--- name: Sheaf description: A proof press for Markdown — read-only desktop viewer where every document arrives as a bound printer's signature; only a proof gone cold is stamped. colors: # The rust ramp (Digital Rust hardware-error taxonomy; hue holds, lightness falls toward Event Horizon) ghost-pixel: "#f7eae8" phosphor-smoke: "#efd5d1" fatal-error: "#cf8175" amber-alert: "#bf5747" amber-alert-text: "#cb6353" digital-rust: "#af2e1a" kernel-panic: "#9d2917" data-rot: "#8c2414" daemon-blood: "#57170d" bad-sector: "#46120a" core-meltdown: "#340d07" null-pointer: "#230905" event-horizon: "#110402" # Accents stack-overglow: "#d4a759" memory-leek: "#8fa667" dead-thread: "#6fa5a0" # Dark world (canonical) surface-base: "#110402" surface-secondary: "#230905" surface-elevated: "#340d07" surface-highlight: "#46120a" text-primary: "#f7eae8" text-secondary: "#efd5d1" # Daylight print (derived world, @media prefers-color-scheme: light) daylight-base: "#f2e6d8" daylight-secondary: "#eeddc9" daylight-sheet: "#fdf6ec" daylight-ink: "#2c100b" typography: heading: fontFamily: '"Rajdhani", "Saira SemiCondensed", "Trebuchet MS", sans-serif' fontWeight: 700 lineHeight: 1.22 letterSpacing: "0.04em" body: fontFamily: 'ui-serif, "Iowan Old Style", "Source Serif 4", "Charter", Cambria, Georgia, serif' # Body size is the reader's system font size (CSS `medium`) × any zoom step; # every other size is a golden-ratio power of it, in em. fontSize: "system (medium)" fontWeight: 400 lineHeight: 1.72 label: fontFamily: '"Rajdhani", "Saira SemiCondensed", "Trebuchet MS", sans-serif' fontSize: "0.618em" fontWeight: 700 letterSpacing: "0.2em" mono: fontFamily: '"IBM Plex Mono", "Space Mono", ui-monospace, Menlo, Consolas, monospace' fontSize: "0.786em" lineHeight: 1.62 rounded: sm: "2px" md: "4px" lg: "6px" spacing: xs: "0.25rem" sm: "0.5rem" md: "1rem" lg: "1.5rem" xl: "2.5rem" 2xl: "4rem" components: button-primary: backgroundColor: "{colors.digital-rust}" textColor: "{colors.ghost-pixel}" typography: label rounded: "{rounded.md}" padding: "8px 24px" button-primary-hover: backgroundColor: "#b74230" textColor: "{colors.ghost-pixel}" rounded: "{rounded.md}" padding: "8px 24px" button-ghost: backgroundColor: "transparent" textColor: "{colors.text-secondary}" typography: label rounded: "{rounded.md}" padding: "8px 24px" collate-stamp-gone: backgroundColor: "transparent" textColor: "{colors.amber-alert-text}" typography: label rounded: "{rounded.md}" padding: "6px 11px" signature-sheet: backgroundColor: "{colors.surface-elevated}" textColor: "{colors.text-secondary}" typography: body rounded: "{rounded.md}" padding: "44px 60px" width: "min(920px, 100%)" error-readout: backgroundColor: "{colors.surface-elevated}" textColor: "{colors.amber-alert-text}" rounded: "{rounded.md}" padding: "8px 16px" code-fence: backgroundColor: "#110402" textColor: "{colors.text-secondary}" typography: mono rounded: "{rounded.md}" padding: "16px" syntax-highlighting: note: "Token classes emitted by the Go backend (Chroma) on fenced code blocks; coloured per the Digital Rust Syntax Highlighting Specification. Daylight world re-inks each role toward the ink end of its ramp." keyword: "{colors.fatal-error}" constant: "#d3ae6e" type: "{colors.dead-thread}" attribute: "#a07e43" builtin: "#a07e43" function: "{colors.stack-overglow}" string: "{colors.memory-leek}" number: "#d78556" operator: "#d7968c" comment: "#ac6d4a" error: "{colors.amber-alert-text}" --- # Design System: Sheaf ## Overview **Creative North Star: "The Bound Proof"** Every document Sheaf opens arrives as a bound printer's signature; reading it is trusting a proof. The app is a proof press: a top **bench rail** (56px) names the file in tracked small caps on a rust rule, the body of the window is a near-black bench, and the document itself is printed on a single **signature sheet** — an elevated plate of warmer stock deckled at both edges, floating on a hard cast baseline. Nothing further adorns the proof while it lives; the moment the watched file vanishes from disk, a bordered **GONE stamp** cools the sheet's foot in rust. The world is **Digital Rust** — the [Digital Rust](https://digitalrust.katsuricata.com/) hardware-error design system Sheaf vendors. Color means machine states: heat, faults, live current, dead threads. Its primitive names (Ghost Pixel, Kernel Panic of the rust ramp; Dead Thread, Stack Overglow of the accents) are that taxonomy and are registered verbatim — treat the whole palette as hardware-error naming, not print-shop poetry. Chrome is machined, pressable plates: 2px walls, an inner