Pixel Provenance: a click can only reach what you actually see (a world-first)
Every browser answers 'what did I just click?' from the page's structure - box positions and stacking order - worked out entirely separately from what was actually painted on the screen, on another thread, in the graphics card. That gap is the reason clickjacking has survived fifteen years of defences: the pixels you see and the element a click lands on are decided by two systems that never compare notes. The classic attack lays an invisible element over a real button, so you see and aim at the button but the click is delivered to the attacker's element on top. Because Floati paints every pixel itself, deterministically, it can close that gap outright: as it paints, it records for every pixel which element's VISIBLE ink is actually there, and a click is then checked against that map. If the page's structure would deliver the click somewhere other than the element whose ink you can see under the cursor, that disagreement IS the attack, and the engine catches it - proven on a real rendered clickjacking page, where an invisible link exactly covering a button is flagged while the honest button is not. A transparent or near-invisible overlay owns nothing by design (it paints no visible ink), and the whole thing is free of visual risk: the recorded ownership is a parallel channel that never changes a single colour byte. This is a guarantee no GPU-composited browser can make, because their hit-testing is deliberately decoupled from painting - the same deterministic-rendering property behind Render Receipts and time-travel debugging, turned inward. It is an engine capability and an opt-in integrity check today, not yet the default click path or a visible panel; Security moves 41 to 42, and the overall holds at 57 (an innovation is real capability, not one of the named infrastructure floors). Honest limits are written down in docs/pixel-provenance.md.