Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -106,3 +106,7 @@ This repository contains SourceOS overlays only:
## Rule

Do not bury SourceOS product behavior inside the upstream mirror. Keep the mirror clean. Keep SourceOS changes explicit here.

## bearfoot

A bear is plantigrade — its hind track looks like a barefoot human print, which is why so many peoples call it kin. Anti-fingerprinting works the same way: it does not hide your track, it makes **every track the same track**. So the **bearfoot property** is that every profile claiming to flatten its print must flatten it *identically* — a disagreement between profiles is itself a distinguishing bit. Checked by `scripts/bearbrowser-verify-bearfoot.py`; the story is in [docs/bearfoot.md](docs/bearfoot.md).
124 changes: 124 additions & 0 deletions docs/bearfoot.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,124 @@
# bearfoot

*An easter egg that had to earn its keep, so it became a check.*
Run it: `python3 scripts/bearbrowser-verify-bearfoot.py`

## The track

A bear is **plantigrade** — it walks on the whole sole, heel through toe, the way we do. Nearly
every other four-legged animal walks on its toes. The consequence is that a bear's hind print is
startlingly like a **barefoot human print**: a broad sole, five toes, a heel.

That single anatomical fact is why, across the whole northern hemisphere and quite independently,
peoples who share ground with bears name the bear **kin** — *the one who walks like a man*. Skinned,
a bear looks disquietingly human, and the tracks it leaves say the same thing. This is not one
people's story; it is what anyone reading the ground would conclude.

## The property

> **A print that distinguishes you is a print that betrays you.**

Anti-fingerprinting does not hide your track. It makes **every track the same track**, so that no
single print identifies anyone. You are not concealed — you are *indistinguishable*, which is the
stronger thing. You walk as one of many.

From which a real invariant follows, and the reason this is a script and not a comment:

> **THE BEARFOOT PROPERTY** — every BearBrowser profile that flattens its print must flatten it
> **the same way**. If `human-secure` and `agent-runtime` disagree on a print-surface pref, that
> disagreement is *itself* a distinguishing bit: an observer still cannot tell you from other
> users, but *can* tell which BearBrowser you run. **The herd only protects you if the herd is
> uniform.**

`scripts/bearbrowser-verify-bearfoot.py` refuses both failure modes — a profile that omits a
print-surface pref, and two profiles that set one differently. Silence is not agreement.

## Barefoot

The pun is load-bearing. **At the threshold you uncover your feet.**

*"Put off thy shoes from off thy feet, for the place whereon thou standest is holy ground"*
(Ex 3:5) — said to Moses at the bush, **before he is sent**, and long before Nebo where he will
look across and not enter.

And the Talmud gives the other half: *"the feet of a person are responsible for him; to the place
where he is in demand, there they lead him"* (*Sukkah* 53a). The Aramaic word is **`arevin`** —
**guarantors**. Your feet stand surety for you; they will deliver you. Solomon sent his scribes
away from death and the sending *was* the delivery.

But a guarantor must be **independent of the subject**, and your feet are not — they are yours,
their authority derives wholly from you. So:

> **Your feet are your guarantors, and that is exactly why they cannot be your witness.**
> They carry you to the threshold. They cannot vouch for you at it.

Which is the same law this codebase enforces elsewhere: a browser's own claim about itself is not
evidence about it. The print has to be checked by something that isn't the browser.

## On the bear medicine, said carefully

Bear is **sacred medicine** in many indigenous traditions of this continent — a healer's medicine,
associated with strength, introspection, and the dreaming that goes with the winter den. Those are
living traditions, not mythology, and much of what surrounds them is **ceremonial and closed**.
Nothing here reproduces or claims any of it.

For the Lenape specifically, on whose homelands much of this estate's founding geography sits: the
**Mesingw** (Misingw, *Living Solid Face*, the Mask Spirit) is the guardian of the game animals —
deer, bear and the rest — a sacred medicine being, and a focus of living Big House ceremony. He is a
**guardian**, not a returning god.

