/invariants at the arc boundary: 1, 3 and 5 held and were checked rather than assumed; 2, 4, 6, 7, 8 and 9 are not yet applicable, with the pre-freeze core figure recorded as 619. Invariant 2 turned up a load-bearing default nobody had written down: goldmark omits raw HTML unless WithUnsafe is set, verified, and that is the only reason authored Markdown cannot inject script today. The obvious move when a shortcode needs to emit HTML removes it, so it is now a latent item triggered by queue entry 12 rather than a surprise. The other two latent items are triaged as the arc-close rule requires: the counter-correctness gap is accepted with a reason, the untrusted-boundary gate is scheduled to Arc 3.
khosra
A flat-file personal publishing engine in Go. Point the binary at a directory of Markdown and it becomes an owned, networked home for fiction, webcomics, art, and essays, in English and Bengali. The site's content lives in its own repository, not this one (ADR-0011).
Build and run
Needs Go 1.26+ and git; nothing else.
make build # or: go build -o khosra ./cmd/khosra
make run SITE=/path/to/site # or: ./khosra -site /path/to/site
make test
make verify # everything the project enforces — green before every commit
make help lists targets. make is a convenience wrapper; go build, go test and
./scripts/verify.sh work on their own and are what the gate uses.
A site root is a directory holding content/, and optionally static/ and templates/. It lives in its
own repository, not this one — the binary is pointed at it.
If you are a human: start at HARNESS.md — what the scaffolding is, how to use it, and what to decide.
If you are an agent: start at CLAUDE.md — the constitution and the read order. It is loaded for you automatically; this file is not a prerequisite and nothing here is a rule.