Skip to content

Latest commit

 

History

History
657 lines (573 loc) · 356 KB

File metadata and controls

657 lines (573 loc) · 356 KB

Mere Documentation Index

The design-docs index for the Mere workspace. All authoritative project documentation belongs under design_docs/. Entries are one line each; the deep rationale lives in the doc itself.

Current bounded proofs (2026-09-05): the projection grammar adoption plan records executable Graphshell authoring, the interactive practice workspace with retained rendering and measured compiler improvements, and the two-peer Woodshed comparison space with signed admission, authority filtering, and offline disk reopening; fixture scope and source-hashed receipts are explicit.

Required reading order

Active implementation: projection refresh and surface reuse covers dependency-aware layout caching, independent appearances, bounded live richness, and separation of paint from placement work.

Active continuation (2026-09-05): Moot collections and community publishing extends the historical M1 plan. Its same-machine live-peer proof passed scoped iroh transfer, stable-Persona binding, current Gemot contribution/hosting authority, unadmitted-peer refusal, author exit, durable host restart and ordinary Gemini retrieval. Production publication/hosting records, historical authority proof, the Persona-to-device adapter and a two-machine receipt remain open. Retention, Fleece collections, application co-op and addressed mesh delivery follow.

  1. DOC_POLICY.md — documentation governance rules.
  2. TERMINOLOGY.md — canonical current terminology.
  3. 2026-05-04_lexicon_brief.md — naming history; its 2026-08-31 amendment points current terms back to TERMINOLOGY.md.
  4. 2026-05-24_external_deps_topology_brief.md — the Code/ workspace-root crates/repos/ split, path-dep convention, and cross-repo rename lineage.

Cross-cutting briefs (design_docs root)

Root-level briefs that span multiple area-docs (not required reading).

  • projection_scenes_and_graph_native_platform — direction record for graph-native projection scenes, the scene catalog, and the capability boundary among Mere, Scenograph, Cambium, and Genet; September 5 reviews working surfaces against earlier tile, card, and custom-leaf designs and distinguishes resolved identity boundaries from unproven nested-surface lifecycle; it opens no implementation task.
  • standards_survey_briefresearch brief (2026-08-24): the workspace's single home for cross-repo standards findings (DOC_POLICY §2 — genet, retinue, smolweb, woodshed et al. cite it by path rather than copying; plans that act on it live in their own repo and point back). 174 entries plus a hand-added Nym WATCH row (2026-09-01, when §4's local-link claim was also corrected) graded ADOPT/PULL/SKIP/WATCH across castellan, the ports, genet's fleece/pelt/tabard, and the apps. Thirty-two entries were wrong on first pass and were corrected by an adversarial fact-checking pass, which is the brief's main methodological result and why every status carries a verification date; the sharpest lesson is that the two entries a surveyor self-flagged as "long-settled, quoted from memory" were both stale — confidence that a settled standard cannot move is exactly what produced the errors. Corrected the 2026-08-10 credential brief in place: the ssh-agent protocol is now RFC 9987 (Standards Track, May 2026), CXF v1.0 reached Proposed Standard (Aug 2025, errata 2026-03-09) so it is neither a draft nor an unclaimed Rust niche, and Linux gained an emerging third-party passkey seam (credentialsd + proposed XDG portal). Vault findings, verified in code: every real gap is crypto agility, not crypto choice — neither passphrase_storage.rs nor keypair.rs records its own derivation parameters (no m_cost/t_cost/p_cost in the file format, Argon2::default() sits below both RFC 9106 §4 options, derive_child has no versioned context slot), which makes raising cost indistinguishable from corruption and an argon2 default change a silent unlock failure; a v2-root decision, not a patch. Also: otpauth:// has no normative specification at all and castellan already imports it; CXF files are plaintext by design because CXP has not moved since 2024; a WebAuthn credential is scoped to an RP ID, not a persona, so the face model has no representation in the standard; TPM 2.0 NV counters close the freshness-ledger rollback gap; and only one process can own org.freedesktop.secrets, so on a stock GNOME session castellan loses to gnome-keyring and is silently inert — wants a runtime invariant, not a comment. Design-to findings: fleece can mint W3C Web Annotation selectors (REC since 2017, eight types, refinedBy) essentially free during a traversal it already performs, plus Text Fragments for shareable provenance with zero infrastructure, and Rust prior art is absent; tabard's DTCG target went stable at 2025.10 with no Rust implementation at all; APCA is a SKIP because WCAG 3 still names no contrast algorithm. Largest hole is in none of the named repos: there is no local-link discovery story anywhere — mDNS/DNS-SD (RFC 6762/6763) is the layer distillery's ring, moot's places and turnstone's shared places all need. Two dated actionables: RFC 8446 was obsoleted by RFC 9846 (July 2026), and smolweb/crates/scorpion-protocol/src/tls.rs:29 still cites the dead designator (flagged, not fixed — out of scope); and continuous UTC goes to a vote at the 28th CGPM, 13–15 October 2026, with Draft Resolution C making it effective 2027-05-20, which would end leap seconds and remove a live data dependency from turquet. Refusals recorded with reasons (post-quantum for the vault, FIPS 140-3, SOC 2, PCI DSS, MLS-for-the-vault, LoRaWAN, XMPP, glTF, and "no standard exists" for P2P job/lease semantics and for the readable article). §8 records the method, the four sources that 403 automated fetch and are therefore unconfirmed, and the re-check cadence; §9 lists seven open decisions for Mark.
  • turnstone_suite_composition_censusdirection (2026-08-22, with Mark; amended same day; lane correction 2026-08-24): Turnstone ruled the flagship compositor, not the owner of port functionality; each port owes a sovereign tool plus an embeddable surface, both consuming one shared product model. Corrections: Graphshell narrowed to overmap/Mere-management/routing, ports/djinn repurposed from the stale Knot name reservation to the user-scoped resident, and the place-port plan's "not another application" ruling reversed (the authority half — gemot/commons/murm/stickleback — unchanged). Strongest finding: the composition seam is missing before the apps are — Turnstone's BUILTIN_PANES table and PaneRenderer enum are closed, so ports cannot contribute surfaces. A1's landed External source identity is reusable; the provider-contribution seam is separate from A2's graph runtime pool. Port verdicts, amended same day: Moot — one port (mere-moot, [lib] name = "moot"; crates.io moot/murmur are taken), two surfaces — murmur (conversation; mere-comms is its model, rescued from "fold or retire") mountable alone for Signalman, and moot (community/governance); gazette founded on the dramatis tier beside castellan (contact/recipient picker = embeddable half; resolution, feed polling, trust state = authority half in Djinn; picker consumed by Knot/Moot/Signalman is the boundary proof) — executed 2026-08-23 by promotion, not founding: the resolver crate already held the gazette name and bare gazetteer is a stranger's, so crates/dramatis/gazette (historical citation) moved to ports/gazette keeping its package and code (the word's three senses were the roadmap; knot is the precedent for a port holding its own stack); Alembic = the granted-agent and automation workshop (Athanor was always an agent; recall feature carries memory surfaces without the workshop; mere-alembic), founded behind the one-bounded-agent-in-two-hosts receipt. Stubs founded 2026-08-23 and published 2026-08-24: mere-moot 0.0.1 (ports/moot) and mere-alembic 0.0.1 (ports/alembic (historical citation) ), both MPL-2.0, registered and compiling, no implementation; names claimed per the heddle lesson. Alembic needed one correction first — the fleece F5 pass had added an unused fleece dep to the stub, which also made it unpublishable (versionless branch-git entry); ruled with Mark to drop it and re-add with a version when alembic has code that consumes an Article. Plus the gazette promotion above. §8 lists capabilities needing exposure rather than ports (search, extraction/reader via fleece, downloads/custody, Djinn status, pickers, activity, diagnostics, map/table/timeline arrangements); §11 gives the composition done-conditions. Sharpened 2026-09-02: Graphshell is a viewer and redirector and the preeminent projection manipulator; it reads structured content through Genet and Workbench, Knot may use Workbench too, and the browser proper is Turnstone's; Alembic re-ruled into Distillery as a component crate, Athanor with it, both flat under the port and mere-athanor founded (§7.4).
  • license_posture_briefruling recorded 2026-08-22: MPL-2.0 by default for everything Merely owns, with correct provenance. Ruled in two steps the same day: first "copyleft on the platform, consumers license themselves", then the default, once Mark noticed every app becomes a platform at maturity and classification was the churn behind every license event since May. Applies to mere, genet, the games, the applications, and the standalones alike; third-party-derived code keeps its license and notice (ledgered per repo in LICENSES.md); substantial derivatives taken in go MPL with the upstream notice retained (cambium/meristem ruled). No exceptions: the fork/vendor criterion survives as the test for future requests, but illume, buckram, errand, and tinct were all considered and declined. Header shape C (copyright line + Exhibit A + SPDX) and the notice Mark Alan Boykin, replacing Mark AB (markik) on 489 files; Exhibit A attachment is what makes a file Covered Software (§1.4), and the copyright line is optional attribution. Records the history (founded MPL dee147b4, relicensed permissive a9902e3c on provenance grounds only, then the radio and games rulings) so the change is a decision, not accretion; why MPL locks in others' forks and never Mark's own; the sweep's measured size and the crates.io posture (47 published, no license-only republish). Entity note: Merely LLC exists but a notice is not title — naming it would need a written assignment. Side finding: mere does not resolve locally since genet 55c05d11 removed the genet-layout manifest.
  • execution_ordering_prior_art_briefresearch brief (2026-08-18): a close read of the external wavelet crate (a single-threaded, deterministic, push-based computation-graph runtime; 20k downloads, zero reverse dependencies) for what transfers to our execution layer. Five ideas: two separately-named edge kinds (Trigger propagates, Observe only orders and reads, which on inspection has no site in our stack today: the set graph, chartulary, and cambium's rebuilds carry no propagation semantics to divide, and woodshed's invalidation is whole-swatch hashing rather than a dependency walk), depth-ordered scheduling where scheduling backward is a hard error rather than a silently dropped path, a per-node mutation epoch for staleness (armillary's Generations at a different scale), a clock as a swappable component whose third implementation is replay, and build-time factories that hold the topology still while swapping leaves. Corrects a claim made before reading either closely: wavelet is not a counter-position to armillary but the missing half of it, since armillary owns the thread boundary and says nothing about ordering inside the kernel. Two non-dataflow lessons: the crate was renamed from reflex-rs, trading a mechanism-describing name for one already spoken for in signal processing, and download counts are CI traffic, not adoption. Companion to the data-oriented doctrine brief, which owns representation where this owns execution.
  • family_composition_thesis_briefresearch brief (2026-08-12, digesting a chat chain with Mark): the family's product thesis in four nouns — personal datalakes, cross-application identity, peer-to-peer association, composable views — the Drive inversion (reach without a universal repository, account namespace, or landlord cloud), restated in canonical vocabulary (source truth / a mere, personae + insigne, stickleback domains, granted scores and petitions). New deltas extracted: the port law (castellan's embeddable-half/authority-half split generalized to the definition of every port), Graphshell as embeddable capability (a swatch at the session boundary), the anti-shell test (a second host, not a second view, is the receipt), the narrowing gradient (possession ⊇ disclosure ⊇ sync ⊇ projection as a testable bug class), and the release narrative (Woodshed alone → Personae/Castellan → Graphshell → second-host embed → Knot). Adds the decomposition-altitude prior-art survey (Solid, atproto, Sandstorm, Plan 9, Holochain, OpenDoc, remoteStorage) beside the three sibling surveys, with Holochain as the warning for shipping sovereignty without a composition capability. Corrections: castellan owns no repository; "repository" stays unminted (source truth / mere cover it); signalman is retinue's app. Capability named 2026-09-02: the projection manipulator is Scenograph (the name the boundary plan frees and reserves for the editor), a home-page graph of app graphs, Graphshell its preeminent host, appearing in every application with its own graph. Research lanes added 2026-09-08 (§7): stack-pillar candidate map, execution/lifetime R1 and identity/custody R2, source-grounded gaps and owner-specific implementation gates; delegated retention stays distinct from domain authority. Initial experiments recorded 2026-09-08: real Rust arena retention/foreign-handle failures, a passing scratch retention correction, and drive plus capture/custody models with negative controls; full consumer gates remain open. Bounded continuation added 2026-09-08: approximately ten owner-specific slices; replacement retention and template-root corrections committed in Genet, with handle, worker-drive and capture correlation work in progress.
  • leverage_census_briefresearch brief (2026-08-10, updated 2026-08-12): cargo-metadata reverse-dependency census of both platform workspaces joined with all 133 external family consumer edges. Its largest true zero is now resolved: Distillery v0 consumes mere-mesh-host and owns its retention-maintenance projection. Remaining headline zeros include mere-eidetic-search, the three unwired registry crates, the shell-era quartet, verso-tile, and the scenograph facade. Also clears the false flags: import, incipit, luggage, signals, stickleback, and the graphshell family are all consumed.
  • application_prospects_briefdirection brainstorm (2026-07-24, with Mark): the intersection filter over the stack's differentiators; six candidate applications (field telemetry commons, mesh knowledge commons, mesh stewardship console, attenuated-authority agent workshop, flow-native modeling, performing documents) each with its disposition; the three-seam composition thesis (genet-host-api, engram content classes over eidetic/murm/retinue, the sceno scene contract); and the seven separators with rulings. Spun-out siblings: the shared-engram commons brief and genet's docs/2026-07-24_pelt_knot_direction.md.
  • auto-update_brief — configurable auto-update across every deployment surface (desktop, radio firmware, web/wasm, mobile-later): the policy/transport two-layer recommendation, prior art (Velopack Rust core, axoupdater, TUF/tough, Sparkle/Omaha as references, embassy-boot for firmware, Meshtastic UF2/DFU practice), and the offline minisign release-key posture. Updated 2026-08-26: the browser/native session pulls Luggage's carrier-neutral ReleaseRefV1 and Wasm-clean signed-envelope verifier forward while general P2P distribution stays deferred; v2 splits signed content identity from disposable feed, mirror, host, and peer locators.
  • dependency_footprint_brief — cross-repo dependency audit baseline (406 unique crates checked 2026-07-03): the deliberate gates recorded (iroh 0.98 gated on the p2panda release, wgpu 29 gated on vello + settling, taffy re-vendor gated on stylo_taffy), the ungated actionable queue (stylo v0.19, text-stack lockstep, wasmtime 46, RustCrypto family, icu 2, mere singles), 20 dead genet crypto workspace deps deleted, and the footprint numbers to re-measure ~twice monthly.
  • deterministic_replay_brieffollow-on to the data-oriented doctrine brief's capture/replay section, written after Tangle came up while designing games-wing co-op. Records the correction that both halves (state-as-fold, and capture/replay) have been doctrine here since 2026-07-02 with netrender snapshot_postcard/replay_postcard and graph-kernel history already shipped — so the arriving idea was a rediscovery. What is genuinely new is narrower: totality without authorship, since a wasm module's linear memory is its world, so whole-heap capture cannot have the forgotten-field failure mode that hand-written capture can. Tables the per-layer-versus-whole-heap trade and concludes per-layer is correct for mere/Turnstone/genet (their state is a host, not a heap), with whole-heap winning only for bounded owned state, i.e. game cores. Also fixes two boundaries: documents can be deterministic while renders and DSP cannot, and a browser cannot replay the web. Notes Hocket as the family's live experiment, and separates input-replay (shared session) from snapshot-transfer (turn-taking, visiting, grafting).
  • data_oriented_doctrine_brief — names the stack-wide representational discipline (identity = index, meaning = kind, in/out edge asymmetry, delta streams, incremental folds; the Valmet/Nova provenance); tables the seven instances (Nova heap → orrery graph); answers the literal-substrate question (no shared core; the doctrine is the unit of reuse) and lists the cheap shared instruments (wire discipline, capture/replay everywhere, per-table instrumentation, oracle diffing, delta-log persistence). Expanded form of the README's "stack's technical architecture" section.
  • substrate_parallelism_composition_brief — composes the parallelism strategy (engine performance layer) with the DocumentScript substrate plan (capability layer): the shared armillary actor substrate; the Wasmtime-out-vs-in resolution (native = Wasmtime, browser = jco AOT, no JIT either way); the across-instance = across-actor parallelism symmetry; the co-located script-host-in-content-actor decision; the serialization "better way" (co-locate so the script hop is an intra-worker memcpy, per-turn batch, transferable flat Scene for the one expensive worker→main hop); and the web build budget (3 builds / 2 toolchains; the feared 2×2×2 collapses because jco support is not SAB-gated and std/no_std is a per-extension policy).

