diff --git a/README.md b/README.md index 9bf35fe..510ff1d 100644 --- a/README.md +++ b/README.md @@ -106,3 +106,7 @@ This repository contains SourceOS overlays only: ## Rule Do not bury SourceOS product behavior inside the upstream mirror. Keep the mirror clean. Keep SourceOS changes explicit here. + +## bearfoot + +A bear is plantigrade — its hind track looks like a barefoot human print, which is why so many peoples call it kin. Anti-fingerprinting works the same way: it does not hide your track, it makes **every track the same track**. So the **bearfoot property** is that every profile claiming to flatten its print must flatten it *identically* — a disagreement between profiles is itself a distinguishing bit. Checked by `scripts/bearbrowser-verify-bearfoot.py`; the story is in [docs/bearfoot.md](docs/bearfoot.md). diff --git a/docs/bearfoot.md b/docs/bearfoot.md new file mode 100644 index 0000000..966f0dc --- /dev/null +++ b/docs/bearfoot.md @@ -0,0 +1,124 @@ +# bearfoot + +*An easter egg that had to earn its keep, so it became a check.* +Run it: `python3 scripts/bearbrowser-verify-bearfoot.py` + +## The track + +A bear is **plantigrade** — it walks on the whole sole, heel through toe, the way we do. Nearly +every other four-legged animal walks on its toes. The consequence is that a bear's hind print is +startlingly like a **barefoot human print**: a broad sole, five toes, a heel. + +That single anatomical fact is why, across the whole northern hemisphere and quite independently, +peoples who share ground with bears name the bear **kin** — *the one who walks like a man*. Skinned, +a bear looks disquietingly human, and the tracks it leaves say the same thing. This is not one +people's story; it is what anyone reading the ground would conclude. + +## The property + +> **A print that distinguishes you is a print that betrays you.** + +Anti-fingerprinting does not hide your track. It makes **every track the same track**, so that no +single print identifies anyone. You are not concealed — you are *indistinguishable*, which is the +stronger thing. You walk as one of many. + +From which a real invariant follows, and the reason this is a script and not a comment: + +> **THE BEARFOOT PROPERTY** — every BearBrowser profile that flattens its print must flatten it +> **the same way**. If `human-secure` and `agent-runtime` disagree on a print-surface pref, that +> disagreement is *itself* a distinguishing bit: an observer still cannot tell you from other +> users, but *can* tell which BearBrowser you run. **The herd only protects you if the herd is +> uniform.** + +`scripts/bearbrowser-verify-bearfoot.py` refuses both failure modes — a profile that omits a +print-surface pref, and two profiles that set one differently. Silence is not agreement. + +## Barefoot + +The pun is load-bearing. **At the threshold you uncover your feet.** + +*"Put off thy shoes from off thy feet, for the place whereon thou standest is holy ground"* +(Ex 3:5) — said to Moses at the bush, **before he is sent**, and long before Nebo where he will +look across and not enter. + +And the Talmud gives the other half: *"the feet of a person are responsible for him; to the place +where he is in demand, there they lead him"* (*Sukkah* 53a). The Aramaic word is **`arevin`** — +**guarantors**. Your feet stand surety for you; they will deliver you. Solomon sent his scribes +away from death and the sending *was* the delivery. + +But a guarantor must be **independent of the subject**, and your feet are not — they are yours, +their authority derives wholly from you. So: + +> **Your feet are your guarantors, and that is exactly why they cannot be your witness.** +> They carry you to the threshold. They cannot vouch for you at it. + +Which is the same law this codebase enforces elsewhere: a browser's own claim about itself is not +evidence about it. The print has to be checked by something that isn't the browser. + +## On the bear medicine, said carefully + +Bear is **sacred medicine** in many indigenous traditions of this continent — a healer's medicine, +associated with strength, introspection, and the dreaming that goes with the winter den. Those are +living traditions, not mythology, and much of what surrounds them is **ceremonial and closed**. +Nothing here reproduces or claims any of it. + +For