diff --git a/README.md b/README.md index f837ff7..6f2224b 100644 --- a/README.md +++ b/README.md @@ -30,6 +30,7 @@ do not want to be bound to. Measure and attest; never adjudicate. ``` docs/ specification, state, failure log, roadmap +deploy/ service unit and vhost, under version control legacy/openscad/ rev 8.0.0 generators — reference, not a live target fixtures/ frozen acceptance oracles tools/reference-toolchain/ pinned OpenSCAD + BOSL2, build-time only @@ -37,10 +38,14 @@ src/mechcomp/ the application tests/ acceptance against the oracle ``` -Read `docs/ROADMAP.md` first for what this is, then `docs/ENVIRONMENT.md` for -how an instance is built. If you are writing provisioning automation, read -`docs/FAILURES.md` **before** the specification — every entry is something a -script written from the specification alone would have got wrong. +Read `docs/ROADMAP.md` first for what this is, then `docs/PROCESS.md` before +issuing any command against a host. `docs/HANDOFF.md` §0 and `docs/PROCESS.md` +§8 both carry the full reading order and are kept in step with each other. + +If you are writing provisioning automation, read `docs/FAILURES.md` **before** +`docs/ENVIRONMENT.md` — every entry is something a script written from the +specification alone would have got wrong. `docs/DIVERGENCES.md` lists the +requirements that are specified and not currently met. ## Getting started @@ -83,3 +88,8 @@ AGPL-3.0-or-later. See `LICENSE`. Section 13 obliges us to offer source to users interacting over a network, so any deployed web tier carries a visible link back to this repository. That is a licence obligation, not a courtesy. + +**It is not currently met.** The composer has been publicly reachable since +2026-09-11 and the served page carries no such link. Recorded as DIV-001 in +`docs/DIVERGENCES.md`, where it is the first item on the list, and required +again as constraint 11 in `docs/ENVIRONMENT.md` §14. diff --git a/docs/ACCEPTANCE.md b/docs/ACCEPTANCE.md index 85f24c8..2aa3014 100644 --- a/docs/ACCEPTANCE.md +++ b/docs/ACCEPTANCE.md @@ -7,7 +7,7 @@ them readable: a `tolerance` block inside a hashed JSON fixture, and one line of `test_oracle.py`. A person asking "how close does the port have to be?" had to read code to find out, and the reason for the numbers was nowhere. -Last updated 2026-08-22, closing F-034. +Last updated 2026-09-13. Section 7's correction landed; F-034 closed 2026-08-22. --- @@ -156,3 +156,9 @@ The per-profile breakdown recorded there — Three-Fin 9, Y 7, A Frame 5, Rectangle 5, T 1, Four-Fin 1 — sums to 28 against a stated total of 30. Measured, the distribution is **Three-Fin 10, Y 7, A Frame 6, Rectangle 5, T 1, Four-Fin 1 = 30**. Three-Fin and A Frame were each undercounted by one. + +**Applied 2026-09-13.** `HANDOFF.md` §7 now carries the measured figures. The +correction sat here, and in F-034's resolution, for three weeks while the wrong +numbers stayed in the document a successor reads first — which is the argument +against leaving a correction notice parked in a second document. It is kept as +history rather than deleted, because F-034's resolution cites it. diff --git a/docs/IDENTITY-CONTRACT.md b/docs/IDENTITY-CONTRACT.md index 691a74a..11f2832 100644 --- a/docs/IDENTITY-CONTRACT.md +++ b/docs/IDENTITY-CONTRACT.md @@ -61,10 +61,16 @@ browser -> wg-pk public TLS for dev.mechcomp.kane-il.us -> WireGuard tunnel -> DNAT on srv-b scoped to the hub as source - -> CT 101 nginx local staging-CA TLS; DECIDES; sets the headers + -> CT 101 nginx local staging-CA TLS; the deciding hop -- see below -> CT 100 :8770 the application ``` +**Nothing decides anything today.** CT 101 terminates TLS and proxies. It sets no +`X-Mechcomp-Auth-*` header, because §3 is not implemented — see §8. The label +marks where the decision belongs once it exists, not a duty CT 101 currently +performs. An earlier version of this diagram read `DECIDES`, which an outside +implementer would reasonably have taken as a description of what runs. + Three things about this that are easy to get wrong: **CT 101 does not know the public name.** Its `server_name` is @@ -186,6 +192,15 @@ Everything requiring membership lives under `/m/`. Everything else is public. /m/... anything gated later members ``` +**This table is the scheme, not the current state.** `/m/` is not gated today and +`/m/stl` ships open (§8). The right-hand column says where the line falls once +the `location /m/` block exists, not where it falls now. `web/app.py` states the +same thing in its own docstring. + +Stated explicitly because `CONSUMER_INTERFACE_GATES.md` G-1 records the standing +lesson for this document: an interface document should contain no statement a +reader will take as fact when it is not yet one. + The proxy gets **one** `location /m/` block, written once and not edited again. Gating a new endpoint afterwards is choosing a URL in Python — no proxy change, no shared-infrastructure change, no escalation. Ungating one is the same move in @@ -194,7 +209,8 @@ reverse. That cheapness is the point. It means the placement of the line is a reversible decision rather than a structural one. -**Where the line is today: export is gated; looking is not.** The catalogue and +**Where the line falls once it is enforced: export is gated; looking is not.** +The catalogue and the composer are open to anyone. What requires membership is producing an artifact that carries a design record, because the record names an author and an author only means something once somebody established who they are. The site is