mere_docs/implementation_strategy/ — dated plans

  • platform_boundary_and_repository_topology_plancomplete 2026-09-06; P0-P7 landed: Genet owns the web-platform engine and raw host contracts; Mere owns Cambium's retained-widget and data-scene lanes, application composition, and host policy. Woodshed's P4 exception, the public topology and HTTPS receipt, and P7's zero-finding documentation gate are closed; Vello's active experiment is owned by Netrender.
  • theme_modes_planT1–T5 implemented: light, dark, high-contrast, and custom theme policy with the declarative lane shipped; Rhai graduation remains open.
  • virtualized_editor_plandesign, pre-build: the Knot editor consumer for Genet's existing virtual-window infrastructure, gated on the text-editing-layer decision.
  • graphshell_reference_host_planH0–H3 and H5–H7 complete; H4 follow-ons and H8 remain: Graphshell's WASM-safe reference-host boundary, with its first-party application door and Turnstone receipts complete.
  • knot_publishing_protocol_planPhase A implemented and physically receipted; Phase B unstarted: Knot's publishing grammar and renewal path, retaining the historical Mere layout after extraction to the Knot Editor repository.
  • knot_mark_read_adapterimplemented bounded adapter pending an external Demarkus-client receipt.
  • scenograph_absorption_plancomplete historical receipt for absorbing arrangements into the scene family; the platform-boundary plan supersedes its generic Scenograph-facade destination.
  • terminology_and_crate_folds_plancomplete 2026-08-31, landed on main 2026-09-02 after a rebase onto f2924f08: executes Engram→Codicil, generic Codicil→Muniment Journal, Tessera→Standing, memorial Tulpa→Hagiograph, Scholia→chartulary::rdf, and Quint→Numen/Seiche/Conatus; records legacy readers, external consumer commits, focused receipts, and the inherited Genet patch blocker.
  • derived_faces_planpictograph 0.1.0 and 0.2.0 are published; D3 completed on 2026-09-02, and D4 default-scale legibility completed on 2026-09-03: derivation v3 produces deterministic 34–275-byte IconVG faces with digest-pinned fixtures, palette-only theming, and two LOD arms. D2 provides the exact vello bridge. D3 makes Face::Derived the content-sensitive default for favicon-less nodes while preserving explicit overrides and clear-to-re-evaluate semantics. D4 replaces the collapsed low-detail bounding rectangle with a 3x3 coarse silhouette: at the real 25.92px host height, the 68-address monochrome corpus improves from 7 masks / worst multiplicity 57 to 30 masks / worst multiplicity 8. Clean standalone wasm, headless-vello contact-sheet, and 16-step headed default/detail receipts pass on the committed Genet and netrender pins. Editing stays deferred and operates on derivation parameters rather than decoded bytes. The plan also records the family branding gap (three apps ship no icon; genet still ships Servo's).
  • doc_policy_consolidation_plan (complete 2026-09-06; phases A-D landed): the canonical DOC_POLICY.md core is distributed across fifteen repos with local addenda; member-crate doc scatter collapsed into area roots; and smolweb/design_docs/ and genet/design_docs/ were founded. The original 281-record D2 aggregate is now durable beside 34 supplemental identity records; the coverage gate proves all 298 active documents have judgment blocks while retaining 17 archived records as history. The D3 gate distinguishes resolvable citations, occurrence-marked historical evidence, and committed planned targets, with zero failing findings.
  • knot_shared_surface_and_port_contribution_planP0 complete and contribution contract frozen at v1; reconciled 2026-09-05: Knot and Distillery use the same descriptor type and retained-session contract, with distinct surface identities. Turnstone 9d3a7d8 records second-provider admission, generic accessibility and the full-shell build; Genet 001448d55 and Turnstone 3f63671 record contract reduction and freeze. The T-lane captured-widget coordinate receipt remains open; F0, broader Knot status/evidence/sharing surfaces, remains gated on the relevant resident receipts, with effect authority retained by Knot. Knot's sources moved to knot-editor on 2026-09-04; Mere retains the generic composition contracts.

Knot reconciliation, 2026-07-27: the Djot editor/Knot nodes plan is now a historical Meerkat execution record. Its portable editor/readout survived in Genet and is consumed by the independent Knot Editor repository; its file, vault, writer, sync, conflict, and Commons work is complete under the Knot port plan. Product authoring intents, Inspector-to-Knot clipping, and a shared outline/fold surface remain open under the dedicated Knot authoring consumer plan. The older detailed index entry below describes the deleted Meerkat implementation and is not the current queue.

  • projection_receipts_planactive program; Waves 1 and 2 complete 2026-08-25; wave 3 gated: the first five targets supplied a headed two-reading Matrix, repeated source instances, coordinated crossfilter selection, a composed multi-input ShelfmarkV1, and the gazette Ledger replay; the Gazette promotion and plan landed at 0da3b8ba. FT6 restores the full view-state inventory through that same envelope and proves view deltas leave source authority unchanged. FT7 proves the exact InstanceId -> SourceRef mapping through LocalCarrier, an admitted Graphshell MemoryTransport session using Notochord/personae policy to a source-free viewer, and a FrozenScene semantic table. The Mere platform seam is 302bbe72d7597b7573e14199ce926bd3b03eea7f; the Mer3ly consumer is 4c42847272489c41a20dc515884e83f3b413059a. FT8 closes mixed realization in Retinue Signalman 8cea8f9: one GraphCanvasSwatch supplies Sprigging marks and Cambium semantic targets under one focus, pointer-capture, AccessKit, probe, and action model. It reuses graph_canvas; a richer Matrix component remains consumer-gated. The adoption plan owns gate status, the shelfmark note owns the citation envelope, and wave 3 opens only for a real field-data consumer.

  • address_book_muniment_port_plancomplete 2026-08-16: takes p2panda's bundled SQLite backend out of mere's graph entirely; sqlx and libsqlite3-sys are now absent from the workspace. Two findings corrected the scoping: there were two enabler edges, not one (p2panda-net/address_book forcing p2panda-store/sqlite, plus p2panda-store/default arriving through p2panda-sync and p2panda-stream), and the patch table's claim that gemot's groups/encryption features caused it was false — cargo tree -e features showed neither was ever enabled. AddressBookStoreHandle erases the backend so the ~29 files holding an AddressBook stay non-generic and the discovery strategies, already generic, needed nothing; transactions fold into the writes because every tx! site wrapped exactly one operation. stickleback::MunimentAddressBook is the new store, generic over muniment's Backend and Codec, so IndexedDB serves the browser today and OPFS slots in later — where the SQLite binding could never reach wasm32 at all. Behaviour preserved: p2panda's default was :memory: SQLite, the replacement is a memory backend. Verified by p2panda-net's own e2e gossip/sync test, 11 new store tests, and live two-peer transport round-trip and gossip. Residue: the vendored cubecl-wgpu backport is now retire-able on the sqlite axis, which belongs to the burn 0.22 migration. Archived 2026-08-20; sqlx and libsqlite3-sys re-verified absent from the lock on the way out.

  • device_grant_certificate_migration_plancomplete 2026-08-12, archived 2026-08-18: executed the reconciliation ruling end to end, M1 through M5, on Mark's posture of re-issue now, no legacy decoder (signalman was founded 2026-08-11 and no station was sited, so every grant holder was still a machine he could reach; that collapsed the staged sequence, since an intermediate on-disk format only earns its keep if a dual-read window spans it). The device grant is now a SignedDelegationCertificate set, the wrapped-epoch record is separate, revocation travels as a signed statement with the roster demoted to a fold, and the CBOR envelope is deleted with no legacy decoder. Findings that outlived the plan: attenuations was enforced nowhere, so remaining_delegation_depth: 0 was a behaviour gain rather than a rename; path_covers treats "/" as a leaf, which reads like a root and is a trap for whoever first nests under it; the empty-persona case (castellan's sited station has no personas at all) forced the action partition, so a grant is a set and which certificate an action lands on depends on whose authority covers it; and a verifier needs one trusted root per persona, not one master key, which is the architectural consequence M5 built and which anything new evaluating a grant inherits. Closed with a 2026-08-18 re-check rather than on trust: the workspace and all four off-default feature gates are green, which cleared both items it had left under "noted, not fixed". Nothing spun out; the successor work is the carriage design it exposed.

  • epoch_carriage_replicationdecided 2026-08-14, with Mark: replaces the reconciliation doc's malformed "eidetic artifact or wallet file" question (the wallet is already an eidetic consumer via engram_seal::WalletEpochSealer). Mark's question was the right one: if the key material is encrypted anyway, why shouldn't epoch carriage replicate? Ruling: it may, at TrustedPeersOnly and never MootScoped/PublicPortable, but not until the record's plaintext identifiers are blinded, and retention gates shipping. Three findings. Only one of WrappedEpochMaterial's four fields is ciphertext, so a replica discloses persona_id, epoch_id and rotation cadence in the clear — the persona-to-device association graph, which is the one leak persona separation exists to prevent (fixable: the identifiers only route, and the receiver already holds the pairing key, so a blinded index works). The record cannot be sealed by eidetic's sealer at all, since that sealer derives its payload key from the epoch secret this record delivers; it works anyway because eidetic's seal path is Some(sealer) if is_private_lane(..) with _ => cleartext, so a TrustedPeersOnly record with no sealer is stored cleartext and nothing complains — mechanically enabling and a silent degradation from a class that reads as a guarantee. And the risk with no schema fix: replication defeats purge_deleted, converting "revoke, rotate, purge" into "revoke, rotate, and hope", which is harvest-now-decrypt-later against exactly the stolen device the threat model assumes. Stays LocalOnly (eidetic's default, and today's behaviour) until retention is answered, so nothing ships undecided.

  • carriage_against_stickleback_epochsreview (2026-08-16, at Mark's request): checks the leased slots proposal against machinery that already exists. Ratification had already happened on 2026-08-14, so the four findings are amendments to a ratified design; all four were folded into the proposal on 2026-08-16. The transport exists: personal_sync is H7 personal-device sync, running, on stickleback/p2panda with PrivacyClass already enforced, and what is missing is a lane, since PersonalGraphEvent is a graph grammar and carriage is keyring state the proposal's own ruling 1 keeps out of it. A per-device key group already exists on that lane (graph_keys: "this device's membership in one personal graph's key group", pre-keys, GroupSession through Personae's sealed store), so carriage is a second mechanism for one shape and the proposal never mentioned the first; recipient_for_root names the population that still needs a leased slot, the device "paired but never joined the key group". stickleback::epoch_retention is a live engine for this exact problem, in production in moot::commons::chat and knot::sync with a propose/execute pair each, but it does not supersede the lease design, because the two pull opposite directions on the same fact: an unreachable member is a reason to keep a group epoch and a reason to drop a carriage lease. Nor could carriage use it, since propose_epoch_pruning blocks on MissingCheckpoint and carriage has no projection to rebuild. Borrow the propose/execute split and the fail-closed ordering gate; not count-based retention, which needs the authorization the lease design refuses. And the sited radio has no carriage to lease: verified along the whole chain that carriage exists only for persona certificates, so the proposal's central TTL example described a device that cannot have one, an error the 2026-08-18 per-device amendment repeated. Carries two self-corrections: the "before it is ratified" framing, and a claim that graphshell consumed the retention engine when its only use is a retention_probe test that found pruning blocked and declined it. Finding 2 corrected 2026-08-18: its claim that "for any device that is a member, the group session is already a better channel than a replicated slot" was wrong and load-bearing, since the two deliver different key material and neither substitutes for the other.

