EI-8.9 — Binary Derivative Delivery Path & First Portfolio Image
Status: BLOCKED — verified derivative prepared; repository binary handoff still required Date: 2026-08-09
Objective
Establish a reliable, integrity-checkable path for approved archival binaries and browser derivatives to enter the paco.org repository without treating binary data as UTF-8 text, then apply it to the first EI-8.7-qualified finished portfolio output: dualidad.PDF.
Source and derivative
- Archival authority: Google Drive
dualidad.PDF - Drive file ID:
1MeU5gjFZjiDqvMa4qT5G1BTilAeJvEYe - Archival object size: 210,114 bytes
- Classification: VERIFIED MASTER/SOURCE + FINISHED PORTFOLIO OUTPUT
- Browser derivative prepared locally:
dualidad-portfolio.jpg - Local derivative size: 220,750 bytes
- Local derivative SHA-256:
f9e363484030982a31c60445e8a095dca185c574821459e12a3f7cbd61a1b396 - Intended production path:
images/portfolio/journalism-media/dualidad-portfolio.jpg - Transform: neutral page rasterization only; no restoration, retouching, editorial cropping, replacement typography, or compositing
The Drive PDF remains the preservation authority. The JPEG is a DERIVATIVE used only for browser presentation.
Attempted automated handoff
A temporary GitHub Actions workflow attempted to retrieve the Drive archival source and render the derivative inside GitHub. The workflow failed at source download because the Drive object is not anonymously downloadable from GitHub Actions. The workflow was removed immediately after the test.
The connected GitHub API does expose native base64 blob creation, but its connector contract accepts the binary only as an inline base64 string; it does not accept the local mounted file path as a file parameter. A manual upload of the already verified JPEG is therefore the safest remaining handoff with the tools currently exposed.
Required handoff
Upload the prepared dualidad-portfolio.jpg unchanged to:
images/portfolio/journalism-media/dualidad-portfolio.jpg
After upload, verify that the repository copy matches SHA-256:
f9e363484030982a31c60445e8a095dca185c574821459e12a3f7cbd61a1b396
Only after that verification should the public portfolio reference the derivative and EI-8.9 close.
Governance
- Google Drive remains master storage.
- Production repository receives only the browser derivative required by the page.
- The derivative is labeled as such in portfolio context.
- Generic
archive_E*.pdffiles remain unresolved and unpublished. - Ben/Sophie DELETE/privacy material remains ineligible.
idtprof/portal/ firg.xyz remains untouched.