bevel, and a hard offset cast that physically travels when pressed. The document, though, belongs to the reader: prose sets in the reader's own system serif, and only headings, labels, and code speak in the machine's faces. Density is roomy on the sheet (system-size serif, 1.72 line height, 44em measure) and compact in the rail. Nothing decorates that doesn't carry state: the noise-and-scanline ground, the deckle edges, and the stamp all assert the same claim — this proof is physically present and currently trustworthy. **Key Characteristics:** - One accent with one job: Digital Rust marks interactivity and section turns; everything else is ink or paper. - Hard shadows only — offset casts, inner bevels, zero blur; depth is structural, always on. - Every pressable thing travels: hover lifts −2px, press depresses +2px, the cast collapses to zero. - The sheet is the only warm surface in the window; the bench stays near-black so the proof glows. - Dual-mode by doctrine ("Bound Proof" light world): the same signature printed in open daylight, never a recolor. - Confirmed anti-references: the category's blank flat-utility readers; blurred glass and diffuse soft shadows; edit-y chrome (sidebars, tabs, gutters, tool palettes). ## Colors The palette is a single rust ramp, three signal accents, and a derived daylight world — color always reports a machine state, never mere preference. ### Primary - **Digital Rust** (#af2e1a): the one live accent. Primary button field, horizontal rules (2px, 64% width), hover borders, checkbox accent, selection background. Used on ≤10% of any screen. - **Firewall Breach** (#b74230): accent hover, one step hotter. - **Fatal Error** (#cf8175): the dark world's heading color — the only heading color allowed. Also the link-hover and the deckle/rule family above it. ### Secondary - **Stack Overglow** (#d4a759): warm amber of measurement and attention. Code ink, focus rings, footnote refs. Never a structural color. - **Memory Leek** (#8fa667): was the LIVE stamp's green; vacant since the stamp became GONE-only. Held in reserve as a possible state color. - **Dead Thread** (#6fa5a0): informational teal — the 3px blockquote accent bar only. ### Tertiary - **Amber Alert** (#bf5747) / **Amber Alert Text** (#cb6353): fault voice. Error readout text and left bar, invalid borders, the GONE stamp. ### Neutral (the rust ramp as ink and bench) - **Event Horizon** (#110402): the bench — page ground, noise and scanline host. - **Null Pointer** (#230905): secondary surface — bench rail, quote panels, table heads. - **Core Meltdown** (#340d07): the signature sheet (`--sig-paper`) — the warmest, brightest surface the dark world allows. - **Bad Sector** (#46120a): rules, well walls, row hover, fold-marks. - **Dark Packet** (#691b0f) and below: 2px wall ink on controls, table walls, scrollbar thumbs at rest. - **Ghost Pixel** (#f7eae8) / **Phosphor Smoke** (#efd5d1): primary and secondary ink — headings-vs-body contrast comes from the reader/machine faces, but strong/em and headings-adjacent text step up to Ghost Pixel. - **Kernel Panic** (#9d2917) and **Data Rot** (#8c2414): deep inks reserved for the daylight world's heading and link-hover roles. ### Named Rules **The One Heading Colour Rule.** Every heading, everywhere, is the heading color (Fatal Error dark / Kernel Panic daylight) in the heading face. Body text never takes it; the accent never substitutes. One voice for structure, registered once. **The Ramp-Only Rule.** All neutrals come from the rust ramp (Ghost Pixel → Event Horizon). No grays, no pure black, no pure white — if a surface or ink isn't on the ramp, it doesn't ship. **The Daylight Print Rule.** Light mode is the same signature printed in open daylight: cream stock (#f2e6d8 bench, #fdf6ec sheet), deep rust inks (#2c100b). It is never a naive inversion and never plain white paper; headings re-ink to Kernel Panic because washed Fatal Error cannot hold on stock. Roles survive the crossing; ramps do not carry over untreated. ## Typography **Heading Face:** Rajdhani (with Saira SemiCondensed, Trebuchet MS fallback) — tracked-out, tabular-numeral small caps for everything structural. **Reader Face:** the user's own system serif first (ui-serif, Iowan Old Style, Source Serif 4, Charter, Cambria, Georgia) — the document belongs to the reader. **Machine Face:** IBM Plex Mono (Space Mono, ui-monospace fallbacks) — code, fences, footnote refs, numbered readouts. **Character:** a proof printed in three voices that never blend: the press speaks in Rajdhani caps, the author in the reader's own