE REMOVED, NOT ADJUSTED — and the reason is worth keeping:
     **Arabic has no cap height, so a «cap-height floor» for Amiri or Almarai is not a
     wrong number — it is a meaningless one.** Mi'yar applied V7 to his own output.
     The previous entries (Amiri 3.47% · Almarai 9.79%) are struck for that reason, not
     re-measured. The Arabic pair does not touch the object in any case (X12).

     ── SUPERSEDED · REVISION 1 · struck by replacement, NOT erased ──
       technique          Cormorant (3.60%)      Arsenal (6.95%)
       fine laser          1.39 /  1.74           0.72 / 0.90
       mechanical          2.78 /  3.47           1.44 / 1.80
       screen-on-glass     3.61 /  4.51           1.87 / 2.34
       foil                5.56 /  6.94           2.88 / 3.60
       emboss              8.33 / 10.42           4.32 / 5.40

     WHY REVISION 1 FELL — and it is a measurement improvement, NOT a change of ruling:
       (a) PRECISION. It was measured at **em=400px**, where quantisation is ≈0.4
           percentage points — **±11% on the resulting floor.** A number correct at the
           precision it was taken at, and **too coarse for the use it was put to.**
       (b) DENOMINATOR. The stroke was measured against the height of **O**, while the
           published ratios are against **cap H** — two different denominators about to
           be compared as though they were one.
     Re-measured at em=2400 against cap H. Net: Cormorant floors **+5.9%**, Arsenal **−5.7%**.

     ⚠️ AND NOTE WHICH DEFECT THIS IS: **precision is a unit too.** A value right at the
     resolution it was captured at, wrong for the resolution its use demands, is the same
     failure as points-where-strokes-govern and solid-fill-where-coverage-governs. **This
     one occurred on the measuring instrument itself, while we were discussing the
     pattern.** Recorded as the sixth instance.

     (Wasm's foil re-derivation survives the revision: Cormorant at 8pt moves from ×0.32
     to **×0.30** — still failing.)

     ⚠️ «FOIL ≥6pt» IS WITHDRAWN FOR BOTH FACES — Arsenal at 6pt computes ×0.48.
     The retained `--oa-size-foil-min` above is reference only, superseded by this table.

     ⚠️ PAPER PRINT (8pt / 6.5pt) IS NOT SUPERSEDED and does NOT take the ×1.25 margin.
     Ruled explicitly: paper has no hairline-formation limit, so those two remain
     READING conventions rather than production floors. **The ×1.25 absorbs physical
     variance; where nothing physically fails to form, there is nothing to absorb** —
     the same distinction as the scale ratio, applied to a different quantity.

     ── THE RECORD: FOUR FIELDS, ADOPTED BY MI'YAR ──
     Technique alone cannot decide a text floor, because the floor is a function of the
     FACE: Cormorant needs roughly TWICE Arsenal on the same process. So text records
     what the mark records, plus the face. Record the INPUTS, never only the result —
     the same shape as M1f's four fields and M3a's stored `a`. */
  /* ── THE ARABIC GAP IS CLOSED — T3-arabic, Mi'yar. ──
     I raised that this field accepted Amiri and Almarai while --oa-text-cap had no
     meaning for them, and refused to invent a metric. His ruling:

       **The Arabic measure is the height of the reference letter `ه` on a RENDERED
        sample — not a cap height.**
       At em=2400:  Amiri `ه` = 35.5% of em  ·  Almarai `ه` = 49.6% of em
       Thinnest stroke inside `ه`:  Amiri 30.75% of that height · Almarai 14.36%

     AND THE STRUCTURAL PART, which is the half that changes the encoding:
     **an Arabic placement records a DIFFERENT FIELD — not the same field with an Arabic
     value.** So `--oa-text-cap` is Latin-only, and Arabic uses `--oa-text-ref-height`
     below. Two fields, because they measure two different things — **the same reason
     the Arabic rows were removed rather than adjusted.**

     ⚠️ AND THERE ARE NO ENGRAVING FLOORS FOR ARABIC AT ALL — not «not yet», but never:
     the Arabic pair does not touch the object (X12 / Gate 5), so its floors are
     DIGITAL ONLY. A field that cannot arise needs no value. */
  --oa-text-face:      /* per placement: Cormorant | Arsenal | Amiri | Almarai */ initial;
  --oa-text-technique: /* per placement: laser | mechanical | screen-on-glass | foil | emboss */ initial;
  --oa-text-cap:       /* LATIN ONLY — produced cap height, mm. [measured: cap-mm · governs: cap-mm] */ initial;
  --oa-text-ref-height:/* ARABIC ONLY — produced height of `ه`, mm, on a RENDERED sample.
                          [measured: ref-letter-mm · governs: ref-letter-mm] · digital surfaces only */ initial;
  --oa-text-hairline-margin: /* per placement: computed; ≥1.25 on a permanent surface */ initial;