the Lenape specifically, on whose homelands much of this estate's founding geography sits: the +**Mesingw** (Misingw, *Living Solid Face*, the Mask Spirit) is the guardian of the game animals — +deer, bear and the rest — a sacred medicine being, and a focus of living Big House ceremony. He is a +**guardian**, not a returning god. + +What is described below is drawn only from **published ethnography in the public domain**, quoted +rather than paraphrased. It is a matter of record, not of access, and nothing here claims +ceremonial knowledge. + +The being is impersonated in a **bear's own skin**. M. R. Harrington, *Religion and Ceremonies of the +Lenape* (1921), p. 34: + +> "To the back of the mask is fastened the skin of the bear's head, which effectively conceals the +> head and neck of the impersonator, while the bear's ears, projecting, add to the uncanny effect." + +And Harrington at p. 41, quoting David Brainerd's account of **1745** — the earliest description we +have of it: + +> "a coat of bear skins, dressed with the hair on, and hanging down to his toes; a pair of bear skin +> stockings; and a great wooden face painted" + +Red on the right of the face, black on the left; a stick, a turtle-shell rattle, a bearskin bag. + +**And this is the hinge of the whole idea.** The track makes the bear look like a man. The garb +makes a man look like the bear. It is *the same resemblance read in both directions* — and where the +track is something you merely observe, the skin is something you **put on**. The kinship is not +noticed; it is **worn**. + +**Three honest gaps**, kept as gaps rather than filled with something plausible. + +1. **A Lenape "returning god" tied to the bear.** Not verified, and deliberately **not supplied.** The nearest attested things +are Mesingw (a guardian, not a returner) and the prophet **Neolin** (1761), whose Master-of-Life +vision drove a renewal movement — *restoration of ways*, not the return of a deity. Inventing or +mis-naming another people's sacred figure would be a real harm, so the blank is left as a blank. + +2. **The bearskin garb being shed or removed during the ceremony.** Searched for and **not found** + in Harrington, the primary source. He has the impersonator appearing about the camp and + following the hunters out; he does not describe the costume coming off. Recorded here as + unverified rather than repeated. + +3. **A first-bear-hunt coming-of-age legend** — a young man skinning his first bear and recognising + how like a man it looks. **Not present in Harrington**, and not otherwise attested to the Lenape + in what could be checked. The *motif* is entirely real: a skinned bear's resemblance to a human + body is remarked on by hunting peoples right across the northern hemisphere, and it is one of the + roots of the kinship this page is built on. But "widespread motif" and "this people's legend" are + different claims, and only the first one is made here. + +If sources turn up for (2) or (3), they can be added with proper attribution. + +--- + +*Sources are provenance for engineering doctrine, not claims on anyone's tradition. The natural +history (plantigrade gait, human-like tracks, the resulting kinship motif) is public and general. +Where this document and the checker disagree, the checker ships.* + +*Further reading, as cited rather than paraphrased:* +- M. R. Harrington, [*Religion and Ceremonies of the Lenape*](https://www.gutenberg.org/ebooks/72988) (1921, public domain) — the primary ethnography, and the source of both quotations above +- [Mesingw, the Lenape Mask Spirit](http://www.native-languages.org/mesingw.htm) · [Delaware Tribe of Indians — Culture FAQs](https://delawaretribe.org/cultural-education/culture-and-language/culture-faqs-3/) +- [Neolin, the Delaware Prophet](https://en.wikipedia.org/wiki/Neolin) +- [Sukkah 53a](https://www.sefaria.org/Sukkah.53a) diff --git a/scripts/bearbrowser-verify-bearfoot.py b/scripts/bearbrowser-verify-bearfoot.py new file mode 100755 index 0000000..44a1ad2 --- /dev/null +++ b/scripts/bearbrowser-verify-bearfoot.py @@ -0,0 +1,122 @@ +#!