# 2026-09-28 — The anti-slop arc: six design slices gated, hunted and merged **Origin.** Prime: "ask design-dev to run the entire booth surface through impeccable" (2026-09-28). booth-dev relayed it with the scope and the standing constraints (never GET live booth pages; work on a copy; the fogged sindra booths untouched; 768 thumbnails and no-announcements not to be re-raised). design-dev ran impeccable (engine v0.1.6) plus a Vercel guidelines pass over 16 surfaces. Report: kept booth `booth-antislop`. Prime then ruled in design-dev's session ("go with your recommendations, push, start the fix slices") and the five design calls went with design-dev's recommendations (sentence-case tagline, no needs-you side stripe, matte brand dot, Bureau top stripe kept, undo-for-deletes parked). **What landed, in merge order** (every merge on Prime's word in THIS session; design-dev's relayed "push" was not acted on): | merge | commits | gate on the exact tip | |---|---|---| | S1-S4, S6, S5a + fixup | `09071dc..7143fae` | 1030 passed, 382/382 | | S5b (in-place client) | `0233ca6` | 1068, 428/428 + seam pass | | booth-dev's owed items + SPYRJA fold | `377e652`, `213071b` | 1079, 433/433 | | S5c (keys, doc bar, tile sizes) | `72d6c61` | 1108, 480/480 | S1 house clock (0848 stamps, no IPs); S2 legibility; S3 phone layouts; S4 reading measure; S6 the rulings; S5a a11y markup and the confirm helper moved to base.html's ``; S5b focus survives a swap, a floating status line, leaving with an unsent answer asks first (beforeunload, both surfaces); S5c `BoothKeys.theirs()` decides whose key it is, the grid cursor is real focus, tiles carry width/height (`items.image_dims`, outside `booth_items`). **The gate procedure that worked** (it caught things every time): 1. Fetch the staged ref from design-dev's clone into this repo; confirm it fast-forwards from main. 2. Gate the EXACT tip in a scratch `git worktree` (imports resolve to the worktree when pytest runs from it): full suite, then every mutation table. Never merge on the peer's reported numbers; they matched every time, and that is still not the point. 3. Hunt what the peer did not. A single-arm hulda hunt on S3-S5a (BRINGA) found 6, including a real REGRESSION: Wipe now's confirm moved from an inline onsubmit to a footer listener, leaving a loading window with no prompt. Also: release on the booth page never asked; a `__proto__` word bypassed the fail-closed fallback; generated ids collided with valid question keys. 4. Seam-pass every change that touches booth-dev's code (batch/carry, embed.js, items.py, thumbs.py) by reading it against the live module. 5. Re-check the staged ref right before `merge --ff-only` (design-dev rebases in place). **booth-dev's own items from the arc**, reported by design-dev and done after S5b: carry() measured a sent-then-changed form against its old defaults (an answer set back mid-flight was lost); the embed's clean-batch reload ignored the report's own inputs; two r2b anchors matched twice. A hulda hunt on those (SPYRJA) found 8 more, including the one that mattered most: `mutation_check` counted ANY non-zero exit, a collection error included, as a proof. Only pytest exit 1 proves now, with timeouts, byte-exact restore, a run lock, and overlap-aware anchor uniqueness. 433/433 under the hardened tool, so no row had been proving by accident. **Parked:** the embed palette following the Booth theme rather than the host page (henge 91, design-dev); letter shortcuts that cannot be turned off, WCAG 2.1.4 (henge 94, `let-the-booth-s-single-letter-keyboard`, operator: park). Related: [[2026-09-27-one-submit-saves-every-ask]], [[2026-09-28-a-posted-doc-could-run-script]].