  /* ⚠️ WORST-CASE CONTENT RULE — binding on every size and clearance token here.
     A token that assumes representative content is verified against the LONGEST
     POSSIBLE value, never a sample. Live case: an engraving string was measured on
     `12 · III · 2024`, and `III` is among the NARROWEST Roman months — `VIII` is the
     widest. Every downstream figure inherited a best case dressed as a measurement.
     Same logic as touching thresholds: **the failure lives at the edge of the range,
     not in the middle.** A sample that fits is not evidence that all values fit. */


  /* ══════════════════════════════════════════════════════════════════
     SPACE [CARD S2 · W1]
     ══════════════════════════════════════════════════════════════════ */
  /* MODULE M — 8px · grade [Convention · compatibility-checked] · ONE M for the house.
     SOURCE: the AMENDED published text of S2/W1 — **«M = 8px is fixed for the house; a
     layout file INHERITS it and declares only its column count.»** Not a ruling relayed
     through my manager: **Mi'yar amended the standard itself, so the citation now points
     at the originating document rather than at something quoting it** — my own rule [43],
     applied to my own token. Same value, source raised one grade.
     *(The old text — «each layout file declares its own M» — was sufficient for auditing
     a single asset and wrong for a system. Its worst form: **a reviewer correctly
     applying the standard would have rejected the house's own unified token. Correct
     punishing correct.**)*
     (deliberately not written here as a token-shaped string: prose that looks like a
     declaration is what fooled my own checker twice today)

     ⚠️ [45] M GOVERNS LAYOUT SPACING ONLY. Not type sizes. Not visual values inside a
     component. **Ruled because two of Mi'yar's own rulings collided on a value neither
     mentioned:** «every gap is a multiple of M» versus **the focus ring at 2px width and
     2px offset — and 2 is not a multiple of 8.**

     🔴 AND THE SCOPE LANDED IN THE RULE'S OWN TEXT, NOT IN A FOOTNOTE. That distinction
     is operational, not verbal:
       **An EXCEPTION reads as an anomaly, and anomalies get tidied up later.**
       **A RULE says the thing was never inside to begin with.**
     So the type scale (20 · 25 · 31.25) and the focus ring (2px / 2px) are
     **OUTSIDE M BY THE RULE — not «exempt from M».** Worded that way deliberately:
     **otherwise the first person tidying the file will try to drag them onto the grid,
     and will feel like they are fixing it.**
     *(Same family as «a partial remedy manufactures a false signal» — here on the label
     rather than on the stamp.)*
     Read M's scope widely and you either **reject the focus ring** (breaking an
     accessibility requirement) **or inflate it to 8px** (inventing a number with no
     source). **Both wrong.** The ring is legal at 2px/2px exactly as specified.
     *(I had already written the same boundary from the other side — that 20/25/31.25 do
     not land on multiples of 8 and that this is correct. Same limit, reached from type;
     the ruling reached it from components.)*

     ⚠️ AND THE GRADE IS [Convention], NOT [Derived] — Mi'yar corrected the strength of
     his OWN evidence, and the correction is the instructive part:
       **16 × 1.5 = 24 = 3M EXCLUDES; it does not SELECT.** Every divisor of 24 passes
       (1·2·3·4·6·8·12·24). It kills 5, 7, 9, 10 — **and never distinguishes 8 from 4 or
       12.** So the compatibility check narrows the field; **it does not nominate the
       winner.** Choosing among the survivors is a judgement, and it is recorded as one:
       **4 is so permissive it stops rejecting anything — and a grid's worth is in what
       it refuses; 12 forbids ordinary internal gaps; 8 is where the constraint bites
       without outlawing small spacings.**

     [46] A RULE STATED AS UNIVERSAL READS AS *BROKEN* AT ITS FIRST LEGITIMATE EXCEPTION,
     RATHER THAN AS *BOUNDED* — **and the exception usually arrives from the rule's own
     author, in the same breath.** Mi'yar wrote «every gap is a multiple of M» and the
     2px focus ring in one message. **So a rule ships with its scope, or it ships broken.**
     W1/S2 enforce «every gap is an integer multiple of M» — **and the Standard never
     fixed M's value.** So a working control is running on top of a constant nobody
     ruled: **the same shape as the tracking failure, with a far larger blast radius.**
     Tracking appears on a wordmark. **M appears in every spacing on every page — its
     error MULTIPLIES rather than adds.**
     Not removed, and no substitute derived. Asked as a reading, not a derivation:
     *is 8px ruled or inherited, and from which originating document?*

