diff --git a/PLAN.md b/PLAN.md
index fab47e5..464f5b4 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -21,7 +21,7 @@
- [ ] **State:** In progress — the package-native capped xtask entry point is reachable, rejects unknown packages, propagates mutest failure, and mutation-tests `hemx-axum`, `hemx-core`, `hemx-js`, and the full `hemx-test` package cleanly; full package closure remains.
- **User value:** maintainers can run one bounded repository command and trust that meaningful Rust logic across every mutation-applicable library is either killed or explicitly justified.
- **Build:** add a capped `hemx-xtask` mutation command that invokes `/opt/repositories/mutest`/`mutest` through package-native test targets rather than the broken workspace-wide example path; enumerate only current mutation-applicable library/proc-macro packages; finish adversarial tests or simplify code until every survivor is classified; keep equivalent, invariant-only, and infrastructure-inapplicable classifications inspectable and minimal; document the exact local release command in the existing readiness surface.
-- **Blocked by:** none; broad survivors currently remain in `hemx-build`, `hemx-derive`, and `hemx-lsp` outside already-clean focused contracts. The complete 470-mutant `hemx-axum` package gate now passes with 262 caught and 208 unviable after public page/form/multipart/registry/response/runtime proofs and narrow classification of infallible header parsing and streamed multipart unwrap-equivalent mutants.
+- **Blocked by:** none; broad survivors currently remain in `hemx-build`, `hemx-derive`, and `hemx-lsp` outside already-clean focused contracts. The current `hemx-build` slice now adversarially proves policy, client-module/event/state, confirmation, SSE, delay, throttle, and mixed-event diagnostics; remaining generated-resource and diagnostic-contract survivors remain. The complete 470-mutant `hemx-axum` package gate now passes with 262 caught and 208 unviable after public page/form/multipart/registry/response/runtime proofs and narrow classification of infallible header parsing and streamed multipart unwrap-equivalent mutants.
- **Proof:** the new xtask mutation command exits zero within its documented bound, covers each applicable package, emits no unexplained missed mutant, and a deliberate adjacent mutation makes it fail. `cargo run -p hemx-xtask -- test` remains green. req: test/020 req: test/021
## 3. Elect and enforce the release license policy
diff --git a/hemx-build/src/lib.rs b/hemx-build/src/lib.rs
index 73e8658..b796a22 100644
--- a/hemx-build/src/lib.rs
+++ b/hemx-build/src/lib.rs
@@ -3156,6 +3156,84 @@ fn main() {{
"data-hemx-policy",
"latest",
),
+ (
+ "empty-client",
+ r#""#,
+ "data-hemx-client",
+ "non-empty",
+ ),
+ (
+ "client-module-scheme",
+ r#""#,
+ "data-hemx-client-module",
+ "same-origin",
+ ),
+ (
+ "client-event",
+ r#""#,
+ "data-hemx-client-event",
+ "runtime-supported",
+ ),
+ (
+ "client-version-zero",
+ r#""#,
+ "data-hemx-client-state-version",
+ "positive",
+ ),
+ (
+ "client-version-invalid",
+ r#""#,
+ "data-hemx-client-state-version",
+ "positive",
+ ),
+ (
+ "client-policy-invalid",
+ r#""#,
+ "data-hemx-client-policy",
+ "latest",
+ ),
+ (
+ "events-mixed",
+ r#""#,
+ "data-hemx-on",
+ "runtime-supported",
+ ),
+ (
+ "confirm-empty",
+ r#""#,
+ "data-hemx-confirm",
+ "non-empty",
+ ),
+ (
+ "sse-empty",
+ r#""#,
+ "data-hemx-sse",
+ "non-empty",
+ ),
+ (
+ "delay-empty",
+ r#""#,
+ "data-hemx-delay",
+ "milliseconds",
+ ),
+ (
+ "throttle-invalid",
+ r#""#,
+ "data-hemx-throttle",
+ "milliseconds",
+ ),
+ (
+ "duration-suffix-only",
+ r#""#,
+ "data-hemx-delay",
+ "milliseconds",
+ ),
+ (
+ "policy-duplicate-anchor",
+ r#""#,
+ "data-hemx-policy",
+ "latest",
+ ),
(
"debounce",
r#""#,