What is described below is drawn only from **published ethnography in the public domain**, quoted
rather than paraphrased. It is a matter of record, not of access, and nothing here claims
ceremonial knowledge.

The being is impersonated in a **bear's own skin**. M. R. Harrington, *Religion and Ceremonies of the
Lenape* (1921), p. 34:

> "To the back of the mask is fastened the skin of the bear's head, which effectively conceals the
> head and neck of the impersonator, while the bear's ears, projecting, add to the uncanny effect."

And Harrington at p. 41, quoting David Brainerd's account of **1745** — the earliest description we
have of it:

> "a coat of bear skins, dressed with the hair on, and hanging down to his toes; a pair of bear skin
> stockings; and a great wooden face painted"

Red on the right of the face, black on the left; a stick, a turtle-shell rattle, a bearskin bag.

**And this is the hinge of the whole idea.** The track makes the bear look like a man. The garb
makes a man look like the bear. It is *the same resemblance read in both directions* — and where the
track is something you merely observe, the skin is something you **put on**. The kinship is not
noticed; it is **worn**.

**Three honest gaps**, kept as gaps rather than filled with something plausible.

1. **A Lenape "returning god" tied to the bear.** Not verified, and deliberately **not supplied.** The nearest attested things
are Mesingw (a guardian, not a returner) and the prophet **Neolin** (1761), whose Master-of-Life
vision drove a renewal movement — *restoration of ways*, not the return of a deity. Inventing or
mis-naming another people's sacred figure would be a real harm, so the blank is left as a blank.

2. **The bearskin garb being shed or removed during the ceremony.** Searched for and **not found**
in Harrington, the primary source. He has the impersonator appearing about the camp and
following the hunters out; he does not describe the costume coming off. Recorded here as
unverified rather than repeated.

3. **A first-bear-hunt coming-of-age legend** — a young man skinning his first bear and recognising
how like a man it looks. **Not present in Harrington**, and not otherwise attested to the Lenape
in what could be checked. The *motif* is entirely real: a skinned bear's resemblance to a human
body is remarked on by hunting peoples right across the northern hemisphere, and it is one of the
roots of the kinship this page is built on. But "widespread motif" and "this people's legend" are
different claims, and only the first one is made here.

If sources turn up for (2) or (3), they can be added with proper attribution.

---

*Sources are provenance for engineering doctrine, not claims on anyone's tradition. The natural
history (plantigrade gait, human-like tracks, the resulting kinship motif) is public and general.
Where this document and the checker disagree, the checker ships.*

*Further reading, as cited rather than paraphrased:*
- M. R. Harrington, [*Religion and Ceremonies of the Lenape*](https://www.gutenberg.org/ebooks/72988) (1921, public domain) — the primary ethnography, and the source of both quotations above
- [Mesingw, the Lenape Mask Spirit](http://www.native-languages.org/mesingw.htm) · [Delaware Tribe of Indians — Culture FAQs](https://delawaretribe.org/cultural-education/culture-and-language/culture-faqs-3/)
- [Neolin, the Delaware Prophet](https://en.wikipedia.org/wiki/Neolin)
- [Sukkah 53a](https://www.sefaria.org/Sukkah.53a)
122 changes: 122 additions & 0 deletions scripts/bearbrowser-verify-bearfoot.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,122 @@
#!/usr/bin/env python3
"""bearfoot — the print must be the same print.

A bear is *plantigrade*: it walks on the whole sole, heel to toe, as we do. Its hind track is
startlingly like a barefoot human print, and that resemblance is why peoples across the northern
hemisphere name the bear kin — the one who walks like a man. You cannot read a bear's track and
tell it from a person's, and you cannot read one bear's track and tell it from another's.

That is exactly what anti-fingerprinting is for. It does not hide the track. **It makes every track
the same track**, so no single print identifies anyone. A print that distinguishes you is a print
that betrays you.