  • epoch_carriage_lane_grammardecided 2026-08-18, with Mark: closes the last gate on the leased slots design. Two findings reshaped it before any grammar was written, both of the same kind, a named mechanism being wrong and the right one existing a layer down. Slot semantics are a protocol operation, not a store choice: muniment::SlotStore is local only, and what replicates is an append-only p2panda log, but stickleback already has the replicated form (HistoryAction::PruneBeforeCurrent, Admission::prune_before_current as "the surviving head of a pruned prefix", erasing_payloads in the same backend batch, PruneFlag + validate_prunable_backlink, and prune_proof.rs), which drop_io runs live, so the lease is the authorization for a prune the protocol already performs, not a new retention mechanism. And the topic is a privacy decision, because sync_overlay_topic records that discovery announces topic membership: a per-persona topic would let an observer reconstruct the persona-to-device association graph that the blinded index exists to prevent, so it is rejected despite matching carriage's real granularity. Ruling: a sibling topic BLAKE3(graph ++ CARRIAGE_TOPIC_MIX), the idiom sync_overlay_topic already uses, with the graph-versus-certificate granularity mismatch resolved by an explicit commissioning-time field on the roster's DeviceRecord rather than a derivation. Everything checkable lives in the header extension so a replica can accept, refuse and prune without decoding the body, and the certificate id is replaced by a blinded slot id under its own context, since publishing it on an announced topic would have reintroduced one level up the leak precondition one closed. The property that falls out: a replica does its whole job while able to name none of the personas it serves. Roster layering ruled 2026-08-19 (Mark): the wallet roster (personae DeviceRoster, home of CarriagePolicy) governs whether a device holds carriage; the pairing list (owner_settings paired_devices/roster_roots) governs whether it is reachable; the replica set is their intersection, the join is a pubkey-to-root lookup, and each absence stays visible in its own store. Admission is ordered fail-closed (topic, extension and expiry, three ceilings, issuer signature against one trusted root per persona, strict monotonicity, then the prune), refusing where ordering is unknown. Purge borrows epoch_retention's propose/execute shape but not propose_epoch_pruning itself, which gates on a checkpoint carriage has no projection to rebuild. First implementation landed 2026-08-19: graphshell::carriage (CarriageExt, lease sign/verify by trying each trusted root rather than publishing an issuer key, the six-step fail-closed admission as an OperationPolicy producing prune_before_current + payload erasure, and the pure purge proposal), pandect::blinded_slot_id under its own context beside blinded_epoch_index, and CarriagePolicy::{None, Leased{max_ttl_ms, graph}} on the roster's DeviceRecord with None the serde default (the chosen graph lives inside the Leased variant so a leased-but-laneless policy is unrepresentable). Ceilings refined: a bare replica can assert only the thirty-day backstop, since the device TTL and grant expiry are knowable only wallet- and holder-side; CarriageCeilings carries them as options and issue-side code passes both. Seven admission/purge proof tests plus a slot-unlinkability test. Host landed 2026-08-19 (graphshell::native::carriage_host): joins the carriage topic, rebuilds the slot view from the store at open, admits its own writes through the same policy peers apply so a ceiling violation is refused loudly at issue, and refuses expired on read even when bytes are present. The recovery done-condition is demonstrated end to end: two hosts over live sync, the replica learning the slot from sync alone and serving it back, supersession replacing rather than accumulating, expiry refused on read and purged on schedule. One correction the prune law forced: the log id is the slot itself, because PruneBeforeCurrent deletes within its log and a shared log would let one slot's supersession destroy another's live version. Issue path landed 2026-08-19: publish_grant_carriage walks the roster and publishes a slot per leased device per epoch-carrying persona certificate, signing with the persona chain root and passing full ceilings per call; skips are reported rather than erred (no retained wrapping key, no record, grant expired). The commissioning test runs the real machinery end to end, pairing issue through live sync to a peer recovery whose record the pairing key opens. Revocation fast path landed 2026-08-19, as retraction by supersession: the ruled statement-driven destruction cannot exist under blinding (a replica cannot map a DelegationId to a blinded slot, and the wallet deletes the wrapping key during revocation), so the issuer publishes an empty record over the slot and the grammar's own prune destroys the material on every cooperative peer in the same batch; a retraction index written at publish time is what keeps the slots addressable after the key is gone, and a peer never reached still converges at expiry, ruling 5's posture unchanged. Proven through real revocation with the lease hours from expiry. Endpoint fold landed 2026-08-20 after Mark challenged the blocker: the append form already existed in the owned p2panda fork (AddressBook::add_topic), murm exposes it as add_topics, and CarriageHost::attach joins the carriage topic on the sync host's bound endpoint, sharing its node id, ticket and pairing; both lanes proven converging between one endpoint per device. Nothing on the carriage design remains open.

  • epoch_carriage_retention_leasesratified 2026-08-14 by Mark, amended 2026-08-16 and 2026-08-18: scopes the replication doc's ruling 4 (retention gates shipping). The threat sharpening that drives it: a live-stolen device already holds its unwrapped secrets, so replicas add nothing against it; the replica-specific attacker is a wrapping key without live state (cold theft, leaked pairing secret, old backup), for whom the replica set is a second keyring copy purge_deleted cannot reach. Locally that copy does not exist, because rotation already replaces rather than accumulates. Ruling: carriage replicates as a leased slot, never as history: mandatory issuer-signed expiry under three ceilings (the device's own carriage TTL, the grant, a stack-wide backstop), monotonic destructive supersession (late replacement cannot resurrect, signalman's rule), holder enforces expiry on read and on the purge pass, and revocation-statement delivery is a latency optimization rather than a dependency, which decouples the design from retinue's open mesh revocation-propagation question. Claims bounded convergence on cooperative replicas only; uncooperative peers are governed by the crypto alone, stated plainly. Amended 2026-08-16 with the four findings of the stickleback review: the transport exists (H7 personal_sync) and the gate is a sibling topic beside the graph grammar, not a transport; a new section draws the boundary against graph_keys' per-device key group and records the retirement question as open; a new section says why stickleback's retention engine is not adopted (opposite direction on offline members, and a MissingCheckpoint gate carriage can never satisfy) while its propose/execute split and fail-closed ordering gate are; and the sited-radio TTL example is retracted, because carriage exists only for persona certificates. Settled 2026-08-18: the retirement question the 2026-08-16 review left open (whether a group-member device needs carriage at all) is answered yes, it does, and not by the lifecycle comparison the review called for. The two mechanisms never carried the same thing: the group session distributes one graph's DataKeyring, sealing PersonalGraphEvent bodies on the lane, while carriage distributes one persona's private epoch secret, which WalletEpochSealer turns into the key sealing that persona's eidetic payloads at rest. Different granularity, different thing sealed, no shared root, and neither module references the other. So a seated device can read the lane and still not open the persona's store, and the lane serves the full population of persona-certificate holders rather than a narrowed one. Noted on the way, and since closed on 2026-08-19: WalletEpochSealer was constructed nowhere outside its own tests, so carriage delivered material for a seal path that was defined but not live. It is now supplied by castellan::authority::PersonaeHost::payload_sealer (the keeper already holds the carry root, so nothing else must learn where the wallet lives), with access records as first consumer via save_access_record_sealed / query_access_records_sealed, proved by three tests: no cleartext survives in the blob bytes for a LocalOnly record, a reader without the epoch refuses rather than reporting an empty history, and a PublicPortable record stays cleartext under the same willing sealer.

  • device_grant_delegation_reconciliationdecided 2026-08-11: the question W3 spun out, answered now that castellan's sited-station adapter made it concrete. Ruling: converge, as a split. Four findings drive it: the principal gap is a newtype rather than a model difference (the grant's delegator is already DevicePublicKey::from(provider.master_public_key()), so it is persona-master-to-device already, and DevicePublicKey has lived in personae::carry one module from delegation since W1); the envelope does two jobs, proven by refresh appending wrapped epoch material and re-signing an unchanged capability, churning every tracked grant_ref; revocation cannot travel, because roster.revoked is a local list and not a statement a mesh peer can verify, which is exactly the gap the sited-device brief could not close; and personae::delegation documented the division of labour (it owns the grammar, not an application's grant ledger) which the wallet then crossed by authoring its own statement format. The split: capability statement becomes a SignedDelegationCertificate (scope atoms become actions, no-subdelegation becomes remaining_delegation_depth: 0), wrapped epochs leave the signed envelope for their own certificate-keyed record, revocation gains SignedDelegationRevocation and the roster demotes to a local fold. Verified against the code that this needs no change to personae. Costs stated: a wire migration off the pinned 612-byte fixture, one certificate per persona (which is the better revocation shape), and a small re-target of the station adapter. Posture decided 2026-08-12 (re-issue now, no legacy decoder, because no station is sited yet); execution in the migration plan.

  • crypto_stack_decisiondecided 2026-08-10: the crypto-library decision that had never been written. RustCrypto for primitives, dalek for curve25519, one generation across the workspace. Records that the stack was never chosen but inherited three times over (iroh/p2panda pin dalek, Reticulum's spec dictates primitives, Cable brought BLAKE2b), that the only prior rationale was an open question closed silently by a code comment, and that the library question is largely foreclosed while the generation question was live. Rules: bump the row not the crate, pin the row in [workspace.dependencies], never implement primitives, constant-time comparison is explicit, transitive other-row deps are tolerable and first-party ones are not.

  • crypto_generation_unification_planDONE 2026-08-10: executes that decision. Seven pins across six manifests onto the digest 0.11 row; one source change (new_from_slice moved MacKeyInit, and HmacCore still overrides it so variable-length OTP secrets are unaffected). The invariant that mattered: personae::seal's output is now pinned byte-for-byte and was verified identical under both generations by temporarily reverting the manifest, so existing sealed vaults and wallets open unchanged. Residue: every remaining 0.10 consumer is third-party transitive, plus misfin (separate repo) and the ed25519-dalek 2/3 split.

  • sited_device_identity_briefresearch brief (2026-08-10, with Mark): castellan issuing derived, ephemeral identities for radios that will be sited unattended and eventually stolen. Two findings reshape it: signalman's identity is a file that literally is the account (postilion: "The file is the account"), which is the thing to replace with a RemoteAuth device grant; and retinue's flash-policy.toml already forbids persisting latitude/longitude on a node, which resolves the map half rather than blocking it (the node does not know where it is, the host knows where it put it). Those host-side placement facts are exactly the radio fact surface the projection plan's P5 deferred for want of one, and Atlas is already reserved for the geographic arrangement.

  • conatus_nexus_alignment_briefresearch brief (2026-08-10, with Mark): one physics stack across conatus and the isometry wing, against dimforge's transition (rapier = CPU incumbent, nexus = "rapier on the GPU" via rust-gpu/WebGPU). Verified: the only rapier in the ecosystem is inside seiche; quint's GPU lane is already Burn (unchanged); isometry is physics-greenfield and adopts the seam rather than migrating. Frame: three seats, one contested (seiche's integrator becomes pluggable; rapier default; nexus behind a feature). Ruled 2026-08-12: determinism is NOT required for the isometry wing — the multiplayer truth is key replayable facts replicated to hosts/guests (murm/stickleback/codicil rails), simulation between facts is local color, and nonessential divergence is worth GPU throughput. Rapier is not preserved for determinism; A0 answered 2026-08-12: nexus contains rapier (rapier 0.34 + parry 0.29 are its direct deps), so composition holds by construction — the seam targets nexus and lets it carry rapier; seiche's pin aligns to parry 0.29 at A1. Renderling is genet's SurfaceEngine lane, deliberately out of scope.

  • conatus_engine_planactive (2026-08-22); scope corrected 2026-08-23 (ruled by Mark); brick ownership landed 2026-08-26 as modulus: the shared spatial runtime plan; body/runtime foundation implemented (generational identities, fixed/dynamic/kinematic bodies, voxel collision edits, character movement, fixed-step clock, phased schedule, serializable command buffer). The correction settles the engine-stack review chain: product runtime profiles conduct (clocks, triggers, authorization, source bindings, subsystem selection) while Conatus advances spatial state; Seiche stays the 2D graph specialist; the render view narrows to a lean spatial frame without cameras, lights, sprites, or presentation policy; scripts and peers submit product intents, never raw BodyCommands; source bindings are profile-owned; and the extraction rule splits — mechanics may move early under settled ownership, cross-product contracts wait for a second consumer (reconciling the plan with the wing's two-consumer law). Status advanced 2026-08-26: Mesocosm's runtime is the first product tactile consumer, quint's resident join is receipt-proven, and the brick crate (now modulus) advanced on its lift branch. Carries the ruled consolidation map (2026-08-28): realms own truth, two engines (projection; inference coupling analytically and generatively), physics as a stratified capacity, the host out of genet/cambium, and the Nexus decomposition.

  • runtime_composition_acceptance_planactive acceptance ledger (2026-08-23; DDA promotion gate closed 2026-08-26): defines the engine as a product runtime profile's composition rather than a universal crate; assigns durable rules, cadence, input, tactile bodies, voxel mechanics, resident fields, DDA, scenes, device tenancy, inference, assets, audio, replay, diagnostics, and packaging to their natural owners; records Conatus 5767563c, Mesocosm's first voxel-mechanics consumer, and Isometry's first profile slice; and makes the second heterogeneous consumer an executable gate before any conductor, identity, frame, trigger, or lease contract becomes stack law. Ledger advanced 2026-08-26/27: the tactile row is met by Mesocosm's T1 adapter, the resident row is epoch-validated by V1b, and the DDA row's owner is selected (conatus-brick, on its branch); cross-product identity contracts stay gated.

  • scenograph_expansion_briefresearch brief (2026-08-10; reconciled 2026-08-20): the Scenograph expansion map. The published 0.0.3 release remains historical and 0.0.4 is the development line. L1's Woodshed data half is founded; L2 backdrops are landed through Isometry, Woodshed, and Graphshell remote realization; L3's first-device arrangement proof is met while the common shelfmark format waits for a second consumer; L4 retains projection captures; L5's first continuous reprojection is landed.

  • scenograph_content_catalogscene-recipe catalog (2026-08-18; reconciled 2026-08-19): the dependent collection of complete scenes composed from the projection grammar. Ten scene recipes sit beside four lever decks. Grid, Columns, Plotted, and Tabletop are disambiguated; Body and Face remain orthogonal; structural edge forms are separated from Flow motion and Ghost previews. Rosette is landed through Knot over poem and lyric datasets.

  • scenograph_lane_handoffsdispatch document (2026-08-18; reconciled 2026-08-19): Lane C Rosette is complete; L1's data half is founded; its verified-entry snapshot records early 0.0.4 and Score v3. Score v4 now carries the expanded arrangement catalog. A future scene-recipe surface depends on the grammar/compiler types, while sceno remains product-free and selection remains Chirograph/ViewIntent state.

  • eidetic_reorg_planopen (2026-08-12, authorized by Mark): dissolve the never-published mere-embed orphan into the two homes its halves always had — persistence becomes eidetic-core's vector module behind a vector-index feature (its lib.rs already names vector indices as an own-schema lane; esp's default features are empty so the dep is serde-only), and the quint field-bridge/canvas-search pair moves to the canvas cluster. No shim needed (never published). Fetchers stay crates (real dep walls). Lands as one commit when the tree quiets; W4 consumes the new homes.

  • search_surface_wiring_planopen (2026-08-12; lexical n-gram, fusion, and URL-field probes 2026-08-31): leverage-census step 2 as a plan. Audit half done: mere-embed is not a husk (esp re-export + three built-but-unwired glue modules: persistence, field bridge, canvas search; "retire" closed), and the real precondition is capture — nothing authors BrowsingTrace, so recall has no corpus. Slices: W1 turnstone trace capture, W2 omnibar recall, W3 fast-field reports, W4 canvas semantic search through embed's quint bridge (lexical provider first), W5 reciprocal-rank fusion of the two rankings. The W4 input probe keeps exact unigram compatibility and adds explicit token n-gram orders; 1+2 moved Ranking@1 from 7/15 to 15/15 with unchanged dense storage, while trigrams added no win. The real BM25/RRF follow-on found eight equal-weight top-score ties; V3 now retains exact stored URLs while indexing tokenized URL components, closing the titleless-URL Ranking@3 gap through an explicit re-mint. A vector-heavy weight clears the forcing fixture but is not a default. Live host wiring, a captured-trail partition, and a learned-vector baseline remain open. Extracted text enters through the host capture path; eidetic-search consumes traces and does not own a direct Fleece dependency.