     ── MI'YAR'S ANSWER: NOT RULED. NO DOCUMENT CARRIES A NUMBER, BECAUSE HE NEVER
        WROTE ONE. ──
     S2/W1 require that **each layout file DECLARES its own M** and that all spacings be
     integer multiples of it. **They never fix one value for the house.**
     **And the question exposed that the rule is incomplete for a design system, which is
     a defect in his Standard rather than in these tokens:** «each file declares its own
     M» works when auditing a single asset, but **for one system feeding a whole site,
     two files with different M both PASS and the result is an inconsistent house.**

     What supports 8 — by calculation, not taste, and it is a single calculation:
       body 16px × line-height 1.5 = 24px = **exactly 3M**. The line box lands on the grid.
     ⚠️ **But 20 / 25 / 31.25 from the scale do NOT land on multiples of 8**, and that is
     correct rather than a flaw: **M governs SPACING, not type sizes.** Stated explicitly
     so nobody tries to force the scale onto the grid.
     **Verdict: 8px is supported by one explicit calculation and is not ruled. The ruling
     is Haneen's.** Tag stands until she answers.

     ── AND THE FRAMING, CORRECTED BY HANEEN — recorded in HER words, not in the harsher
        version I was about to write against myself ──
       **The rule «every spacing is an integer multiple of M» was UNTESTABLE until this
        token gave M a value. So this token is what made his rule checkable — and it did
        so without support.**
       **Doing something NECESSARY without support is a different defect from doing
        something WRONG.**
     The gap is that the Standard published a rule without its constant; **I filled it so
     the system could function.** Written this way deliberately: **a record that blames
     its author more than the facts warrant reads as truth later**, and this file will be
     read long after the exchange is forgotten.

     [43] A BROKEN CITATION IS AN ORDER TO SEARCH, NEVER AN ORDER TO CHANGE.
       That a value is unsupported creates a duty to **find its source**. It never
       licenses replacing it. **My own case is the proof: replacement felt like
       diligence, produced a new value with no source, discarded whatever justified the
       old one — and arrived wearing the shape of a fix.**

     [44] THE FORM OF M'S ANSWER IS RULED, THOUGH ITS NUMBER IS NOT.
       Either **derived from the type scale's own rhythm** (so the grid never fights the
       typography), or **a declared `[Convention]`**. **A declared Convention is a
       legitimate grade; a silent one is not.** And 8 is **not** to be defended because
       it is common — *«reasonable, consistent, and outside the system»* is the exact
       sentence of the defect. **It gets drawn once, not hunted.** */
  --oa-m:  8px;   /* the declared module M — value unruled, see above */
  --oa-m2: 16px;  --oa-m3: 24px;  --oa-m4: 32px;  --oa-m6: 48px;  --oa-m8: 64px;
  --oa-margin-min: calc(var(--oa-m) * 2);   /* outer margins ≥2M at every breakpoint [W1] */
  --oa-space-tolerance: 2px;                /* ±2px screen · ±0.5mm print [CARD S2] */


  /* ══════════════════════════════════════════════════════════════════
     THE MARK [CARD M-series · W4 · M1f]
     ══════════════════════════════════════════════════════════════════
     CORRECTED: v0.1 held --oa-mark-min-screen: 20px — a value in NO ruling, too low
     for canon art (23px) and narrating the pixel-fitted variant as unapproved when W4
     records it ratified 2026-07-31. Two rulings behind. The screen floor is a TABLE,
     never a single number.