Which yields a real invariant, and the reason this file is a checker rather than a comment:

THE BEARFOOT PROPERTY — every BearBrowser profile that flattens its print must flatten it
THE SAME WAY. If `human-secure` and `agent-runtime` disagree on a print-surface pref, that
disagreement is itself a distinguishing bit: an observer cannot tell you apart from other
users, but CAN tell which BearBrowser profile you run. The herd only protects you if the
herd is uniform.

Fail-closed: a profile that claims the property and omits a pref is refused, and so is a profile
that sets one to a different value than its siblings. Silence is not agreement.

stdlib only. Usage: python3 scripts/bearbrowser-verify-bearfoot.py [--json]
"""
from __future__ import annotations

import argparse
import json
import re
import sys
from pathlib import Path

ROOT = Path(__file__).resolve().parents[1]

# Profiles that assert the bearfoot property. A profile listed here MUST carry every pref below,
# and must agree with its siblings on the value.
BEARFOOT_PROFILES = [
"settings/profiles/human-secure/user.js",
"settings/profiles/agent-runtime/user.js",
]

# The print surface. Each of these is a bit an observer could otherwise read off one browser and
# not another.
PRINT_SURFACE = [
"privacy.resistFingerprinting",
"privacy.resistFingerprinting.letterboxing",
"privacy.trackingprotection.fingerprinting.enabled",
]

PREF_RE = re.compile(r'user_pref\(\s*"([^"]+)"\s*,\s*([^)]+?)\s*\)\s*;')


def read_prefs(path: Path) -> dict[str, str]:
"""Parse user_pref() calls, ignoring commented-out lines."""
prefs: dict[str, str] = {}
for line in path.read_text().splitlines():
stripped = line.strip()
if stripped.startswith("//"):
continue
m = PREF_RE.search(line)
if m:
prefs[m.group(1)] = m.group(2).strip()
return prefs


def check() -> list[str]:
"""Returns a list of violations; empty means the bearfoot property holds."""
violations: list[str] = []
seen: dict[str, dict[str, str]] = {}

for rel in BEARFOOT_PROFILES:
path = ROOT / rel
if not path.exists():
violations.append(f"{rel}: claims the bearfoot property but the file is missing")
continue
prefs = read_prefs(path)
seen[rel] = {}
for key in PRINT_SURFACE:
if key not in prefs:
violations.append(
f"{rel}: does not set {key} — a profile that claims the bearfoot property and "
"omits a print-surface pref leaves a track its siblings do not"
)
continue
seen[rel][key] = prefs[key]

# the herd only protects you if the herd is uniform
for key in PRINT_SURFACE:
values = {rel: p[key] for rel, p in seen.items() if key in p}
if len(set(values.values())) > 1:
detail = ", ".join(f"{Path(r).parent.name}={v}" for r, v in sorted(values.items()))
violations.append(
f"{key}: profiles disagree ({detail}) — the disagreement is itself a distinguishing "
"bit, so an observer learns which BearBrowser you run"
)
return violations


def main(argv: list[str] | None = None) -> int:
ap = argparse.ArgumentParser(prog="bearbrowser-verify-bearfoot")
ap.add_argument("--json", action="store_true")
a = ap.parse_args(argv)

violations = check()
if a.json:
print(json.dumps({"ok": not violations, "violations": violations,
"profiles": BEARFOOT_PROFILES, "print_surface": PRINT_SURFACE}, indent=2))
else:
for v in violations:
print(f" ✗ {v}", file=sys.stderr)
if violations:
print(f"\nbearfoot: REFUSED — {len(violations)} distinguishing difference(s). "
"Every bear must leave the same track.", file=sys.stderr)
else:
print(f"bearfoot: {len(BEARFOOT_PROFILES)} profiles, {len(PRINT_SURFACE)} print-surface "
"prefs, no distinguishing difference — the herd is uniform.", file=sys.stderr)
return 1 if violations else 0


if __name__ == "__main__":
raise SystemExit(main())
Loading