serif, the machine in mono. Letter-spacing is positive everywhere (0.03–0.22em); nothing is tight or sleek. ### Hierarchy The scale is strictly golden-ratio (1:1.618). The body size is the reader's system font size (CSS `medium`); every other step is a power of φ of it, in **em**, so the whole ladder scales with the reader's preference and any zoom step. Stepping up multiplies by √φ (the half-step) from the second rank on; stepping down divides by √φ. - **Display** (700, 2.058em = φ√φ, lh 1.22, +0.06em): h1-tier and the empty-sheet title; h1s also carry a 2px rule beneath. - **Headline** (700, 1.618em = φ): h2 with a 1px rule; h3 at 1.272em = √φ unruled. - **Title** (700, 1em, +0.03em): h4; h5/h6 at 0.786em uppercase; definition terms; table heads at 0.618em uppercase. - **Label** (700, 0.618em = 1/φ², +0.18–0.22em, uppercase, tabular-nums): brand, collating stamp, buttons, doc title. - **Body** (400, 1em = system size, lh 1.72): prose on the sheet, measured to 44em (~65–75ch); secondary ink (Phosphor Smoke), stepping to primary ink for strong/em. - **Mono** (400, 0.786em = 1/√φ, lh 1.62, tabular-nums): fences; inline code at 0.92em of that; footnote superscripts at 0.72em. ### Named Rules **The Three Voices Rule.** Heading face = structure and chrome; reader face = the author's prose; mono = code and measurement. A heading never sets in the reader face; prose never sets in the machine faces. **The Reader's Face Rule.** `--dr-font-reader` leads with `ui-serif`: the reader's OS preference outranks brand typography for prose. Sheaf owns the sheet, not the serif. **The Tracked Caps Rule.** Any label, title, or structural word sets uppercase with positive tracking (≥0.05em). Sentence-case chrome is off-world. ## Layout The window is a two-band rack: a fixed **bench rail** (56px, secondary surface, 2px bottom wall) over a scrolling bench. The rail holds brand left, the live file title centered between two 2px fold-mark rules, and the action cluster right (ghost presses for CONTENTS and RECENT ahead of the primary OPEN FILE). Below, the **signature** floats centered on the bench: a 3-column grid (deckle gutter | measure | deckle gutter; gutters `clamp(2px, 1.1vw, 14px)`) and 3-row stack (headroom `clamp(28px, 3.4vw, 44px)` | body | footroom `clamp(36px, 4.5vw, 58px)`), max width `min(920px, 100%)`, side padding `clamp(30px, 4.5vw, 60px)`. The reading measure is hard-capped at **44em** regardless of window width — a resized window widens the bench, never the line. Because the measure is em of the effective body size, it keeps the same character count when the reader zooms. Overlays are plates, never veils: the find bar and contents panel park top-right on the bench (fixed, just below the rail), and the recent-files menu drops from its press — all on the same 2px-wall/offset-cast vocabulary, all dismissed by Esc. Reading size follows the reader's system by default: the body size is the OS font size (`medium`), and the golden-ratio ladder hangs off it in em. The reader may additionally step it (Ctrl+= / Ctrl+- across 0.7×–2× stops, Ctrl+0 resets). The step rides `--font-size-effective` (the sheet's effective base px, = system × zoom), so the whole typographic system scales together and the system preference stays the 1× anchor. Spacing rides the rem scale (0.25 / 0.5 / 1 / 1.5 / 2.5 / 4 / 6rem); prose rhythm is em-based (paragraphs 1.1em, headings 1.9/0.6em). Minimum window 400×300: the sheet's clamps compress but the grid never reflows to anything but a narrower proof of the same form. ## Elevation & Depth Depth is **structural, always on, and entirely hard-edged**: offset casts with zero blur, inner bevels, and nothing diffuse anywhere in the system. Elevation is not a reward for interaction — it is the physical fact of the object, present at rest. Interaction moves the object through its cast: hover lifts the plate and lengthens the shadow, press drives it flush and the shadow collapses to zero. ### Shadow Vocabulary - **Rest cast** (`box-shadow: 2px 2px 0 0 {surface-highlight}`): every control at rest; 3px/4px steps for primary and images. - **Hover cast** (`4px 4px 0 0 {surface-highlight}` with `translate(-2px,-2px)`): the lifted plate. - **Press state** (`0 0 0 0` with `translate(2px,2px)`): full depression, cast gone — the press cycle's floor. - **Signature cast** (`0 10px 0 0 rgba(17,4,2,0.5)`): the sheet's single straight-down baseline on the bench; it never moves because the sheet is never pressed. - **Inner bevel** (`inset 0 1px 0 rgba(255,255,255,0.06…0.1)` / `inset 0 -1px 0 rgba(17,4,2,0.45…0.6)`): machined top-lit edge on every plate. ### Named Rules **The No-Blur Rule.