     THRESHOLDS CHECKED FOR TOUCH (rule 4 above): 15|16 · 22|23 · 34|35 · 59|60 · 99|100.
     No gap, no overlap, verified edge by edge. This is the check that caught the 38px
     trap: flooring collar art at 38 would leave 35–37 with no permitted tier at all. */
  --oa-mark-floor-absolute: 16px;   /* below this: NO MARK AT ALL [W4] */
  --oa-mark-band-pixelfit:  16px;   /* 16–22px — pixel-fitted variant ONLY, incl. favicon */
  --oa-mark-band-invisible: 23px;   /* 23–34px — T4 art. Canon art starts here */
  --oa-mark-band-collar:    35px;   /* 35–59px — T3 art */
  --oa-mark-band-standard:  60px;   /* 60–99px — T2 art */
  --oa-mark-band-hero:     100px;   /* ≥100px  — T1 art */
  --oa-mark-clearspace:     0.5;    /* × mark height, all sides, at EVERY size [CARD M3] */

  /* PHYSICAL TIER FLOORS [CARD, ruled 2026-07-31] — twenty values, in no token until v0.2.
     🔴 MARGIN LABEL ADDED — these carried NO margin designation until Mi'yar published his
     column header, and I had not noticed the omission. All twenty are the **×1.00** column;
     his ×1.00 mark table reproduces them exactly, value for value, which is how the gap
     surfaced. **On a permanent surface the binding figure is ×1.25 — these × 1.25.**
     A floor without its margin is the same underspecification as a floor without its unit:
     it is not wrong, it is unusable without a fact that was never written down.
     [measured: height-mm · governs: height-mm · margin: ×1.00 baseline] */
  --oa-mark-T1-laser:  5.00mm;  --oa-mark-T1-mech: 10.00mm;  --oa-mark-T1-screen: 13.00mm;
  --oa-mark-T1-foil:  20.00mm;  --oa-mark-T1-emboss: 30.00mm;
  --oa-mark-T2-laser:  3.00mm;  --oa-mark-T2-mech:  6.00mm;  --oa-mark-T2-screen:  7.80mm;
  --oa-mark-T2-foil:  12.00mm;  --oa-mark-T2-emboss: 18.00mm;
  --oa-mark-T3-laser:  1.88mm;  --oa-mark-T3-mech:  3.75mm;  --oa-mark-T3-screen:  4.88mm;
  --oa-mark-T3-foil:   7.50mm;  --oa-mark-T3-emboss: 11.25mm;
  --oa-mark-T4-laser:  1.17mm;  --oa-mark-T4-mech:  2.33mm;  --oa-mark-T4-screen:  3.03mm;
  --oa-mark-T4-foil:   4.67mm;  --oa-mark-T4-emboss:  7.00mm;

  /* [M1f] TIER ASSIGNMENT — MI'YAR'S RULE, NOT MINE, AND NOT DERIVED HERE.
       «Use the THINNEST tier that clears its floor at the produced size with the
        chosen technique (×1.25 on a permanent surface). Not by derivation — where the
        art was born is ratios, not physics. Not by function — a name is a proxy for
        size, and a proxy fills in wrong.»
     His own worked example, recorded because it cuts against intuition: the bag plaque
     was computed at T3 «to be safe» and T2 was correct, being the thinnest tier that
     clears. OVER-CAUTION IS ALSO A LOSS — coarser art produces a heavier mark than the
     surface can carry. Both directions lose.
     ⚠️ I encoded NO assignment logic of my own. The ranges below are Mi'yar's,
     published under M1f in the Prestige Benchmark Standard v1.0, transcribed verbatim.
     I asked for them by code rather than deriving them — his reason: these shift with
     technique, and ONE wrong derivation becomes a WHOLE wrong table.

     M1f — MARK HEIGHT IN mm, PERMANENT SURFACES. Mi'yar, published:
       technique      T1         T2              T3             T4            no mark below
       fine laser     ≥6.25      3.74–6.25       2.34–3.74      1.46–2.34     1.46
       mechanical     ≥12.50     7.49–12.50      4.68–7.49      2.91–4.68     2.91
       screen         ≥16.25     9.73–16.25      6.09–9.73      3.79–6.09     3.79
       foil           ≥25.00     14.97–25.00     9.36–14.97     5.83–9.36     5.83
       emboss         ≥37.50     22.46–37.50     14.04–22.46    8.74–14.04    8.74

     ⚠️ AND A BOUND ISSUED WITH THEM THAT CHANGES WHAT THIS TABLE *IS*:
       «M1f applies WHERE NO ART IS NAMED IN THE CANON. Where David named the tier for a
        placement — as he did with T4 for the invisible signature — THE NAMING IS THE
        ASSIGNMENT, and these ranges become a CHECK, not an ASSIGNER.»
     So the table never overrides a canonical naming. It assigns only into silence, and
     verifies everywhere else. Read it the other way round and it would quietly reassign
     a tier David already chose. */
  --oa-margin-min-permanent: 1.25;   /* ×1.25 floor on any permanent surface [M1f] */