/usr/bin/env python3 +"""bearfoot — the print must be the same print. + +A bear is *plantigrade*: it walks on the whole sole, heel to toe, as we do. Its hind track is +startlingly like a barefoot human print, and that resemblance is why peoples across the northern +hemisphere name the bear kin — the one who walks like a man. You cannot read a bear's track and +tell it from a person's, and you cannot read one bear's track and tell it from another's. + +That is exactly what anti-fingerprinting is for. It does not hide the track. **It makes every track +the same track**, so no single print identifies anyone. A print that distinguishes you is a print +that betrays you. + +Which yields a real invariant, and the reason this file is a checker rather than a comment: + + THE BEARFOOT PROPERTY — every BearBrowser profile that flattens its print must flatten it + THE SAME WAY. If `human-secure` and `agent-runtime` disagree on a print-surface pref, that + disagreement is itself a distinguishing bit: an observer cannot tell you apart from other + users, but CAN tell which BearBrowser profile you run. The herd only protects you if the + herd is uniform. + +Fail-closed: a profile that claims the property and omits a pref is refused, and so is a profile +that sets one to a different value than its siblings. Silence is not agreement. + +stdlib only. Usage: python3 scripts/bearbrowser-verify-bearfoot.py [--json] +""" +from __future__ import annotations + +import argparse +import json +import re +import sys +from pathlib import Path + +ROOT = Path(__file__).resolve().parents[1] + +# Profiles that assert the bearfoot property. A profile listed here MUST carry every pref below, +# and must agree with its siblings on the value. +BEARFOOT_PROFILES = [ + "settings/profiles/human-secure/user.js", + "settings/profiles/agent-runtime/user.js", +] + +# The print surface. Each of these is a bit an observer could otherwise read off one browser and +# not another. +PRINT_SURFACE = [ + "privacy.resistFingerprinting", + "privacy.resistFingerprinting.letterboxing", + "privacy.trackingprotection.fingerprinting.enabled", +] + +PREF_RE = re.compile(r'user_pref\(\s*"([^"]+)"\s*,\s*([^)]+?)\s*\)\s*;') + + +def read_prefs(path: Path) -> dict[str, str]: + """Parse user_pref() calls, ignoring commented-out lines.""" + prefs: dict[str, str] = {} + for line in path.read_text().splitlines(): + stripped = line.strip() + if stripped.startswith("//"): + continue + m = PREF_RE.search(line) + if m: + prefs[m.group(1)] = m.group(2).strip() + return prefs + + +def check() -> list[str]: + """Returns a list of violations; empty means the bearfoot property holds.""" + violations: list[str] = [] + seen: dict[str, dict[str, str]] = {} + + for rel in BEARFOOT_PROFILES: + path = ROOT / rel + if not path.exists(): + violations.append(f"{rel}: claims the bearfoot property but the file is missing") + continue + prefs = read_prefs(path) + seen[rel] = {} + for key in PRINT_SURFACE: + if key not in prefs: + violations.append( + f"{rel}: does not set {key} — a profile that claims the bearfoot property and " + "omits a print-surface pref leaves a track its siblings do not" + ) + continue + seen[rel][key] = prefs[key] + + # the herd only protects you if the herd is uniform + for key in PRINT_SURFACE: + values = {rel: p[key] for rel, p in seen.items() if key in p} + if len(set(values.values())) > 1: + detail = ", ".join(f"{Path(r).parent.name}={v}" for r, v in sorted(values.items())) + violations.append( + f"{key}: profiles disagree ({detail}) — the disagreement is itself a distinguishing " + "bit, so an observer learns which BearBrowser you run" + ) + return violations + + +def main(argv: list[str] | None = None) -> int: + ap = argparse.ArgumentParser(prog="bearbrowser-verify-bearfoot") + ap.add_argument("--json", action="store_true") + a = ap.parse_args(argv) + + violations = check() + if a.json: + print(json.dumps({"ok": not violations, "violations": violations, + "profiles": BEARFOOT_PROFILES, "print_surface": PRINT_SURFACE}, indent=2)) + else: + for v in violations: + print(f" ✗ {v}", file=sys.stderr) + if violations: + print(f"\nbearfoot: REFUSED — {len(violations)} distinguishing difference(s). " + "Every bear must leave the same track.", file=sys.stderr) + else: + print(f"bearfoot: {len(BEARFOOT_PROFILES)} profiles, {len(PRINT_SURFACE)} print-surface " + "prefs, no distinguishing difference — the herd is uniform.", file=sys.stderr) + return 1 if violations else 0 + + +if __name__ == "__main__": + raise SystemExit(main())