  • castellan_otp_planC1 done 2026-08-10; C2 done 2026-08-21, library-complete: castellan's first real slice, the OTP core at ports/castellan/src/otp/. HOTP (RFC 4226) and TOTP (RFC 6238) across SHA1/256/512, hand-rolled RFC 4648 base32, otpauth:// Key Uri parsing (issuer-prefix vs issuer= reconciliation, unknown parameters ignored), constant-time verification with a skew window. All 28 published RFC vectors green; Otp redacts its secret in Debug and exposes no accessor, which is the chatelaine rule enforced at the type. C2 landed 2026-08-20/21: sealed OtpItemStore items, OtpCodeTile and OtpReleaseGate, the Notochord-admitted session consumer, an exclusive resident lock with an authenticated freshness ledger, Freedesktop Secret Service 0.2 on Linux (secret-tool receipt on the ThinkPad), and Steam Guard compatibility. Open: hosting CastellanResident in a product (graphshell enables only keeper), credential replication between persona devices, CXF import.

  • wallet_carry_foldin_planCOMPLETE 2026-08-10 (W0-W4): the 2026-07-08 carry fold-in, executed and narrowed by doing it. personae::carry took the model (wallet manifests, device roster, epoch records, derivation, CarryRef byte-identical to the eidetic::Hash string form so no disk format changed and personae stays eidetic-free). Three pieces deliberately stayed in mere: the store adapter (sequenced filesystem effects), WalletEpochSealer (it is the seal seam), and the capability grants (they would duplicate personae::delegation). wallet_store and wallet_grant both split under the 600 ceiling. Spun out: should a device grant become a SignedDelegationCertificate? Needs its own brief.

  • credential_port_gazette_briefresearch brief (2026-08-10, with Mark): the dramatis tier's two outward surfaces. Part I: the credential-manager port (split architecture: embeddable browse half vs resident-only authority half through the gate; standards inventory TOTP/HOTP → CXF → Secret Service → KDBX → WebAuthn provider, with Secret Service flagged as the one OS surface a third party can be; prior art Stronghold/keyring-rs/KeePassXC; differentiator = persona separation + serverless seed carry + agent-first + library packaging). Part II: gazette from resolver to reading room (persona-handle-as-capability makes trust-tiered reveal work with anonymous WebFinger; the friend-feed pipeline is gazette discovers → nematic parses → eidetic stores → trail composes, four existing owners; open-read survey of RSS/gemfeed/AP-outbox/atproto/nostr with the authorized-fetch caveat). Readiness order: wallet fold-in, then TOTP + Secret Service, then gazette async + feed endpoints.

  • dramatis_tier_planratified + D1-D3 executed 2026-08-10; D4 done 2026-08-21: crates/persona/ (historical citation) renamed crates/dramatis/ (dramatis personae; dodges the in-product term persona); gaz subtree-merged in from its standalone repo as the tier's stored-contact crate; bare dramatis claimed on crates.io as a facade reservation. D4, deferred with anchors and since done: the wallet fold-in from session-runtime (complete 2026-08-10) and the credential-manager port, founded 2026-08-14 as castellan with C1-C2 complete 2026-08-21 (embeddable browse half, resident-only authority half through the participant gate; standards runway TOTP/HOTP → CXF → OS credential surfaces → WebAuthn provider). Only the empty dramatis facade reservation remains.

  • knot_authoring_consumer_plancomplete locally 2026-07-27 for Knot-owned work: Graphshell editable text and typed Save; retained Turnstone Cambium authoring; file, personal-vault, and Commons writes; stale refusal and revision refresh; typed Inspector clipping; consented Resolve/Run with rooted file, anonymous HTTP(S), read-only smolweb, sanitized HTML, and sealed attributable resolve caching. Faithful selected-range clipping is explicitly gated on Genet retaining selection and producing a stable DOM-range selector; Knot already records one when supplied.

Several older plans here carry a 2026-06-09 rename-key banner: their bodies use pre-pivot crate names (e.g. mere-host, graph-canvas, Cable/BLAKE2b) as dated receipts. The banner gives the current mapping.

  • protocol_architecture_plan — iroh-toolkit layering, identity vault, WebFinger self-host, primitive moot nodes. (Substrate sections superseded by p2panda; banner.)

  • identity-vault-ssh-agent_plan — continues the protocol plan's §3: wire personae's existing vault skeleton (slots/lineage/tiers + the production-exercised at-rest layers) into a working credential vault, then an SSH-agent front end (ssh-agent-lib, Windows named pipe + Unix socket) with the Windows→Linux-laptop session key as the first dogfooded credential. V1 durable storage → V2 agent → V3 CLI → V4 item types → V5 sync (deferred to the moot refactor). Gated on the auto-update brief before any load-bearing deployment.

  • event_dag_substrate_brief — substrate pivot: event-DAG identity, BLAKE3, schema-at-engram-boundary, sync-as-projection. (p2panda executed; banner. §6 Veilid retired 2026-09-01 in favour of the reachability plan's privacy lanes.)

  • moot_tiers_and_voluntary_hosting_brief — tier framework (orrery → moot → moothold → coalition), voluntary hosting + reputational stakes, cheesecloth pinning.

  • post_engine_layer_priorities — forward plan after the engine layer landed. (gpui-era snapshot; banner.)

  • graph_cluster_namespaces_brief — namespaces derived from the graph's community structure (Leiden/Louvain), not admin paths; capability-scope mapping.

  • engine_profile_boundary_plan — graph-truth vs engine-profile bytes; per-persona/session/graph UDF path resolution.

  • session_service_runner_plan — sessions declare background workers behind a SessionServiceRunner capability; v0a landed.

  • short_term_memory_substrate_plan — substrate-per-short-term-consumer (JSON sidecars vs in-memory); branch/fork state. Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

  • net_media_plan — the media organ (sibling to netfetcher/netrender): WebRTC media tracks + AV1 decode, three-tier asm-free decode policy; browser data-channel carriage moved to the browser WebRTC carrier plan.

  • host_wiring_grabbag_plan — the host cheap-path plan's spun-out C6: eight remaining genet/xilem-serval host-wiring items in two phases. G1 composition-runway (on_wheel view, transform-aware hit-test, pointer cancellation, memoize) feeds window_composition P2+; G2 host-completeness (IME, environment threading, keyboard escape hatches, chrome a11y actions). (Genet-side complete 2026-06-12; 6 wired / 4 runway at the meerkat layer: G1.1–G1.3 + G2.3 await window-composition P2+ adoption, while G2.1 IME + G2.4 chrome a11y actions have live meerkat callers.)

  • genet_render_glue_extraction_plan — pull the ScriptedDom -> netrender::Scene render glue meerkat consumes from pelt-live (a genet-side probe) into a meerkat-owned genet_render module that calls genet-layout + paint_list_render directly, and drop the pelt-live dep. Fixes the inverted mere→genet-port dependency and ends the shared edit-surface collisions; zero genet changes (pelt-live stays the probe). Unblocks the cheap-path plan's C5-remaining + C6 genet items.

  • scrying_tile_plan — land external web content (flip P4 / integration S6): a ScryingHost on the UI thread spawns system-WebView producers via the existing scrying-engine factory seam, imports their GPU frames, composites via compose_external_texture; X1 Windows-first.

  • modular_integration_planhistorical Meerkat/browser integration record; Mere-wide authority superseded 2026-09-05: preserves the graph-rooted browser design and dated execution evidence. The platform-boundary plan now owns Mere/Genet placement and independent product roots; the Workbench and port-contribution plans own current application composition. This is not the current integration queue.

  • actor_constellation_plan — single-threaded kernel + I/O/content/compute actors (Servo's constellation done in-process; scenes travel as messages). Archived 2026-08-20: spine complete 2026-06-04, P3 re-homed to the scripted tier and genet's event-loop work, P6 to the mesh family.

  • runtime_mod_authoring_loop_plan — the "theme-changing ergonomics, but for extensions" loop: Rhai command packs as local snapshot-in/action-out automation; Wasm component mods as the portable untrusted WIT boundary; a Meerkat pane for model-assisted edit/check/build/load/run/reload.

  • commitment_proof_interface_plan — shared proof surface for moot epochs, tessera receipts, kith grants, storage checkpoints, and mesh result evidence: typed commitments and proof purposes over Merkle/sparse-Merkle/MMR/accumulator/vector/PSI backends, with p2panda operation hashes kept separate from application proof roots.

  • personal_mesh_substrate_m2_planlanded 2026-08-09; archived same day. M1's convergence proof became a bounded execution substrate: JobPostedV2/JobDoneV2 beside the frozen M1 variants (a mixed replica set converges, and an M1-only checkpoint snapshot still hashes to its pre-V2 bytes), an extensible ResourceId, a host-built JobNamespaceView whose four negatives are tested, one registry that also owns the Echo/Blake3 compatibility adapters, and esp.embed.lexical/v1 proven two-peer over real p2panda-net. VerificationClass::ExactBytes was earned by running the same codec on wasm32 under Node, not asserted. Three deferrals (peer blob delivery, tolerant comparison, V2 blob retention) carried into §7 of the lease scheduler plan.

  • mesh_lease_scheduler_planlanded 2026-08-09 as the lease protocol floor; archived same day. The M3a authority gate was decided against the plan's own recommendation: the job author signs a LeaseTerms envelope once at post time and the deterministic claim winner grants itself a lease inside it, because author-grants-each-lease stalls every job whose author closed the lid. The fold keeps lease facts with no clock at all (signed timestamp against signed timestamp, both ends of the claim-eligibility window closed); liveness is a separate job.lease_at(now_ms, &policy). Owner reclaim outranks everything and reads as a device fact, never worker unreliability. Read "complete" narrowly: the algebra is real and tested, but no shipped binary supervises running workmesh-peer declares DevicePolicy::unsupervised and the worker refuses to hand it leased jobs.

  • mesh_host_lanes_planopen; H0-H2 and the lease-bound Distillery remote consumer are complete: mere-mesh-host supervises non-blocking work, publishes authenticated blob locations, refuses unsafe checkpoints, and drives Distillery's owner-controlled collection and plain-WGPU Burn Remote resource. Collection protects the accepted checkpoint plus current replay tail and releases only mesh-scoped custody. Tolerant comparators, portable checkpoints, reliability accounting, and the first training resource remain consumer-gated.

  • autodiff_lora_trainer_plancomplete 2026-09-03; receipts rerun on the rebased tree and on the Fedora ThinkPad: replaces the v0 trainer's central finite differences with Burn autodiff while keeping the PEFT adapter bytes, the loader, and the exact FLoRA stacker unchanged. Finds that ESP's decoder sits on Burn's dispatch backend, so autodiff arrives by wrapping the device (Device::autodiff) rather than a B: AutodiffBackend generic; that Param::from_tensor tracks every base weight unless detached; and that FLoRA rounds are trainer-version homogeneous by the stacker's own checks. Four phases: ESP trainer with a gradient check against v0, Distillery request arm, Djinn CPU/GPU lane, receipts.

  • distillery_v0_planD0/D1/D2 receipts complete; installed port and trainer in progress 2026-08-26; the trainer gained its autodiff arm 2026-09-03 (see the autodiff LoRA trainer plan): Distillery is the first real mesh-host consumer, owns resident lifecycle and owner-triggered retention composition, and proves lease-bound plain-WGPU MiniLM, cancellation/reclaim, allocator cleanup, driver release, and immutable ModelSession/PEFT LoRA parity. The installed slice now persists an explicit Personae profile, derives its mesh authority, exposes a configure/inspect binary, and supplies a read-only Cambium contributed surface; its exact-source library tests, binary check, and package Clippy gate are green. Turnstone registration, operational host policy composition, the deterministic trainer fixture, model browsing, streaming console, and full workspace gate remain open. Components founded 2026-09-02: ports/distillery/{alembic,athanor}, reservation stubs, no lane opened.

  • distillery_projection_walk_planW0 complete; W1 direct, admitted-carrier, and headed WebRTC fixture paths green 2026-09-06; readable layout and live-resident path open: Distillery owns the session-bound Chronicle endpoint plus a session-free shared observer for materialization, card resources, notices, and retained diff history. Graphshell owns the mount, same-session rediscovery/resume, and a frozen table whose generic presentation details expose observation tick and lease spans. The admitted test drives a signed MemoryTransport session through ResidentProjectionHost::accept_one, transfers and validates all six card resources around the revision 11 to 12 diff, applies it in ClientState, and freezes the served table. The headed Chrome fixture proves real WebRTC admission, revision 11, three mounted remote cards, session selection, and capture; the capture also shows the three card geometries overlap into one unreadable block, so it is transport/mount evidence rather than readable-Chronicle acceptance. A fresh admission mints a fresh projection session, so cross-admission continuation needs an explicit protocol contract and is not claimed by the current receipt. The board and resident receipts cannot reconstruct historical job spans because neither correlates a JobId with a posting tick; W2 therefore needs an owner-supplied event journal if it retains that claim. W3 Circuit remains the prospective A5 schematic consumer, and W4 still requires Graphshell and Distillery's independent host receipts, with Turnstone third.

  • burn_0_21_baseline — the "before" the stable Burn 0.22 migration gets diffed against, captured 2026-08-10 ahead of the release so nothing has to be reconstructed once APIs move: environment, the two remaining direct Burn dependents, the Burn-free default ESP tree, the per-feature native/wasm matrix, CPU suites, and real-hardware WGPU parity. Also records what could not be run — the model-backed receipts, MERE_MINILM_DIR being unset — so the 0.22 comparison cannot mistake a never-green receipt for a regression.

  • lease_bound_remote_sessionsimplemented through the supported plain-WGPU Distillery row: Burn Remote mounts on Mere's endpoint, accepts a signed live-lease projection rather than a bearer token, interrupts live requests on close, orders stop before reclaim, drains sessions to zero, and recovers under a fresh lease. Fusion/autotune remains an upstream compatibility lane; portable remote checkpoints remain open.

  • kith_capability_sharing_plan — first trust-widening slice: kith/kin grants, revocation/expiry, namespace caps, live capability refs versus offline signed proofs, and board-level claim validation before any economy. Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

  • mere_turnstone_boundary_pass_plan — sharpened the Mere/Turnstone boundary and executed the host promotion. Its 2026-07-09 decision to keep the generic eidetic typed-memory crate Mere-side is superseded by the Graphshell boundary audit, written after the Eidetic family repository was founded.