** Zero blur radius on every shadow, forever. Depth comes from hard offsets and inner bevels; a soft or blurred shadow is a defect to remove on sight (confirmed anti-reference: glassmorphism). **The Cast-Never-Lies Rule.** Because the cast is structural, anything with a cast is pressable and travels when pressed. Never put an offset cast on an inert surface — the sheet's baseline is the one sanctioned exception, and it is flat (0 x-offset, no travel affordance). ## Shapes Corners are machined, not rounded: **2–6px radii** only (2px wells and small plates, 4px default, 6px rare). The signature's deckle edges are the single organic form — a 3px dashed torn edge with an elliptical corner (10px 26px). Walls are **2px** everywhere it matters (controls, tables, images, fences, rail foot) with a 4px option for emphasis; 1px is reserved for hairline rules and subtle wells. Recurring geometry is rectangular and panel-like; circles appear exactly once, as the stamp's 7px status dot. ### Named Rules **The 2px Wall Rule.** Interactive boundaries are 2px solid walls in ramp ink. If a control, plate, or table needs a border, it is 2px — never hairline, never 3px+ except a plate's cast or the sanctioned 3px left accent bar on callouts. ## Components All chrome is machined, pressable plates: 2px walls, an inner top bevel, a hard rest cast, and the full press cycle (hover −2px lift, press +2px depression, cast collapse). Type is always the heading face in tracked uppercase; numerals always tabular. ### Buttons - **Shape:** machined plate (4px radius), 2px wall, inner bevel, 3px rest cast on primary. - **Primary:** Digital Rust field and wall with Ghost Pixel ink (`padding: 8px 24px`, 0.875rem, +0.05em); hover heats to Firewall Breach, lifts, lengthens the cast, and adds a faint rust glow (the only glow allowed). - **Ghost/plain:** transparent field, secondary ink, 2px Dark Packet wall; hover steps to elevated fill and rust wall. - **Focus:** 2px Stack Overglow outline with 2px offset — amber, never the accent. - **Disabled:** highlight fill, muted ink, no cast, no travel. ### Chips / Status Stamp (signature) - **Collating stamp:** bordered plate (2px wall, transparent field, 6px×11px padding, 0.75rem +0.18em caps, tabular-nums) with one 7px dot. A single state: **GONE** (Amber Alert) — it appears at the sheet's foot only when the watched file vanishes from disk, declaring the proof cold. Nothing is stamped while the proof lives: presence is the default; only absence earns a mark. It is the component ambassador of the whole system: state as stamp, integrity as metal. ### Cards / Containers - **Signature sheet:** the system's only large surface — elevated paper, 4px radius, deckled left/right edges, 10px baseline cast, clamped padding. Holds only the body measure; the head (cap, subline, rule) and the standing foot readout were distilled away, and the GONE stamp appears in the foot solely when the file goes missing. - **Empty sheet:** same stock and cast with a 2px wall; centered device glyph, caps title, serif sub, primary press, mono format line. ### Inputs / Fields - One exists, and it only filters: the **find bar** (Ctrl+F or `/`). A fixed plate below the bench rail's right end — secondary surface, 2px wall, inner bevel, hard rest cast. Its field is the sanctioned search plate: elevated fill, 2px wall, amber focus ring, machine bevel, mono input. A mono tabular counter (`3 / 17`, or `No hits` in Amber Alert Text) and Prev/Next/Done presses ride the same plate; Enter/Shift+Enter (or F3/Shift+F3) step hits, Esc retires the bar. Hits paint the sheet as Stack Overglow `` washes; the active hit is solid Stack Overglow on Event Horizon ink. ### Navigation & Rails - **Bench rail:** 56px secondary surface, 2px bottom wall; brand wordmark in caps (+0.22em) with the 22px glyph; the centered doc title rides a 2px underline flanked by fold-mark rules. Right end carries the action cluster: ghost CONTENTS and RECENT presses plus the primary OPEN FILE — every one a machined plate with the full press cycle. - **Contents panel (TOC):** the navigable index the Don'ts clause allowed to earn its place (T or F6). A floating plate top-right (2px wall, offset cast, inner bevel) listing the document's headings as an indented index — depth set by heading level, h1 rows in tracked caps. Choosing an entry scrolls the sheet and flashes the `:target` heading; Esc or the backdrop dismisses. Wide benches (≥1200px) may pin the same plate beside the sheet instead of floating it. - **Recent