docs: the ACL leaves the roadmap, and the development-name excuse is withdrawn

Four documents brought into line with what landed at 54f0296 and ee3fedf.

HANDOFF section 4 item 5 said the ACL was deliberately last. It is deleted, not
deferred. Authorisation lives upstream at the last proxy hop, decided against a
membership system this repository knows nothing about, so the compiler will
never have a user table, a login form, a session, or a group name in any form --
including as a configuration value, which is how that leak arrives by the side
door. An item left the roadmap rather than moving down it.

Item 4 claimed persistence was the prerequisite for a library of saved designs
and for access control. The second half has been false since the identity
contract landed and was found by reading the anchor rather than recalling it.
Corrected, and item 4 now states the position that follows: the filesystem is
the first store, not a database. Design records are already plain text, already
content-addressed by input_id, and already readable by someone with none of this
software. A directory of them is a store with perfect provenance and no schema
to migrate. SQL earns its way in when there is a query walking files cannot
answer -- "every design by this author since March" is that query, and it
arrives with membership, not before.

"Acceptable for a development name" is withdrawn from HANDOFF section 4 and
WORK-ORDER-004 section 3. The name is production, dev abbreviates Mechanical
Compiler Developers, and it appears on printed material. The posture is
unchanged -- world-reachable, unauthenticated, /m/ not yet gated, STL export
will ship open -- but it is carried openly as open question 10 instead of
excused. The phrase survived three documents and two earlier corrections
because it was plausible and nobody challenged it, which is the same mechanism
that produced the stale ingress paragraph.

Section 0 gains the two new documents, with CONSUMER_INTERFACE_GATES.md marked
read-before-proposing-an-integration: several tempting cross-project moves are
recorded there specifically as things not to build yet, and a successor who
finds them independently will be tempted to solve them. Also a note that
deploy/ now holds the unit and the vhost as they actually run, and that the
repository is the single source of truth -- read a container when you suspect
drift, then fix the drift here rather than on the host.

HANDOFF section 1 and PROCESS section 9 gain the same rule: pct exec runs no
shell. A glob, redirect, pipe or && is expanded by the host shell against the
host's filesystem and the container receives whatever literal survives, so an
unwrapped glob reports "No such file or directory" and reads as a broken
container. Third instance of this class after F-035 and F-036 -- each time the
tool was invoked wrongly and the error named the wrong subject. Not filed as a
new failure: it is the same finding as those two, and a third entry would
record the instance rather than the pattern.

STAGING-STATE records the deployment configuration as committed. The unit had
been marked delivered at deploy/mechcomp.service on 11 SEP while existing only
on the host.
This commit is contained in:
2026-09-12 09:48:22 -05:00
parent ee3fedf794
commit c72036cbbb
4 changed files with 73 additions and 10 deletions
+7
View File
@@ -547,6 +547,13 @@ provisioning:
- [x] ~~Dependency install from committed manifests~~ — done 2026-08-18
- [x] ~~`mechcomp.service`~~ — done 2026-09-11, `deploy/mechcomp.service`
- [x] ~~Deployment configuration under version control~~ — done
2026-09-12. `deploy/mechcomp.service` and
`deploy/nginx/mechanical-compiler.conf`, imported verbatim and
checksum-proven equal to CT 100 and CT 101 at import. The unit had
been recorded as delivered at that path on 11 SEP while existing
only on the host. `mechcomp.env` is deliberately **not** committed —
see `deploy/README.md`
- [ ] `mechcomp-worker.service` — no worker exists yet; `src/mechcomp/worker/`
is still a stub
- [ ] Reference toolchain image `mechcomp/reference-toolchain:8.0.0`