  • eidetic_on_muniment_planlanded 2026-07-12; archived 2026-08-06. Rebased eidetic onto muniment rather than letting two crates declare the same storage boundary: eidetic::Store survives only as an alias for muniment::Backend, and eidetic-fjall became a backend the whole family can reuse. Also recorded the correction that the boundary pass never forbade eidetic depending on muniment; it named that rebase as the destination. Its one live tail, mooting adopting eidetic-fjall, is in the archived-plan tails backlog.

  • murm_peer_runtime_and_moot_domain_planactive replacement for the sibling posture: Murm becomes the reusable peer-exchange family; murm-replication owns the shared p2panda session, processor, muniment store, retention mechanics, and native drop; direct conversation, Moot, and mesh supply domain schemas and policy; Moot becomes a governed-space domain over the lower replication crate; Mere stays offline-first and Turnstone stops assembling LogSync. The earlier sibling plan remains as completed-work history.

  • murm_moot_sibling_posture_plansuperseded 2026-07-12 by the murm peer-runtime and moot-domain plan; archived. Reorganised the comms families as siblings, consolidated the triplicated log-sync substrate onto upstream p2panda, and executed the naming payload. Its R/N/S receipts remain historical implementation evidence, but the sibling purity rule, the host as sole composition point, and the standalone-package boundary it targeted are all retired.

  • iroh_p2panda_bump_plansuperseded and executed 2026-07-17; archived. Planned forking iroh and p2panda to move retinue onto the final crypto line; upstream released first, so the fork never happened. Mere runs p2panda 0.7.0, iroh 1.0.2, iroh-blobs 0.103, and iroh-tickets 1.0, accepting the upstream wire: operation headers omit timestamps and use u32 sequence/payload sizes, and p2panda-net session frames use postcard while core operations stay canonical CBOR.

  • stickleback_replication_promotion_plancomplete 2026-07-27; stickleback 0.1.0 is published on crates.io. S0 froze the contract, S1 cut the path/package over, S2 deleted the transport facade (which left transport with no replication dependency at all), S3 passed the publishable-boundary review and added the neutral ledger example. 291 tests green, wire formats unchanged, no forwarding release needed, murm-replication 0.1.0 deliberately not yanked. A sibling repo stays gated on a real external consumer. Promotes the already multi-consumer murm-replication runtime to Mere-owned stickleback: one behavior-preserving path/package cutover, direct Murm/Mesh/Moot/transport consumers, domain authority kept in each domain, and no sibling-repository move without an external consumer.

  • stickleback_s0_contract_freeze_receiptS0 receipt; S1 has since landed: the frozen consumer/export matrix for all 66 murm-replication exports, all classified generic (no public type carries Murm grammar, so nothing moves back). Four findings shape the cutover: the mere-transport::synced_space compatibility module already has zero callers, the ReceiptPeer KDF context string contains "murm" and must survive S1 unrenamed, CheckpointAuthority is declared in the shared crate but enforced domain-side, and Murm's gossip_sync SyncStatus/SyncRound are separate types that must not be unified. Boundary fixtures in tests/boundary.rs are the tripwire.

  • deletion_retention_and_native_drop_planD0/D1 landed; mesh D2 landed; D3 framing/protector seam landed; generic D4 complete; mesh and conversation mappings landed; direct Murm runtime consolidated: one deletion/retention law for p2panda-backed spaces plus a BLAKE3-native asynchronous drop carrier. Mesh proves checkpoint + tail replay, typed snapshot commitments, atomic body erasure, p2panda prefix pruning, and settings-driven catch-up/archive/radio selection without per-object tombstones. Direct conversation adds per-author-frontier catch-up, independent signed-header/body privacy, and a Murm-owned engine over ConversationStore; local sends, gossip receipt, and LogSync now share the muniment authority. The duplicate CableEngine, cabal stores, hand-written redb LogSync adapter, and murmuring package are deleted. murm-replication owns bounded public/protected framing, domain-driven blob collection, atomic staged import, content hydration, caller-driven stage controls, explicit file carriage, peer-scoped receipt statements, and the injected privacy/priority selector with byte budgets. Production group encryption, live peer command wiring, durable conversation reopen, drop-import view refresh, the Moot mapping, complete reference tracing, and the live Moot constitution fold remain. Iroh and Retinue stay opaque carriers.

  • one_node_facets_layer_mapruled and executed: one node — chartulary::Container is the neutral node and the kernel Node has dissolved to a Container wrapper plus explicit content-addressed image-reference residue. "Web page" is a turnstone-defined content class; the browser dogfoods the facet system. Atomic facets hold all other node metadata (compile-time capability traits + runtime schema-validated facet records; custom content classes = facet bundle + schema engram, shipped as packs, gated). Amends the north star: OQ 5.4 resolved-redundant, OQ 5.1 closed 2026-07-27. 2026-07-22 boundary amendment: Conatus now owns numen/quint/seiche; generic scene contracts and analytic arrangements go to Scenograph; mere-cartography and kernel-aware mere-canvas stay Mere-side; shared interaction promotes through Cambium/Sprigging under the Woodshed consumer.

  • projection_proofs_plan — executes the projection_engine_prior_art_brief's five proofs. P1-P5 landed: Turnstone wires the analytic catalog; sceno owns spaces, footprints, scene instances, regions, routed relations, and Score v3's Spiral/Grid/Geographic/Hulls arrangements. Mere persists projection-score.json; Isometry emits its authored tile grid through the same score/scene types; P5 ships the coastal_map.json fixture. The naming register now distinguishes portable Grid, local categorical Columns, future Plotted coordinates, and the complete Tabletop scene.

  • shelfmark_format_noteruled 2026-08-16; founded 2026-08-23 through Wave 1: the scene citation is shelfmark, housed in incipit. ShelfmarkV1 names the projection and an ordered map of authority/reading inputs, each with its own expected generation and optional reconstitutive parameters; target-owned delta sections remain opaque to the envelope. Mer3ly's composed Matrix and Gazette's Ledger force and replay the shape. The exposure audit found no emitted collapsed-name registry id, so no alias machinery is currently required.

  • scene_citation_index_briefthinking brief 2026-08-16; all five questions ruled same day (see shelfmark_format_note, now the authority): reads mer3ly's scene-state wire as a scene citation, the index layer above the projection contract (realized scene / score / citation). Anatomy: authority cite + projection cite + authored delta + envelope; citations are checkable because score.generation derives from the authority hash; two resolution modes (reconstitutive vs referential); A6 changes a citation's fidelity, not its schema. Kept as the reasoning record behind the ruled note.

  • mer3ly_stack_consumer_surveysurvey 2026-08-16, commissioned by Mark before re-gating the adoption plan: what the public site (repos/mer3ly, mer3ly.net) actually consumes from the projection stack. Six Mere crates pinned at 8a7ede70 plus cambium/genet-scripted-dom from crates.io; mere is 112 commits ahead but only one touched the scene crates and it changed a doc line, so the 0.0.3 freeze is holding under a live public consumer. Central finding: the site consumes the stack along two disjoint paths (a portable Score/solve/diff-trace path with no coordinates, and a live seiche path with pins, mobility, and backdrops that never reaches a Score), so it built its own wire, mer3ly.graphshell-scene-state/v1, base64url in a URL hash, carrying five fields the contract lacks (motion, backdrop classing, physics, selection, pinned coordinates). L3's second-device gate is already met in production. Target-by-target verdicts re-gate A1-A4, B1, and C3, and correct four claims from the 2026-08-18 first pass. Three questions open for Mark: authority-grade vs donor, whether the missing seam is its own target, and whether the site's wire is a promotion candidate.

  • projection_grammar_cataloggoverning primitive catalog and boundary map (founded 2026-08-15; reconciled 2026-08-29): defines the projection stack and grammar used to build scenes. The dependency is projection grammar -> scene recipe -> product adapter/authority. Score v4 carries the expanded arrangement catalog and per-item disclosures. C3's minimum source-backed, visible/collidable, hit-transparent backdrop contract is closed; richer basemap resources, rasters, and scalar field semantics remain consumer-gated. The promotion suite is an evidence harness founded by a named first proof consumer, not a substitute for the catalog's required second heterogeneous consumer. Signalman's FT8 receipt confirms mixed realization composes through Cambium's existing graph_canvas, without adding a portable grammar primitive. The 2026-08-23 follow-on owns the revised scene judgments. The content catalog depends on this document rather than being superseded by it. A third external-prior-art shelf (2026-08-28, Ink & Switch: PlayBook, Drawdeck, Portemine, Potluck) covers readings, bindings, and overrides as tangible scene material — flux as a reified reading, slot/card/whisker as drawn binding and provenance, overriding as spatially reversible intent.

  • port_gui_composition_and_comparable_stacks_briefresearch brief (2026-09-02, from Mark's assessment ask): where the port GUI story stands against the Cambium+scenes platform (two ports with surfaces, two with endpoints, none end to end; the census §6 seam; ten scenes on paper, two with consumers); meerkat read from the harvest (what carried, the focus card as a Cambium primitive, "drawer" as new vocabulary); the crux stated as readings + recipes + the nine questions, no inference; and eight comparable stacks (AT Protocol, Holochain, Urbit, Solid, Willow/Meadowcap, Spritely/OCapN, Anytype, Plan 9) with the lines each drew — none carries inference as a layer; the strongest borrowings are placement tests. Records the 2026-09-02 rulings: Graphshell's charter, Scenograph as the manipulator, Alembic into Distillery.

  • projection_grammar_adoption_planactive gated plan (2026-08-15; reconciled 2026-09-01): B1 is definitively closed at clean Turnstone 648bf19, including routed screen-reader interaction. A2 resolution is closed through the headed spatial/Matrix crossfilter receipts and Gazette replay. FT7 closes local, admitted remote, and frozen Matrix parity at Mere platform commit 302bbe72d7597b7573e14199ce926bd3b03eea7f. FT8 closes mixed realization in Retinue Signalman 8cea8f9. A3 stage two waits for a remote viewer with a local camera over a served scene (gate sharpened 2026-09-01 against C4a; C4b is not it; fact transport ruled: evaluation without host facts is the baseline, carrying them the stretch). Embedded apps ruled per site: merelyllc.com hosts Graphshell embeds, mer3ly.net embeds the full applications, Graphshell first, superseding the site's own canvas and serving as the site index (a new objective). The served Mere endpoint is ruled to select from the ladder at declared zoom rather than hardcode Card. A5 remains gated, with Distillery W3 named as its prospective schematic consumer pending the W3 entrance check; the promotion suite begins with that proof and every portable addition still requires a second heterogeneous consumer.

  • license_sweep_planplanned 2026-08-22, confirmations settled, P0 tooling not started: carries the license posture brief's ruling (MPL-2.0 by default, correct provenance, no exceptions) into every owned repository without code changes, bumps, publishes, or edition migrations. Invariants: provenance before license (a file gets Exhibit A only if Mark wrote it; everything else is ledgered in a per-repo LICENSES.md), Exhibit A never Exhibit B, one LICENSE per repo, header shape C with the notice Mark Alan Boykin, never sweep a dirty tree, no license-only republish. Phases: P0 header tool (scripts/relicense_headers.py, dry-run / apply / audit, line endings preserved) + ledger template; P1 mere (gated on a clean tree and the genet-layout patch being retired); P2 genet (all ~18 own permissive manifests, cambium/meristem with retained Apache notice, Servo files get bare Exhibit A); P3 isometry; P4 turnstone/woodshed/hocket as each tree comes clean; P5 wavicle, mora, gaz; P6 documents. Each phase has grep-level done-conditions and an --audit receipt. P7 (ruled 2026-08-22) normalizes the already-MPL repos to shape C, retinue first, with a provenance ledger required before the wgpu trio.

  • device_resident_consolidation_planapproved direction, implementation open 2026-08-20: one logical device resident owns persona-scoped durable stores and network runtimes, daemonized on desktop and embedded on mobile. Routes Knot through the existing owner-only Graphshell application door; separates shared Knot source state from per-session state; folds personal-vault authoring, Stickleback sync, and iroh evidence into one owner; replaces private urn:blake3/urn:sha256 spellings with RFC 6920 SHA-256 identity beside iroh BLAKE3 transport hashes; and gates physical CAS consolidation on serving-side (scope, peer, hash) authorization. Keeps p2panda logs, iroh blobs, Graphshell sessions, Personae pairing, Gemot authority, and per-domain network identities distinct.

  • djinn_family_resident_services_planplanned after the djinn 0.0.2 registry release; notification owner renamed 2026-09-04: moves family update polling and durable status out of applications and into Djinn while Luggage retains signed-feed, staging, and platform-apply semantics. The first gates extract Hocket's proven policy grammar, make a staged offer self-sufficient, and add a portable ReleaseRefV1 plus Wasm-clean verifier: one signed content manifest names application, source revision, compatibility, and target artifacts, while a disposable offer supplies URLs or peers without changing release identity. Later consumer-forced slices add the resident scheduler, Athanor jobs, product-neutral notification delivery, an authenticated local agent door, Murm-owned DNS-SD mechanics, and firmware staging without letting Djinn flash devices. Redshank remains the separate Woodshed listening and timed-annotation product.

  • graphshell_remote_projection_host_plan: ruled with Mark: Graphshell is the family-wide remote projection host above Scenograph, not the engine or Mere's internal chrome. Defines a clean sibling repo (chirograph, graphshell-client, graphshell-endpoint, graphshell app), four wire planes (session, projection, presentation resources, intents), epoch/revision diff identity, Graphshell-owned cross-application curation, disclosure and offline rules, carrier profiles, and seven executable proofs from loopback representation fallback through authenticated multi-app composition. Includes the live Code/repos boundary audit: arrangements → scenomise; kernel-aware canvas stays Mere; shared graph view grows through Cambium/Sprigging; content-contract decomposes across NetRender/Genet/Mere; typed Eidetic core moves to the new Eidetic family; duplicate mere-identity retires; Murm/Moot promotion proceeds; Retinue/Tulle/Sennet/Tucket merge into one radio workspace; Woodshed's two-consumer audio-primitives promotes; donor register-* islands are rehomed or retired rather than exported. Repository posture superseded 2026-07-23 by the repo consolidation plan; the protocol design, proof sequence, and receipts remain in force.

  • physics_catalog_planin progress; P1, P1b, P2 on both hosts, P3 on the remote board, and runtime extraction landed; P4 next: a catalog of distinct physics laws (Springs, Charge, Stress, Energy, Orbit, Kinds, Flock, Sync, Flow, Anneal, Still — all v1) as a lever beside the arrangement catalog, with the donor's Level-2 extra forces as composable overlays (degree repulsion, domain cluster, hub gravity, depth gravity, grid snap, gravity locus, plus fields, affinity and anchor already landed) and named profiles as (law, overlays, tunables) triples — the donor's ten presets (liquid…void) read from the archive and mapped, all one law with different overlays, which is the collapse this plan refuses. Laws and overlays as seiche Forces, the catalogs in the canvas, pickers in both hosts, receipts per law on the web scenario lane, then the remote board under physics and drag/add rows.