files (MRU):** the session's last 8 documents under the RECENT press — a plated menu of caps filenames over mono directory lines. Ctrl+Tab / Ctrl+Shift+Tab opens it cycling; Enter commits the pending row, click chooses directly, Esc cancels. The open file is marked, never duplicated. - **Scroll rails:** always-visible 10px thumbs (ramp ink, 2px bench-colored inset ring) that heat to Daemon Blood on hover — position must stay legible without interaction. - **In-document anchors:** a `:target` heading block takes a soft Fatal Error flash wash (14% alpha, 2px radius). The live reload restores the reader's place after every reprint — by the first visible block's anchor when it survives, else by proportional scroll depth; the sheet never flings back to its head on save. - **Links:** prose links set in Digital Rust and heat to Fatal Error on hover. External (http/https/mailto) links open in the system browser via `OpenExternal`; relative links to other Markdown files open in-place as documents via `OpenRelative`; in-document `#fragment` links scroll the sheet. ### Content plates (in-document) - **Code fence:** deep near-black inset well (#110402, 2px wall, inner lowlight) set apart from the body stock, mono at 0.875rem. Fences whose info string names a recognised language arrive syntax-highlighted from the Go backend (Chroma), each token a short Pygments-class span coloured per the Digital Rust Syntax Highlighting Specification: keywords Fatal Error, functions Stack Overglow, types Dead Thread, strings Memory Leek, numbers Thermal Throttle, constants Bright Stack Overglow, comments Dim Thermal Throttle italic, operators/punctuation Copper Trace; diff fences paint additions Memory Leek 15% and deletions Amber Alert 15% over the whole line. Unrecognised or language-less fences render as plain mono ink, untouched. The daylight world re-inks every token role toward the ink end of its ramp so the highlighting holds on cream stock. - **Inline code:** 55% fill chip, 1px rule wall, 2px radius, Stack Overglow ink. - **Blockquote:** panel note — Null Pointer fill, subtle wall, sanctioned 3px Dead Thread left bar, inner bevel. - **Table:** walled plate (2px wall, separate spacing, radiused corner cells), caps head row on Null Pointer, hover row on Bad Sector. - **Error readout:** elevated plate, 2px Amber Alert wall with the sanctioned 3px left bar, "Fault" sigil in caps. ## Do's and Don'ts ### Do: - **Do** keep Digital Rust to roughly 10% of any screen — accent means action (primary press, section rules, hover heat) and nothing else. - **Do** give every pressable element the full press cycle: rest cast → −2px lift on hover → +2px depression and zero cast on press, on the 150ms default easing. - **Do** report state with restraint: presence is silent; only a gone file earns the GONE stamp. Never badges, banners, or toasts. - **Do** keep the reader's place sacred: live reload reprints the proof around the reader, restoring scroll against the new content — never fling the sheet back to its head. - **Do** keep navigation read-only and contextual: the contents panel, find bar, and recents menu appear on request and vanish on Esc; nothing edit-y ships. - **Do** set all structural words in tracked uppercase Rajdhani with tabular numerals. - **Do** keep the sheet on its 44em measure with deckled edges and the 10px baseline cast at every window size. - **Do** honor `prefers-reduced-motion` by cutting noise, scanlines, and transitions — the proof stays, the hum stops. - **Do** implement light mode by re-inking roles onto cream stock per the Daylight Print Rule. ### Don't: - **Don't** add chrome that isn't the document: no sidebars, tabs, gutters, tool palettes, or anything edit-y — the read-only conviction is absolute (a contextual, read-only affordance like a navigable TOC panel could earn its place; editing UI never can). - **Don't** use blur, translucency, backdrop-filter, or diffuse soft shadows — depth is hard offsets and bevels only. - **Don't** draw the category's blank flat-utility reader: no white void, no hairline gray chrome, no inert flat buttons. - **Don't** set headings in any color but the One Heading Colour, or prose in any face but the reader's. - **Don't** introduce off-ramp grays, pure black/white surfaces, or a second accent hue. - **Don't** fake print with skeuomorphic textures, stitching, or literal machinery — the Bound Proof stays typographic: deckle, rule, stamp, measure. - **Don't** let prose outperform the machine faces: chrome and measurement stay mono/caps; italics and em never wear the heading color.