  /* [M3a] CLEAR SPACE ON A ROUNDED CARRIER — RULED A FUNCTION, NOT A CONSTANT:
         h ≤ D ÷ (1 + √(1 + a²))        a = ink-box ratio of the art being placed
     Declared input for the favicon case: a = 0.4142.
     CSS cannot express a square root, so the function is NOT faked here as a number.
     Any clearance bound on a rounded carrier is computed from its own `a` and recorded
     with that `a` beside it. **A constant published without its input is exactly the
     M1d defect** — the third appearance of that same fault in one night. The flat
     --oa-mark-clearspace above is the STRAIGHT-EDGE case (M3) and is not a substitute
     for this one. */
  --oa-m3a-favicon-a: 0.4142;   /* the declared input, so the output is re-derivable */

  /* [M1f] PLACEMENT RECORD — FOUR FIELDS, NOT ONE. Binding: every placement records
     tier · technique · produced size · computed margin. Encoded as four so a later
     auditor re-derives the assignment instead of asking us what we meant. */
  --oa-placement-tier:     /* [PEND] per placement — T1|T2|T3|T4 */ initial;
  --oa-placement-technique:/* [PEND] per placement — laser|mech|screen|foil|emboss */ initial;
  --oa-placement-size:     /* [PEND] per placement — produced size, mm or px */ initial;
  --oa-placement-margin:   /* [PEND] per placement — computed, ≥1.25 if permanent */ initial;

  /* The 3mm Invisible Signature — T4 ART ONLY, margin NOT uniform [CARD]:
     laser  PASS (0.1286 / 0.05 — ×2.57)
     mech   PASS (0.1286 / 0.10 — ×1.29)
     screen FAIL (0.1286 / 0.13 — ×0.989, short by 1.1%)
     On hero geometry the same 3mm mark strokes 0.03mm and fails every technique.
     The tier deviation is the only thing that makes the signature real. */
  --oa-signature-size: 3mm;

  /* Wordmark [CARD M5]
     Tracking is now ruled (+100), so these are NUMBERS again rather than functions of
     an open value. The pending-input flag they carried is cleared, not deleted:
     it was correct while tracking was open and is resolved now that it is not.
     [measured: mm/px · governs: width at tracking +100 → RESOLVED] */
  /* [Convention — unverified against the hairline] — Mi'yar's wording, verbatim, and
     deliberately not widened: these are WIDTH floors that have not been checked against
     the hairline. That is the precise open question; anything broader would be my
     paraphrase travelling under his name. A number travels under its owner's name. */
  --oa-wordmark-min-print:   20mm;
  --oa-wordmark-min-digital: 60px;
  --oa-tagline-cap-ratio:    0.40;   /* a RATIO of cap height — never was tracking-dependent */

  /* ⚠️ AND A DISTINCTION FOR ANY SURFACE SHOWING BOTH — Haneen, and it is not stylistic:
     **the wordmark ANNOUNCES and the date RECORDS. Two different registers, so they do
     not take the same typographic setting.** If a page shows both, one template must
     not set them from one value. `--oa-track-label` is the recording register and is
     deliberately a separate token from `--oa-track-wordmark` for that reason. */


  /* ══════════════════════════════════════════════════════════════════
     MOTION [W3] — restraint quantified. Absent from v0.1 entirely.
     ══════════════════════════════════════════════════════════════════ */
  /* ══════════════════════════════════════════════════════════════════
     COMPONENT GROUP — SCOPE, AND THE CONDITION THAT REOPENS IT.
     ══════════════════════════════════════════════════════════════════
     This group is INTERACTION STRUCTURE ONLY: button · field · error message · menu.
     **No price token. No cart. No discount field — not one of them «for completeness».**
     A component with no route consuming it does not get built.
     Scope ruled from `/discovery`: the button, the field and the error message are
     interaction structure, not commerce — **a focus ring does not depend on who owns
     the pricing** — and everything the vacant commercial seat actually owns (price,
     discount, cart) is outside this launch by the Founder's own sentence: *«the site
     complete, lacking only that the products be displayed.»*

     🔴 RE-ARMING CONDITION — Haneen, and it lives HERE rather than in a report on
     purpose: **a structural fix is invisible, so it reads as an absence — and a
     condition that lives in a message dies with the message.** It is written beside
     the thing it guards:
       **The day a price appears on any page, this group's scope reopens immediately —
        and at that point it is not a design question. It is a question of honesty with
        people outside the house, and that is not this seat's category.**

     TOKENS: none yet. Absent, not forgotten — see NSQ-A06 §2. Blocked behind
     breakpoints and the focus-ring ruling, in that order.
     ══════════════════════════════════════════════════════════════════ */