  • browser_webrtc_carrier_planC0-C3 landed 2026-08-28; C4 landed 2026-09-02 (C4a session, C4b surfaces; browser profile marked proven); C5 next: direct browser-to-native WebRTC below Notochord, a private invite redeemed into a narrow delegation for a browser-generated ephemeral Personae subject, host-signed DTLS-fingerprint link binding, forced-TURN and reconnect gates, then the real Graphshell snapshot/diff/intent session and public mer3ly.net/join/ rendezvous. InviteV1 carries Luggage's manifest-hash + publisher-key ReleaseRefV1; C5 verifies the exact browser bundle before execution, and C6 makes the same release an explicit native adoption offer without changing publisher trust or feed settings. Iroh-over-WebRTC remains a measured later adapter. (C0: crates/murm/webrtc-carrier builds for native and wasm32-unknown-unknown; TransportKind::WebRtc maps to CarrierKind::Other and reuses Reticulum's link binding unchanged; Graphshell's accept path split into admit_accepted_session with every call site untouched.)

  • repo_consolidation_planhistorical execution record; Cambium, upper-component placement, and final-topology posture superseded 2026-09-02: Mere is the platform and the extracted families remain its components; the separate-repo bar is coherent identity apart from the six primaries. Nine repos fold into mere (personae, armillary, the eidetic four, servitor, vates, sibylla, conatus, scenograph, graphshell), cambium and netfetcher fold into genet, misfin founds a smolweb bucket, the radio four merge into one workspace, tinct is consumed through genet, and netrender/wavicle/wgpu-* stay separate as passing the bar. Withdraws the murm/moot promotion and the Graphshell plan's neutral-commons repo posture; the portable-crate CI walls travel into mere; phases C0-C6 with per-phase done conditions. Executed 2026-07-24: C0-C6 done, the publish sweep republished 21 crates at their new homes, every absorbed repo deleted except graphshell (archived, donor docs); still open: the toolchain bump for isometry/hocket/turnstone (each blocked on its own pre-existing breakage) and the four graphshell-* crate publishes (held until the protocol settles through G5-G7).

  • scenograph_0_0_3_release_plancompleted historical release plan: S1-S4 landed and the four 0.0.3 crates were published 2026-07-24. It records rulings D1-D4 for intent ownership, deletion of measure, item channels, and Scenotime picking. It is a release receipt, not a claim that the protocol stopped developing.

  • knot_port_planhistorical in-tree execution record; K0-K7 complete 2026-07-27, sources removed from this repository 2026-09-04: Knot began as a Mere port at ports/knot (historical citation) beside ports/graphshell and now lives in the independent Knot Editor repository, which Djinn and Turnstone consume from one immutable revision (E2 of knot-editor/design_docs/2026-09-01_knot_editor_repository_extraction_plan.md). It ships a host plus a knot_endpoint binary, and has files-in-place projection with an autonomous attributed watcher, file/note content classes, a sealed vault, grant-filtered local analysis, encrypted Stickleback sync over real p2panda, format-selective writers, and a Cambium-backed editor. Knot now signs causal frontiers, reports per-document multi-writer conflicts without hiding unrelated documents, automatically merges exactly two compatible concurrent UTF-8 text versions with independent line edits, returns pending-history diagnostics, restores its author head after Redb reopen, and persists the projection and derived merge in its checkpoint. Overlapping edits remain visible conflicts, and Knot does not translate documents through chartulary facets.

  • overmap_sessions_graph_plan: rungs O0-O3 COMPLETE 2026-07-20: sessions as container nodes in a derived graph one level up (a pure builder over ManifestStore, no new storage), the switcher as a graph view on the shared swatch leaf, fork drawing its lineage edge, and session deletion through the manifest trash (the directory move IS the removed-sessions record; no session-level bin record). Held, correctly gated: stored-overmap promotion (needs an overmap-native edit), cross-session edge vocabulary (murm/moot's seam).

  • low_power_managed_network_plan: joins the Heltec V4 low-power continuous-RX radio personality (UART0 + Light-sleep, retinue-side) with owner-controlled Mere service access and Reticulum transit enforced from honest incoming-session facts. V1-V8 landed: Murm admission passes over Memory, Reticulum/TCP, and p2panda, while the Commons direct-PHY receipt proves a headed 1,177-byte encrypted operation over the connected T114 and Heltec V4. Still open: the V0/V2 current and sleep bench.

  • notochord_session_policy_spine_planN0-N4 complete 2026-07-27: Notochord is the typed facts/claims/admitted-session spine used by real Murm and Graphshell carriers. The promoted package retains revocation-checkable claims, persists versioned owner rules and verified revocations without live session state, and has a headed independence receipt for service, discovery, and transit controls.

  • commons_multi_writer_convergence_planDecision 1 implemented and property-tested 2026-07-26/27: the tracked commons-spine workspace package (crates/moot/commons) bridges chartulary batches to signed p2panda operations and real LogSync. Per-author backlinks plus a signed observed frontier preserve causality; (verifying_key, log_id, seq_num) is only the concurrent tiebreak, avoiding permanent public-key write priority. Chartulary 0.2.0 uses signer-bound (writer, counter) edge ids, restores counters after replay and durable reopen, and ingress rejects writer forgery or counter reuse. Missing parents now yield a partial projection rather than hiding unrelated state. Whole-node edits remain coarse; the Commons fold resolves concurrent remove-versus-insert as remove-wins while a causally later insert recreates.

  • commons_authority_keys_consumers_planC1-C7 complete 2026-07-27, with the Commons profile promoted 2026-07-28: Knot owns document events, format writes, and visible conflicts while using Stickleback's shared causal bookkeeping. Structurally valid facts are retained and classified effective/pending/revoked through stable Personae-root bindings and typed Servitor capabilities. GemotAuthorityView makes a current Gemot delegation effective, reprojects a revoked one without deleting history, and leaves expired or non-covering grants pending. The p2panda Data keyring persists epochs, receives DCGKA welcomes from Gemot-shaped membership, and rotates on removal; Data/Message semantics are explicit profile choices. Encrypted commons.channel and commons.message operations converge over Memory and real LogSync, survive protected native drop and Reticulum/TCP unchanged, and the same 1,177-byte signed ciphertext passed from a T114 to a Heltec V4 over direct PHY before Commons independently verified and decrypted it.

  • commons_epoch_retention_planE0-E4 complete locally 2026-07-27: Stickleback persists exact epoch chronology and computes blocked-by-default proposals. Commons chat carries an authorized encrypted checkpoint; chat and communal Knot both supply pending, reachability, authority, and offline-member holds without sharing domain grammars. Explicit execution revalidates the reviewed proposal, then atomically persists the reduced keyring and receipt through Redb. Reopen and offline resume/bootstrap outcomes are tested.

  • commons_direct_phy_rf_receiptpassed on real hardware 2026-07-27; archived. The Commons authority plan's C6 carried over direct PHY rather than a simulator: one 1,177-byte signed ciphertext left a T114, arrived at a Heltec V4, and Commons verified and decrypted it independently of the radio that carried it.

  • murm_v7_direct_phy_acceptancepassed headed 2026-07-27; archived. Murm's V7 acceptance over the direct-PHY carrier, run headed rather than asserted, so the carrier matrix rests on an observed session instead of a unit fixture.

  • murm_v7_p2panda_acceptancepassed 2026-07-27; archived. The same V7 acceptance over p2panda, which is what makes the matrix a comparison between two carriers rather than a claim about one.

  • commons_calls_planA0 complete 2026-07-28; A1-A6 not started, A1 gated on Turnstone place-port T5: retained invitation and terminal facts plus the sans-I/O control fold now have permutation, expiry, duplicate, terminal-dominance, equivocation, and wire receipts. Admitted sessions and media remain later gates, and an open question records whether a call should be owned by Commons or by a reusable calls service before A1 settles it by accident. The plan separates retained invitation and sparse history from expiring presence and live media, starts with two-person audio over p2panda/Iroh, and treats Reticulum/direct PHY as invitation and voice-note carriers until radio voice earns its own bitrate, airtime, and intelligibility receipts.

  • reachability_rungs_and_privacy_lanes_planR0 recorded and R1 landed (2026-09-01 audit); R2/R3 scoped; Veilid retired: the relay-leg experiment disproved bare-node-id dialability (a relay makes the local endpoint reachable and resolves nothing about the peer; the address book dies with the process), so the resolver ladder had one working rung, mDNS. R1 caches the peer's last relay-tagged endpoint ticket on PairedDevice as a refreshed, disposable hint (Syncthing's shape minus the discovery server), minting pairing_id in the same schema move per the H6 addendum. R2 extends the retinue announce's signed app data to carry the iroh dial hint: announces re-propagate on an interval, so the mesh IS the address cache, over TCP transport nodes or RF alike. R3 is the privacy plane: emissary (embeddable Rust I2P router, forked) proves itself on a netDB rendezvous receipt with mDNS dead and no hints, then the turnstone i2p:// web lane, then retinue-over-I2P; arti stays consumer-posture for a later clearnet browse toggle. Plane split ruled: iroh is the byte plane, identity-routed lanes are the control plane, nothing moves blobs off iroh. n0 DNS discovery is recorded as the superseded shortcut. (R0, added 2026-09-01, is the one home for landed local-link discovery: Murm's P2pandaOverlayHost, the two branch-pinned mDNS forks and their verdicts, the macOS signing finding; DNS-SD service browsing stays absent and owned by Murm per Djinn F3.)

  • castellan_keeper_founding_planexecuted 2026-08-18. The identity surface moves to its port: graphshell's H4 lane (secret-free read model, card/intent projection, PersonaeHost authority) becomes castellan's keeper feature per the port law, with graphshell re-exporting at the pre-founding paths so no call site changed. Wire strings keep their castellan.* values; renaming the wire vocabulary is an open item. The persona-switch receipt now composes castellan directly — the port law's own proof. 46 castellan tests + 106 graphshell tests green.

  • family_shared_identity_planlanded 2026-08-08 for Turnstone and Woodshed; Hocket blocked on purpose. Identity was split across two lanes: the personae vault at a fixed per-machine path, shared by accident of that path, and the session-runtime wallet under whatever data root each application passed, so ensure_local_device_identity minted a different device key per application. Every consumer hardcoded ProfileId("default") in five places, so a vault holding a work persona beside a personal one could not say which was in use. Adds session_runtime::shared_root (one wallet root, MERE_ROOT-overridable, with a move-not-copy adoption of an application's legacy identity on first access), personae::roster (list, remember, open — with a sole-persona rung so a vault holding one persona under another name does not silently gain a second identity), and mere-persona-picker (a Cambium view over the roster, a crate rather than a personae module because the view drags the whole Genet stack into a crate headless bins depend on). Woodshed's practice session now seals to the chosen persona, non-blocking, with adopting_plaintext as the migration. Hocket is a key rotation, not a wiring change: its contact tokens are the full public key and musicians have already pasted them to each other, so pointing it at the shared vault would silently make each user a new person. Cleromancy and Isometry have no identity to move.

  • knot_in_graphshell_planK0-K3 complete, including the physical K2 receipt on 2026-08-08. KnotEndpoint was already a graphshell endpoint; only its deployment was accidental, wrapped as a process Turnstone spawned. K0 removed that boundary for every Knot mode. K1 chose Option A: shared documents are projected and personal ones replicate, which dissolves the shared-Knot authority question rather than answering it, at the cost of offline co-authoring; Option B is kept on file and is much cheaper than first recorded, since Knot already speaks the Stickleback group keyring and already merges independent text edits, leaving only a static writers allowlist to replace with a Gemot capability query. K2 proves all three clauses of the revised done condition against the real ResidentProjectionHost: two peers with distinct subjects mount one holder's vault, one saves, the other hears the bell and reads it, the holder's own file is the truth both were reading, and a visitor whose holder goes away is told rather than shown a stale copy. Its two-machine runner also passed from a Q-PC holder to a Windows visitor over an explicit ticket, with the holder's file matching the visitor readback. Three things had to change for that: rhai's sync feature plus a BlockEvaluator: Send bound in genet, so a KnotEndpoint can be scheduled by a host; a carrier error that distinguishes an endpoint's refusal from a dead link, so a session can be marked disconnected without doing it on every refusal; and register_resumable_notifying, because the catalog's typed registrations were answering resume with a refusal for an endpoint that supports it. K3 kept the stdio spawn path deliberately — not the default, but the only carrier with a real process boundary and so the only one that can catch a message type that stopped round-tripping, and the only deployment for an endpoint that genuinely is a separate program. Also scopes Knot search onto the hybrid seam (approved, independent of hosting): the defect is that LexicalEmbeddingProvider is hash-bucket embeddings, so Knot has one recall engine wearing lexical clothing and fuse has nothing to fuse.

  • graphshell_carrier_seam_plancomplete 2026-08-06; archived. graphshell's README claimed its protocol ran "over an unspecified carrier" while StdioCarrier was concrete and RetainedEndpointSession held it by type, which meant the Knot editor could not ship on web or mobile at all. C0 extracted the four-method trait; C1 added the in-memory carrier, still serializing so the local path cannot silently diverge from the wire; C3 added the network carrier, whose dialling half had existed only inside the g5_peer receipt binary, and gave the admitted session loop the revision bell it had never had. C2 followed on C3's evidence: NetworkCarrier needs only the protocol crate and tokio, so it became graphshell-network beside -stdio and -local, while RetainedEndpointSession and action_draft moved to graphshell-client so Turnstone names the crate layer instead of another product's port. spawn could not follow a type holding Box<dyn Carrier> and became sessions::spawn_endpoint_session. C3's error type later gained the Refused/Disconnected split under K2. Consumed by the Knot in Graphshell plan.

  • node_dissolution_facets_plan — executes the one-node ruling in three lanes: F facet store, S spatial completion, and D the kernel Node dissolution ladder. S0's numen/quint/seiche extraction has consolidated into Conatus; remaining spatial work moves positions through arrangement facets and retires Node.position/velocity. The old canvas-family promotion tail is superseded by the Scenograph/Cambium split in the Graphshell plan.

