Release 3.5.1 -- the documentation was wrong in ways that mattered A patch release with no intended behaviour change to the codec: a full decode is byte-identical to 3.5.0 on all 11 decodable corpus files, with all 11 refusals unchanged. What changed is what the project SAYS, which in several places was false, and one public function that refused files it should have accepted. Three false statements in the clean-room record. CLEANROOM.md claimed no PGF decoder binary was ever obtained or run, and that verification therefore rested on round-trips rather than differential comparison -- while eight harnesses invoke the reference decoder and the digest's strongest evidence is 48/48 files exact against it. docs/SOURCE-LOG.md had no entry at all for the reference binary, despite its own entry 1 promising one would be added when a binary was obtained; the entropy coder was derived through that binary. SPEC-DIGEST.md's front matter said no source other than the two Stamm papers was consulted, which was untrue of some 5,800 of its 6,325 lines. All three are corrected with explicit withdrawals rather than silent replacements, and the backfilled log entries are labelled as backfilled. Attestation clause 5 now says "compiled encoder and decoder output"; the signature block remains unsigned. Four defects in the published format specification, each sufficient to produce a broken implementation (docs/PGF-FORMAT.md 1.13): the bit-plane count documented as a 4-bit nibble when it is 5 bits, misdecoding every 16-bit-per-channel file; the retracted 45/32 deadzone constant still standing in the quantizer pseudocode, with the prose that corrects it directly beneath -- stale for nine document versions and wrong on the |v| = 359 case the v1.3 changelog names; the deliberate int32 deadzone overflow unspecified, without which qualities 29-31 disagree with the reference; and a quality-18 ceiling in the shift pseudocode, refusing 13 valid values. One real bug. parseMacroblock enforced "bit 4 clear" as an invariant after section 7.5.86 had shown bit 4 to be the bit-plane count's high bit, so it rejected legitimate RGB48 and CMYK64 payloads with PGF_SPEC_GAP -- claiming the format was undetermined about a field this project had measured. decodeToPixels never used that path and was unaffected. Fixed, with a regression test; the existing test named for the invariant turned out to exercise only bit 5. tools/roundtrip.js ran its whole sweep on import, the only harness lacking import.meta.url gating. The supported quality range, stale in roughly forty places -- README, types, the npm description, the specification and a dozen source comments still said 0..18 or 0..19 where the code has done 0..31 since 3.4.0, and two comments claimed quality 3 was refused when it is among the best-verified values. Every corrected figure was re-derived from harness output rather than copied; two numbers no shipped harness produces were dropped instead of reattributed. Recorded rather than guessed: four mis-keyed gap tags in bitstream.js, types declarations that no type-checker has compiled, and one reference tool that cannot be hashed or dated, whose contribution is now stated as unknown. 618 tests. roi-check, progressive-check, formats-check (420/420 each direction), encode-check, pgfa-quality-check (960/960 over qualities 0..31), and the bitmap, indexed, gray, lab, untransformed and gray8-step harnesses all pass.