  /* ── FOCUS RING — RULED [MYR-W2b]. Mandatory, and encodable today. ──
     ≥3:1 against the ADJACENT background · thickness ≥2px · offset ≥2px ·
     on every interactive element · never removed · never reduced to a colour change.
     Colours from the measured matrix:
       dark grounds  → Antique Gold   (6.35:1 on Obsidian)
       light grounds → Obsidian       (12.23 on Linen · 16.40 on Ash White)
       gold on light → FORBIDDEN      (1.93 — below the floor)

     ⚠️ AND A CORRECTION TO ME, recorded because I nearly blocked this on a bad reason:
     I hesitated to encode a ring at all, arguing the rendered-contrast collapse made
     published pair values unsafe. **Wrong in its direction.** That collapse is about a
     **hairline of a high-contrast typeface rendering sub-pixel**. **A 2px solid ring has
     no hairline, so the C5 numbers describe it accurately.**
     Applying the text warning to a solid graphic element is **an A3 scope error in
     reverse — a correct warning used outside its range.** The caution was right; my
     range for it was not. Encodable now, with no render pass needed. */
  --oa-focus-width:  2px;
  --oa-focus-offset: 2px;
  --oa-focus-on-dark:  var(--oa-gold);      /* 6.35:1 on Obsidian */
  --oa-focus-on-light: var(--oa-obsidian);  /* 12.23 on Linen · 16.40 on Ash White */

  /* ── COLLECTION SURFACE — WRITTEN AS A POSITIVE REQUIREMENT, NOT A PROHIBITION ──
     Measured: the eleven print lines run 80 to 183 characters — **2.29×**, and
     `0008 ANCIEN` is 31% longer than the next.
     [Haneen] The print line is **never truncated, clamped, or given an ellipsis. It
     wraps.** If eleven uneven lines do not fit the layout, **the layout gives way, not
     the line** — 0008's line is long because it does work no other line does (the
     descriptor rules; the notes do not describe it), and **clipping it would repeal a
     house ruling with a stylesheet.**

     🔴 THE PROHIBITION ALONE DOES NOT SECURE THIS, which is why it is phrased positively:
     someone can honour «do not truncate» completely and still build fixed-height cards
     that happen to fit today's longest line — **breaking the first time a text is edited
     or a twelfth fragrance arrives.**
       → collection item height is **auto**. No `height` or `max-height` on it.
       → alignment must handle rows of unequal height.
     **A prohibition is read at review. A positive requirement is read at build.** */
  --oa-collection-item-height: auto;

  /* ── PAGE TITLE / DESCRIPTION — [Convention], Haneen. ~60 and ~155 characters.
     🔴 THE NUMBER AND ITS PRECEDENCE PRINCIPLE ARE ENCODED TOGETHER, DELIBERATELY:
       **The sentence holds. The character count gives way.**
       **A count is NEVER the reason a line loses a word that carries meaning.**
     Written as one because **a number without its principle reads as a FLOOR when it is
     a TARGET** — and a target mistaken for a floor turns an editorial guideline into a
     truncation rule, which is exactly the defect the collection line ruling exists to
     prevent, one surface over. */
  --oa-meta-title-chars: 60;
  --oa-meta-description-chars: 155;

  --oa-motion-min: 200ms;
  --oa-motion-max: 600ms;
  --oa-motion-ease: cubic-bezier(0.4, 0.0, 0.2, 1);  /* [NSQ] one easing family, site-wide */
}


/* ═══════════════════════════════════════════════════════════════════
   SET 2 of 2 — THE FRAGRANCE LAYER. NOT MEMBERS OF THE PALETTE.
   ═══════════════════════════════════════════════════════════════════
   [VIS line 415, David, verbatim]:
     «Each fragrance carries the natural color of its matured liquid. THIS IS THE
      SECOND LAYER OF IDENTITY — specific to each fragrance, REVEALED IN PHOTOGRAPHY.»
   [PC5]: they never join the system palette, never tint chrome, never appear together
   as a "rainbow" surface.

   Note David's containment is TIGHTER than PC5's: he scopes them to photography, not
   merely away from chrome. Encoded to his text, which is the stricter of the two.

   HOW THE SEPARATION IS ENFORCED — and this is the point of A6:
   these tokens are declared HERE, inside the fragrance context, and NOT in :root.
   A var(--frag-…) reference on a system surface resolves to nothing, so the colour
   never paints. The mix is UNWRITABLE rather than rejected-after-writing.
   ⚠️ DESIGNED, NOT OBSERVED — this relies on CSS custom-property scoping resolving as
   specified. Correct by specification; not yet confirmed by rendering.