  • graph_behaviors_plandesign (with Mark, 2026-08-13); frequency bound landed 2026-08-18 at actuation: reactive automation as denizens with triggers. Two tiers split by "does it write graph truth": projection rules stay with the scriptable field regions plan; graph behaviors are gate-plan denizens plus a watch (a Cap::Scope subscription, watch ⊆ read ⊆ grant) matched against the attributed GraphJournal tail at the after-dispatch drain. All three open questions ruled 2026-08-18: the noun is watch (in TERMINOLOGY.md), watches are reviewed at install beside the rings, and the cascade budget is a live setting (default 4, floor 1, no unlimited). Cascades are a bounded rounds loop: stable subject order, self-authored entries never wake their author, loud budget exhaustion; deterministic and scenario-replayable. Time arrives only as an injected watchable source (replay clock). Slices W0–W5 end at the flagship neighborhood-summary-into-a-knot-note behavior; W0 landed 2026-08-18 in servitor::watch (containment enforced at registration, no self-waking under either journal's author convention, cursors persisted through servitor's to_wire idiom). Building it added W0.5, resolved same-day: mere's main graph is UUID-keyed, so Mark ruled container membership, and a node's watch scope is its EdgeFamily::Containment ancestry written as a ScopePath of UUIDs (a vocabulary the kernel already has, needing no change to Cap). W1a landed alongside: servitor::cascade, the bounded rounds loop whose exhaustion names the behaviors still answering each other and defers their work rather than consuming it. W1b later landed with the remaining slices. The wavelet brief's Trigger/Observe split lands here as the watch/read scope pair, not as edge kinds; no new scripting language (rhai / piccolo Lua / wasm as placed). Frequency bound (landed 2026-08-18): cascade depth was bounded and cascade frequency was not before this slice, so a behavior that settles and re-triggers forever never exhausts a budget counting rounds within one cascade; because the graph is the replay of the journal, that oscillation writes history whose load and replay cost outlive the fix. A declared deadband (minimum change, minimum interval) now runs at actuation, with behavior-defined scalar output, host-fed time, persisted accepted state, and named refusal before journal growth. See facet signaling and control loops.

  • participant_gate_packs_plandesign (with Mark): one authority gate for every non-UI actor (script, wasm component, moot peer, agent, scenario runner): personae identity → grant → typed proposal → journal apply with attribution. Participants reside as nodes bearing nested graphs (new chartulary containment capability, B0 spike); packs are signed engram-profile envelopes distributed over retinue (gated on R4) and curated as moot flora with tessera receipts. Vocabulary rulings: nested graph vs graphlet vs swatch. Wraps document-host P2.3/P2.4 and the typed turnstone world; deletes future moot-ACL / agent-sandbox / per-app-package work by unification.

  • capability_model_plan — successor round to the participant gate plan (whose B0-B5 are complete, and whose OQ3 revocation round was never taken). A capability is a type with a partial order, not a string with a prefix test. Findings verified by probe: coverage is string-prefix-shaped (a grant on app/nav covers app/navigate, and scenario/ covers a .. traversal), one mechanism serves two different kinds of capability (closed-set app rings vs unbounded graph scopes, so the rings inherit the hierarchy's failure mode), the grant projection is lossy (mode lives in a display title and rebuild hardcodes Write), and Mode::Delegate is inert because the order does not exist. Design: Cap::{Power, Scope} with equality and segment-prefix coverage, lossless tagged projections, the user as root subject so install becomes an attenuating delegation and revocation is severing it, lazy cascade, host-set clock. Round closed 2026-07-24: C0-C4 landed (C5 retired into the phases' consumer halves; C3 superseded same-session by C3', servitor as an adapter over personae's signed certificates), turnstone's root identity is the personae vault via DPAPI auto-unlock, and both follow-ons (vault swap, re-root heal) landed. Tail closed 2026-08-18: D3b's algebra now lives in the dependency-free mere-capability leaf shared directly by servitor and gemot; Cap::Facet adds dot-segment facet-namespace coverage, and the gate requires it alongside node scope for SetFacet and RemoveFacet. A web. grant permits web.viewer while refusing denizen.binding on the same node.

  • graph_delta_capture_apparatus_stats_plan — the mere half of the doctrine brief's shortfalls: a serializable CapturedDelta mirror recorded after apply_graph_delta in resolved (Replay*) form (the replay lane's first producer), env-gated session delta logs, a replay-onto-empty oracle test, and per-table stats (kernel / engine / Scene) surfaced live in the apparatus panel. Genet half: genet:docs/2026-07-02_dom_mutation_capture_replay_plan.md (DomMutation capture/replay + engine arena stats).

  • meerkat_promotion_pass_plan — promote host-neutral modules out of meerkat (54.7k LOC, ~85 bin modules) into workspace crates, ordered by the Fetched dependency chain: fetch actor → crawl (frontier/robots/sitemap) → content-transfer wire contract, then web_clip→import, graphlets→graph family, History/suggest→chrome, theme_edit→register-theme, pane data halves→a new crates/domain/ tree (workbench stays platen's; apparatus migrates when touched). Import-audit table proves the candidates (zero/near-zero crate:: refs); names what stays host by nature; agent_harness deferred to the CLI tooling plan.

  • overlay_roots_and_ua_widgets_plandesign/direction (with Mark): browser features as views. Satellite roots (engine-hosted xilem_serval subtrees inside content documents, two slot kinds: anchored overlay + UA shadow) make find highlights / reader mode / annotations / autofill chips / link previews ordinary views with app state, positioned by engine layout instead of coordinate-math overlays; form controls rebuild as the same control views the chrome uses (the standards-aligned UA-shadow pattern; ElementInternals is the contract checklist, HTML-AAM the AccessKit feed). Rides host_pool, graft_subtree, and the DomMutation stream; P0 engine probe → remote runner → find-highlights first feature → details/checkbox → select → text input → the feature wave.

  • archived_plan_tails_plan — backlog holder for deferred items spun out of the 2026-07-03 + 2026-07-04 archive passes (23 completed plans across archive_docs/2026-07-0{3,4}_completed_plans/): wgpu-scry capture-settle + compositing cleanups, net-hardening E1/E2/E3 + B4/D2, find-field paste, submenu polish, keyed-sequence P4, engram rkyv compaction + kernel merge promotion. The document-lane retained-text find/copy pointer was closed 2026-07-03.

  • host_p2p_wiring_plan — wire the p2p substrate into the meerkat loop via the fetcher's async seam; S5.0–S5.2 shipped, S5.3 → comms shell.

  • comms_shell_plan — docked comms pane (misfin mail + murm cabals) over a host-neutral comms domain. (Largely implemented.)

  • node_navigation_lineage_wiring_plan — drive the built per-node nav-lineage substrate from the live navigation path (within-node history + across-node relations).

  • moot_constitution_brief — the constitution primitive: a per-moot ruleset + amendment rule (the §8.8 policy-authorization layer); home is moothold beside tessera.

  • apparatus_pane_and_theme_switcher_plan — apparatus pane + runtime theme switcher; A1 + A2 shipped (chrome/pane theming + orrery backdrop/edge palette, persisted); A3 (fold the settings overlay into apparatus) + per-theme HC node fills remain.

  • system_diagnostics_and_accessibility_plan — wire Apparatus to one meerkat observability spine (ux-events, register-diagnostics, tracing/probes, UxTree/AccessKit, agent harness).

  • accesskit_screen_reader_verification — AccessKit screen-reader verification notes. Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

  • shellbar_plan — F2 shellbar: a docked chrome strip (edge-configurable) with pane-toggle buttons, outside the frame tree.

  • multi_graph_activation_plan — wire meerkat to hold many graphs per window, switchable from the shellbar (Model B = window holds panes/graph is content, goal; Model A = session owns the content band, checkpoint at MG2). MG1–MG5 + host text path done (per-session storage, switch/close/rename, window-scoped frame, labelled switcher tiles); MG6's far-B + tear-out are now owned by window_composition (OpenGraphBeside summons a 2nd Orrery pane); only the persona chip + per-session engine-profile escalation remain unique here.

  • multi_window_plan — drag a pane/tile out to a new OS window sharing the backing graph (the tear-out brief's leaf/branch/fork trichotomy). Carves the App god-struct into Shell (shared state) + per-window WindowView. MW1–MW3 done (per-window reshape, registry, one-device/N-surfaces, spawn/close, slim leaf chrome). MW4–MW6 superseded by the window_composition_plan. The N-runner/N-dom/N-ShellState shape it built is now the migration source, not the target — see meerkat_one_state_migration_plan (archived).

  • meerkat_one_state_migration_plan — COMPLETE, archived 2026-07-07 (canonical checkpoint entry in the archive section below) — the meerkat consumer migration onto genet's GenetMultiRunner (one app state, N windows as projections), executing step 2's second half + steps 3-4 of the one_state_n_windows_design. Key finding: the framework needs no extension — GenetMultiRunner<State, Logic, V>'s Logic: FnMut(&State) -> V accepts a boxed per-window closure capturing its projection index into AppState.windows[i], which is the design's FnMut(&AppState, &WindowLocal) lens as sugar; the one type change is ShellLogic from bare fn. Sliced: S0 SharedChrome seam (ShellState.shared: Rc<RefCell<SharedChrome>>, sync/crawl off Chrome, fan-out + spawn-seeding deleted; keeps per-window runners; the seam Slice 3 lifts into AppState.shared), S1 rest of shared fields (comms/sessions/shellbar/physics_paused), S2 name WindowLocal, S3 flip Shell to own the multi-runner + reroute the ~30 view.runner sites through ProjectionId (the load-bearing borrow re-architecture), S4 source-first rebuild order (unblocks portable tiles). Landed 2026-07-06 (verified green, 302 tests): S0 (SharedChrome seam; the confirmed friction was that the toolbar/Steward/Apparatus views read the shared fields off the Chrome lens, so S0 routes crawl as a param + redirects sync host-side, and crawl rides a per-window rebuild-nudge); S1 (reassessed — most listed fields turned out shared+local mixes, real separation deferred to S3; trimmed to deleting the vestigial Chrome.shellbar_edge mirror); S2 (WindowLocal split, ~40 accessor sites). S3 scope-corrected to ~250 sites/30+ files (removing WindowView.runner forces the ~215 accessor callers to move, not the ~30 first estimated; the lens routing rules out a cheap Rc facade), with a green-checkpointed execution sub-plan → slice3_multirunner_flip_subplan (archived). Workspace toolchain bumped to 1.96.

  • forest_dom_planstep 3 of the one_state_n_windows_design, successor to the completed step-2 migration: collapse the N per-window doms into one ScriptedDom with N window-root elements, each window a subtree with its own layout session, so a cross-window move_before becomes legal and a torn-out tile keeps its DOM identity + scroll (the only payoff — plain multi-window already works on N doms). Gate: worth doing only if state-preserving tear-out is wanted soon. Leverage: the multi-runner's dom(id)/root(id) API already anticipates it, so meerkat is a render-path rewire, not a state rewrite. Work = 3 genet capabilities (RunnerTree mounts-at-node, genet-layout subtree sessions, scripted-dom mutation routing by root) + 1 meerkat rewire (shared dom, per-window PaneSession from multi.root(pid), routed draining). F0 spike first (riskiest unknown: can genet-layout isolate per-root relayout + partition the mutation stream?), then F1 genet → F2 genet-layout → F3 meerkat (same-DPI; folds in OQ-3 a11y-id salting + the dual-collection assert) → F4 multi-DPI (deferred) → step 4 portable tiles.

  • family_repo_merges_plan — group lockstep satellite repos into family repos: eidetic (muniment + codicil + chartulary + scholia) and conatus (numen + quint + seiche), histories preserved, consumers repointed; retinue household stays separate (legal); open follow-on: mere's crates/eidetic/* lane renames to mere-eidetic.

  • portable_tiles_planstep 4 (the last of the one_state_n_windows_design sequence), the meerkat consumer of genet's landed moveBefore / PortableKeyed: a cross-window tile drag lowers to one atomic move_before keeping the tile's DOM node + scroll + focus, and the §6 trichotomy (leaf-move / sticky-note / rekey) falls out of state mutations. Key finding: meerkat's tiles split into two lanes — DOM-lane (folded panes / document-lane cards; move_before; needs the forest dom) and surface-lane (pelt/external-texture workbench tiles; member→window reassignment; needs no forest dom) — so P0 (surface-lane move + carry view.scroll[member]) banks the felt payoff (a web tile keeping its live page + scroll) before step 3, while P1/P2 (DOM-lane PortableKeyed + the trichotomy) wait on the forest_dom_plan. Also records the middle path (a cross-tree key registry carrying view-side state on N doms) and recommends against building it speculatively.

  • tearout_composability_plan (continuation of the completed window_composition_plan, archived) — the second-window architecture as orrery (authority) vs panes (views): orreries pool by GraphId (the source of pane content); panes (workbench / gloss / steward / inspector / apparatus / alembic / the spatial orrery-view) resolve to an orrery by graph_id, co-located or not; a window is a split of panes, possibly resolving to different graphs. Linkage (synced vs independent) is emergent from shared-vs-distinct orrery resolution. P1 pools the orrery off Shell (converges with far-B / MG6) → P2 panes-resolve-everywhere → P3 cross-window panes (the leaf) → P4 cross-graph move/copy with provenance → P5 tear-out gestures. Enabled by the UUID-keyed graph-agnostic constellation (no graph extraction; only a same-graph two-camera case is deferred). Supersedes multi_window MW4–MW6. (P1 + P2's load-bearing half done; OpenGraphBeside summons a 2nd Orrery pane with per-pane render + wheel/hover; C1, the per-pane focus/active-session decoupling, shipped 2026-06-14 as the pane-as-unit refactor, regression-tested 2026-06-19.) Window-composition completed + archived 2026-06-19 (P1 + P2 load-bearing half + C1 banked); the live forward scope is C2 (external-texture-input bridge), C3–C5 (tear-out + cross-graph gestures), and the deferred camera. CLOSED 2026-06-24 — foundation complete + driven headed (C1, C2-gated, C4 core kernel cross-graph copy + CopiedFrom, camera-on-the-view, MW3 5/6 chrome+redraw fan-out + per-window a11y); kept in place (not archived) as the foundational record siblings cite. The remaining named purpose (the actual tear-out gestures) spun out → tearout_gestures_plan.

