flowchart LR
A[Authorized local resource] --> B{Read-only probe}
B -->|FPD| C[Header and container evidence]
B -->|EGPACK| D[Field-key parser]
B -->|RIO / CRsa| E[Chunk and checksum verification]
D --> F[Stable ID and language slot]
E --> G[Block and payload offsets]
F --> H[Translation provenance and QA]
G --> H
H --> I{Exact expected value matches?}
I -->|No| J[Fail closed with audit]
I -->|Yes| K[Write to a new output]
K --> L[Reparse or decrypt round trip]
L --> M[SHA-256-locked byte patch]
| Layer | Address | Failure boundary | Verification |
|---|---|---|---|
| FPD | File magic and fixed header offsets | Unknown or short header | Header fields only |
| EGPACK | Relative path, text ID, language slot | Stale text, malformed record, unknown slot | Reparse rebuilt file |
| RIO / CRsa | Filename, block offset, payload offset, capacity | Invalid sizes, checksum, offset, encoding, or capacity | Decrypt re-encrypted block |
| Translation QA | Stable ID, source text, target text | Empty, duplicate, newline, or control mismatch | Structured audit report |
| Distribution | Base file size and SHA-256 | Wrong input build or overlapping ranges | Output SHA-256 |
- Unknown binary formats begin in read-only mode.
- Format markers are treated as clues, not proof.
- Expected source values make stale manifests fail safely.
- Translation review and binary validation remain separate stages.
- The public repository demonstrates behavior with synthetic fixtures only.