   Describing C6 as "6 + 11" is what weakens X4: under that phrasing a fragrance hex on
   chrome reads as in-palette. The closed palette is SIX.
   ═══════════════════════════════════════════════════════════════════ */
.oa-context-fragrance {
  --frag-0003-absorbed:  #C17A3A;   /* Warm amber — late sun through glass */
  --frag-0007-gravitas:  #7B3D1A;   /* Deep cognac */
  --frag-0008-ancien:    #5C3A18;   /* Ancient amber */
  --frag-0009-vanilla:   #D4B97A;   /* Honey cream */
  --frag-0014-bower:     #E8C5C0;   /* Blush */
  --frag-0015-dusk:      #C4907A;   /* Dusty rose gold */
  --frag-0022-nocturne:  #4A1520;   /* Black cherry */
  --frag-0023-smolder:   #6B2C12;   /* Dark ember */
  --frag-0024-alba:      #C8B870;   /* Cold gold */
  --frag-0025-limpid:    #E8E0CC;
  --frag-0032-oud:       #A07830;
  /* All eleven traced to source: [VIS] lines 418–426. */
}


/* ═══════════════════════════════════════════════════════════════════
   TYPE ROLES IN USE — surfaces name a ROLE, never a face.
   ═══════════════════════════════════════════════════════════════════ */
.oa-identity { font-family: var(--oa-role-identity); }
.oa-support  { font-family: var(--oa-role-support);  }


/* ═══════════════════════════════════════════════════════════════════
   GATE 5 / X12 — THE OBJECT IS MONOLINGUAL.
   STATUS: DESIGNED, NOT OBSERVED.
   ═══════════════════════════════════════════════════════════════════
   [CARD X12] «Arabic type on the object or in any engraving» — kill on sight.
   [RD] «The Arabic pair never touches the object … not the bottle, the engraving, the
   base, the collar, the plaque, the box, the insert, or the bag.»

   v0.1 could not express this at all: one global stack meant Arabic on an engraving
   spec rendered in a house face and LOOKED CORRECT — invisible at authorship, catchable
   only at audit.

   Here both roles are redefined inside the object scope with the Arabic faces removed.
   Custom properties inherit, so every descendant gets the Arabic-free stack, and Arabic
   set on an object surface has no house face left to render in.

   ⚠️ THIS IS NOT YET «IMPOSSIBLE» AND MUST NOT BE CALLED THAT. The block depends on
   browser font-fallback behaviour. It is correct BY SPECIFICATION and unconfirmed BY
   OBSERVATION. A render pass on the second palace closes it. Until then the honest
   word is DESIGNED — the difference between «right by spec» and «right by observation»
   is the difference this house was hurt by.

   Wrap every object surface: bottle · engraving · base · collar · plaque · box ·
   insert · bag. Digital and service surfaces never carry this class. */
.oa-surface-object {
  --oa-role-identity: var(--oa-face-identity-latin), Georgia, serif;
  --oa-role-support:  var(--oa-face-support-latin),  Georgia, serif;
}


/* ═══════════════════════════════════════════════════════════════════
   LEGAL TEXT PAIRS — the only way to set text colour. [Naqsh's model, kept]
   Every ratio recomputed this cycle with contrast-wcag.ps1, the instrument the Audit
   Card names. The instrument was validated first against the six published ratios and
   returned them at zero deviation.

   ⚠️ [contrast measured on solid fill — thin-stroke behaviour pending render]
   MI'YAR, and it applies to EVERY ratio below when the identity face is set small:
   on screen there is no «formation failure» — a sub-pixel hairline simply renders at
   PARTIAL TRANSPARENCY, which pulls the EFFECTIVE contrast below the measured number.
   **Cormorant's hairline does not reach a whole pixel until 44px; at 16px it is
   0.363px.** So these figures describe SOLID FILLS, and they OVERSTATE a high-contrast
   face at small sizes.

   🔴 THE RENDER TEST HAS NOW RUN, AND IT IS FAR WORSE THAN THE CAUTION SUGGESTED.
   Cormorant on Obsidian — nominal **15.44:1** — measured on the rendered output:
       16px  →  **2.12:1**   (**8% of the nominal figure**)
       32px  →  4.43:1
       48px  →  7.64:1
   **At body size the published ratio overstates reality by more than an order of
   magnitude.** Haneen's `PASS [INAPPLICABLE]` is now confirmed by number, not argument.
   The tag below is not a hedge — **it is the only true written statement about this
   behaviour anywhere in the house.**

   ⚠️ AND THE CHECK IS DUE PER SURFACE, AT SHIPPING SIZE — NOT ONCE (Mi'yar):
   a renderer's antialiasing is not a browser's antialiasing. One passing measurement
   does not transfer to another surface, another size, or another engine.

   No number here is removed and no correction is derived — **the ratios are correct
   for what they were measured on, and incomplete for what we use them for.** That is
   the same defect as the point-size floors: a value right in one unit, used where the
   unit is not the one that governs.
   Mi'yar ruled no floor for it: the geometry is measured, **the acceptance is a render
   test**, and he does not rule on what he has not seen rendered. Folded into the render
   spec as its fifth check, alongside X12 — the one check whose instrument is an eye.
   ═══════════════════════════════════════════════════════════════════ */

/* Grounds — [W5] permits only these three on web pages. Crystal Silence is absent:
   promotion of Crystal to a ground = reject [PC2] — it sits 1.3 ΔE from Clive
   Christian's observed canvas and that surface would read as theirs. */
.oa-ground-dark  { background: var(--oa-obsidian); color: var(--oa-silence); }
.oa-ground-linen { background: var(--oa-linen);    color: var(--oa-obsidian); }
.oa-ground-ash   { background: var(--oa-ash);      color: var(--oa-obsidian); }

/* NON-WEB ground. [CARD C5] rules Gold/Sandalwood legal at 4.78, but [W5] permits only
   three page grounds — so the pair is expressible for print/packaging and barred from
   web by name. v0.1 had neither, making a ruled-legal combination unbuildable. */
.oa-ground-sandalwood-nonweb { background: var(--oa-sandalwood); color: var(--oa-silence); }

.oa-text-silence-on-dark { color: var(--oa-silence); }     /* PASS (15.44 / 4.5 — ×3.43) */
.oa-text-gold-on-dark    { color: var(--oa-gold); }        /* PASS ( 6.35 / 4.5 — ×1.41) */
.oa-text-muted-on-dark   { color: var(--oa-text-muted); }  /* PASS ( 5.95 / 4.5 — ×1.32) */

/* PASS (3.11 / 3.0 — ×1.04) at LARGE only. The size floor is welded to the colour so
   the pair cannot be set small. CAVEAT, recorded not hidden: max() raises font-size
   against the parent, so this can introduce a size the surface did not choose and push
   it past T5's five; and it does not express the ≥18.5px BOLD branch, which stays a
   manual check. An enforcement with a known edge beats a silent one.
   Note the margin — ×1.04 is thin, and thin margins are how this house gets hurt. */
.oa-text-faint-large { color: var(--oa-text-faint); font-size: max(24px, 1em); }

.oa-text-obsidian-on-light   { color: var(--oa-obsidian); }   /* linen PASS (12.23/4.5 — ×2.72) · ash PASS (16.40/4.5 — ×3.64) */
.oa-text-sandalwood-on-light { color: var(--oa-sandalwood); } /* linen PASS ( 9.20/4.5 — ×2.04) · ash PASS (12.34/4.5 — ×2.74) */
.oa-text-gold-on-sandalwood  { color: var(--oa-gold); }       /* PASS (4.78 / 4.5 — ×1.06) — non-web only */

/* ── THE ABSENCES ARE THE ENFORCEMENT — and these ARE structural, not browser-dependent.
   A class that does not exist cannot be applied, whatever a browser does.
     no .oa-ground-gold      → X2   no .oa-ground-crystal → PC2
     no .oa-ground-white     → X3   no gold-on-light text → X11 (1.93 linen / 2.58 ash)
     no negative tracking token → X7
   On light grounds gold is a line or an ornament, and only that: */
.oa-rule-gold { border: 0; border-top: 1px solid var(--oa-gold); }

/* ── WHAT THIS FILE CANNOT ENFORCE — stated here, not buried ──────
   C1 dark share · C2/C3 gold area · S1 ink ≤50% · P2 white regions · P3 negative space
   · C7 ΔE00 · P1 single light · D1 feed rhythm.
   Every one is an AREA or a PHYSICAL measurement over rendered output. A fully
   token-compliant surface can still be 80% gold under three light sources. These
   belong to a measuring instrument, not a token layer.
   Full split: 01_Audit\NSQ-A02__Enforcement_Boundary_Log.md
   ────────────────────────────────────────────────────────────────── */

/* Produced by: Nasaq */