  • tearout_gestures_plan — spun out of the closed tearout_composability_plan (foundation banked there). Owns the user-facing tear-out gestures implementing the tear-out operations brief: the trichotomy (drag = leaf, Shift+drag = branch, Ctrl/Cmd+Shift+drag = fork) + toast on the ambiguous drag, on top of the banked substrate. Slices: G1 drag+modifier plumbing + drag-ghost + op-split (done, driven 2026-06-25); G2 leaf content — a Workbench pane on the donor's pooled orrery, no Orrery pane (content done + tested 2026-06-27 via build_leaf_view_for / leaf_workbench_frame; trigger pending); G3 branch (forme Branched graphlet — done via graphlet_wiring_plan Phases 1+2); G4 fork (subgraph copy via copy_component_from + new session+graph + weak parent_sessiondone, driven 2026-06-25; restore-on-restart done / already-working 2026-06-27, locked by a test); G5 cross-graph single-node drag = copy/move (copy done, move done 2026-06-27 as the Alt-modified MoveNodeAcross); G6 cascade on donor delete (leaves lose node, branches die, forks survive — done 2026-06-27 via the graphlet plan's #3). Reframes (Mark, 2026-06-27): the ambiguous-drag toast → a Steward-accounted notification subsystem (foundation built + tested: NotificationRecord log + record_notification + Steward notification_rows) with toasts as its transient view; the tile-tab origin → orrery-as-desktop (the orrery is the persistent dock anchor; make the workbench dock side/ratio a setting; add a pelt_core drag-out signal). The interactive/cross-crate remainder (chrome toast view, actionable notifications, the no-modifier drag-out-vs-pin gesture, the dock-side setting + toggle UI, the pelt_core DropTarget::Outside) is sequenced for a headed session. Plus the N-orrery-elements rendering seam (carries per-window camera persistence). Open: OQ-1 the two gesture axes, OQ-2 move-vs-copy default (Alt = move), OQ-4 fork scope, OQ-5 toast styling, OQ-6 node-per-tile, OQ-7 forme graphlet API.

  • notification_subsystem_plan — Mark's reframe of the tear-out ambiguous-drag toast into a Steward-accounted notification subsystem (notifications = a first-class record; the Steward is the center/log; toasts are the transient view; actionable ones carry verbs). A notification has two homes: the log in HostObservability (Steward-surfaced — the truth) and a transient toast queue in Chrome (drained from recent transient records via the chrome_update fold). Actions live in the chrome (commands reachable; observability stays free of ShellCommand). Continuous chips (sync, crawl) stay; notifications are for discrete events. Phase 0 (foundation) DONE + tested (NotificationRecord + record_notification + notification_rows); Phases: P1 the chrome toast view (interactive), P2 actionable notifications (the ambiguous-drag the first consumer), P3 producer consolidation (~37 record_diagnostic sites audited; failed fetches / crawl-done / sync / save-export-clip outcomes route through), P4 severity routing + dismissal + AccessKit a11y. Findings: command_drain.rs:72 already wants a toast it cannot make; no toast element exists today. Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

  • graphlet_wiring_plan — spun out of the gestures plan's G3/OQ-7 deferral. Gives graphlets a live home: scouting found forme's graphlet API (GraphletRef / GraphletBinding::Branched / reconciliation) first-class + unit-tested but unwired, and forme's GraphTree container superseded by the live arrangement (kernel graph = truth, orrery = cartography projection, platen Workbench = tree projection). So the work is not "instantiate a GraphTree" but add a per-session graphlet index reusing only GraphletRef (decision B; A = graft onto platen; C = resurrect GraphTreeCLOSED by the derivation finding: forme has no kind-derivation engine, only a taxonomy + a ~10-line diff, so GraphTree adds nothing even for Linked graphlets, and derivation belongs on the kernel graph). P1 + P2 DONE + driven (2026-06-25): branch mints + persists a Branched graphlet, shows a ⎇ <anchor> chip, and grows its roster on navigation (round-trips a restart). P3 (Linked / auto-derived graphlets + reconciliation) is now in scope — Mark chose selectors-that-track-drift — built by harvesting forme's types + the diff and writing derivation on the kernel graph (Ego=BFS, Component=weakly_connected_components, selector=edge-family filter). Open items: #1 per-window focus/selection isolation (the keystone — mirror the camera install/readback; makes any two windows on a graph independent, fixes the cartography-focus nuance, unblocks a branch-scoped orrery), #3 branch lifecycle on donor delete. crates/meerkat/src/graphlets.rs (historical citation) is the live home. Branch (gestures G3) is the first consumer; relational-browse is the likely first Linked consumer.

  • context_submenus_plan — a depth-1 nested-submenu primitive for the context menu, built on xilem-serval's overlay_at/anchor_point (the sanctioned host-overlay geometry the host had not been using). The relate (11 kinds), layout (10 strategies), and shellbar (4 edges) flat pickers fold under one "X ›" parent each; ContextItem.children + ContextMenu.submenu; press-gate hit-test + ArrowRight/Left/Escape. Adversarially reviewed (fixed an unpositioned-wrapper offset that painted the menu a toolbar-height low + a root scroll mis-latch). Shipped 2ce9884; visual feel pending a GUI pass. Spun the capability-adoption findings into the three plans below.

  • overlay_primitive_adoption_plan — adopt xilem-serval overlay_at/anchor_point across the floating surfaces meerkat hand-positions (context menu, tear-ghost, focus card, comms/shellbar) + fix the stale overlay/select stacking docs (the pre-z-index "must be last sibling" model that misled the submenu work). P1 (a/b/c) = docs + submenu placeholder + context-menu/tear-ghost; P2 = card.rs flip math → anchor_point; P3 = a size-carrying overlay variant (genet).

  • host_scroll_engine_adoption_plan — the capability sweep's biggest "host reimplements an engine feature": route the wheel through genet's IncrementalLayout::scroll_at (the 2026-06-14 audit's "one line") and delete the per-pane offset fields + manual rect-routing + clamp + offset-mirroring; expose scroll_extent + absolute_rect/box_model on IncrementalLayout to dedup the three host copies of each; extend scroll_element_into_view to nested containers. P1 absolute_rect + origin-walk dedup → P2 wheel→scroll_at → P3 nested scroll-into-view. Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

  • xilem_serval_control_adoption_plan — meerkat uses only 1 of xilem-serval's 7 controls (text_field); button/radio_group/checkbox/toggle are hand-rolled from divs + an active class, omitting the ARIA roles the primitives stamp. P1 button adoption (15 near-drop-in sites) → P2 ARIA stamping on the settings pickers/toggles (the bankable a11y win; PaneItem's key-drain model blocks direct lensing) → P3 full primitive adoption if a lensed path emerges. Non-goals: select (no consumer), slider (segmented is a different widget).

  • engram_compose_merge_planP1+P2+P3 done 2026-06-30. Spun out of the Alembic tail handoff B7 + decision #1 (merge-by-identity, layer the context, post-A/D, does not gate save/open). Unions two graph engrams by URL identity: same-URL nodes layer (union tags, append both sources' import_provenance so they coexist), distinct nodes added, edges deduped; the merged engram's ProvenanceRecord.upstream (previously always empty) records the source ids. P1 snapshot-level merge_snapshots (no kernel edit — PersistedEdge is node_id-keyed) → P2 compose_graph_engrams → P3 shipped as a direct host action (>compose_engrams("<id-a>","<id-b>") verb + an Alembic Engrams two-select gesture), deliberately not a ShellCommand (compose never touches the orrery pool) or an Athanor propose/apply (the user already names both ids, so there's no discovery judgment to propose). rkyv engram compaction (B6) is parked here as a deferred follow-on, not yet started.

  • athanor_steady_heat_actor_planP1 done 2026-06-30. Spun out of the Alembic tail handoff B1 (slice D's remainder): schedule the forgetting pass steady-heat (idle-throttled, yields to foreground) vs the manual click, then add consolidation + facet passes. P1 shipped as a host-side idle cadence (Shell::last_activity/last_forgetting, checked every about_to_wait tick — no ControlFlow::WaitUntil needed since the app already runs winit's default Poll). P2 (consolidation) waits on the lineage engram-compose P3 now provides; P3 (the off-thread spawn_athanor armillary actor) waits on the heavier facet-extraction pass that would justify its own thread.

  • workbench_staging_plan — the #5 staging flow (stage nodes → commit to workbench → latent staging relation), spun out of the completed card-system plan. Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

  • scriptable_field_regions_planplanned: a field as a placed spatial rule region (the third graph element) whose rhai rules govern forces (couplings/gyre), edge visibility (graphlet EdgeProjectionSpec), and node layout (arrangements) inside its extent. Substrate exists (kernel Field/Coupling, aether FieldProjection+rhai); gaps are placement (mirror add_node_at), orrery rendering, and the unified rule surface. P0 place+render+move → P1 forces → P2 edge-visibility → P3 layout → P4 the rhai rule surface. The third rhai lane after knot note-blocks and the omnibar command shell.

  • lane0_sidequests_planactive: the Tier-A glue-only wins from the in-the-wings audit (deps already present, each a Command + thin host method): JSON-LD export, recover-deleted-node, relation-kind picker, tessera score+ticket on the chip, Trail shellbar button, Barnes-Hut repulsion, Steward per-row controls. Carries the 2026-06-16 cross-agent handoff (Lane 2 tiled-render + genet threads owned elsewhere; forme parked-submodule delete is non-mechanical; wry.web already deleted). Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

  • find_in_page_host_ui_planplanned: the Ctrl+F find-bar + match-highlight overlay over the HTML/genet lane, on the committed find-in-page backend (Constellation::request_find/find_matches, genet 28e3e553 + mere eefbed6). Host pieces mirror the palette + drop-target-overlay patterns; built in two compile-checked stages (input/bar half → overlay/scroll half). Gemtext-lane find is a follow-on (needs a glyph→char map on DocumentRenderPacket).

  • retained_text_tiled_render_planuser-facing slice landed; active only for precision tails: the audit's Lane 2 / §5 foundation. The document lane now lays out once, retains the DocumentRenderPacket, lowers/rasterizes only the scrolled-to band, uses the retained packet for host-side Ctrl+F, and supports block-scoped page-text selection/copy. The 12 KiB body cap and 8192 px texture cap are retired; the remaining tail is precise glyph→char cluster geometry for intra-block highlights/carets.

  • meerkat_render_perf_plan — spun out of the cross-repo grand audit §3+§4. Splits the ~1700-line render() under the 600-LOC ceiling (M1), dirty-gates the redraw loop that currently repaints on every actor wake (M2), kills per-frame orrery/state/favicon rebuilds + allocations (M3), lands per-surface scenes to end card/tile content-actor thrash (M4), and caches/batches the find-overlay + scrying-flush + netrender-tail redundancies (M5). Multi-window fan-out folds into tearout_composability; HTML-lane parity into render_ladder_and_extraction. Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

  • unified_document_host_planCLOSED 2026-06-23 (core complete; Phase-2 tail spun out) — kept in place, not archived, as the still-current foundational record of the Phase-1 consolidation + orrery-as-element architecture that active siblings cite. Phase 1 done 4/4; pressing slices 1-4 landed + verified (content-actor retained layout; orrery Tab-order + orphaned-plumbing retired; orrery a11y sourced from the DOM cards, project_graph retired). Tail re-homed: cond 1 -> orrery_custom_layout_element_plan (parked); slice 5 -> layout_phase_split_probe_plan; secondary-orreries -> tearout; tiles -> composition spine; the JSON-LD broadcast + sighted-keyboard orrery focus-stop = noted follow-ons. Original scope: grow xilem_serval's role from "reactive layer for the chrome strip" to "host of the whole document shell". Code-verified finding: only chrome + each document pane run a genet GenetAppRunner (each its own ScriptedDom, view_pane.rs:50), while orrery / workbench tiles / gloss / cards bypass genet and are hand-composited as 7–10 Y-band scenes with ~5 disjoint hit-test + focus models — architecture-2 drift. P1 (start now, decision-independent) consolidates chrome + panes into one ScriptedDom / multi-root runner = one focus ring + Tab order + a11y tree. P2 (Path A target, gated) makes the orrery a custom-layout element with DOM node-cards + gyre-delegated geometry (perf prereq met: transform = RepaintOnly). Path B fallback = formalize the surface compositor. Converges with window_composition; extends the archived eval §6 orrery-as-element.

  • node_representation_arrangement_plansuperseded 2026-06-23 (P0–P4 done; kept in place, siblings cite it): representation axis re-based into node_body_face_model_plan, arrangement axis into graph_signals_layer_plan. Original: the orrery-as-element work made nodes DOM cards, right for the semantic half (a11y, JSON-LD, expand state), wrong for the visual half (flattened content-typed draggable objects into uniform label pills; hardwired one form). Generalize the node's presentation into two pluggable, customizable layers. Representation: a per-node form over tile / card / textured-body / shape / scripted (the binary render_as_cards flag generalized); drag stays winit-driven so any form is grabbable; "materialization is state" picks glyph-vs-card by focus/expand. Arrangement: mostly mature (orrery/arrangements registry + apply_strategy_positions + the field-regions plan for localized/scripted); the delta is scene-wide persistence + the customization surface. Node truth stays kernel+DOM-authoritative; presentation is experience-derived. P0 restores the lost gnode cues (shape variety, footprint, favicon-as-face, selection) to the card → P1 per-node representation → P2 textured-body/scripted (gated on the external-texture element view) → P3 the arrangement delta. Folds in the 2026-06-18 fix-up pass (label slug+ellipsis 1c564ab, layering cull 2c6ddb8, snapshot/frame reorder 2f5141a, favicon PNG 745682a).

  • node_body_face_model_planplanning (with Mark): successor to the representation half of node_representation_arrangement_plan (superseded), re-basing the node's presentation on two orthogonal axes, Body × Face: tile = standard node (content-type silhouette body + favicon), shape = a customized body (directly-authored hull + material) carrying any face. Breaks today's coupling where a sprite owns both the face and the only path to a tailored hull (node_collider gates the hull on representation==Sprite; node_card_view face-picks Sprite-or-favicon, so a custom body can't keep a favicon and a hull is sprite-only). B0 decouple hull from sprite (independent per-node body store; sprite-trace seeds, not owns; Face pick independent of Body) → B1 tile/shape as body presets → B2 per-node material (restitution/friction/mass/damping setters mirroring set_linear_damping/set_node_tangibility, default-preserving, cartography-sidecar-persisted, composing with physics_scenes tangibility) → B3 the Stage-B swatch generalized into a body designer (vertices/primitives/material sliders + sprite-underlay trace — the gloss_navigator_design §2b swatch over the node body) → B4 form parity (in-scene sprites on secondary panes + the corrected interactive/scripted feasibility: the live-WebView body is built-and-unwired via the scry off-window-capture + API-input path, not blocked; the decorative scripted face is DOM-substrate-available; only the canvas <external-texture> input bridge is genuinely unbuilt, tearout C2). Collects the orphaned representation follow-ons (styling lens + label density of Decisions 3-4, scene-pane defaults Decision 6, facets-panel structure + sprite federation from the probe, routed edge-trim) with named owners. Resolves the node_editor_customization_probe Q3/Q6/Q7 (Q6 = orthogonal, the Body × Face split). Substrate owners cross-reffed (compositing → native_surface_compositing, widgets → object_card, facet pane → settings_lane, scene physics → physics_scenes, arrangement → graph_signals).

  • graph_query_layer_planslices 1+2 shipped: SPARQL query over the focused graph, kernel-sourced and read-only (the query facet of the spine's made-semantic stage). node_quads is the single kernel→RDF projection (both JSON-LD shapers render from it); linked_data::query::sparql runs it through an in-memory Oxigraph store behind a query feature (no RocksDB, wasm-viable); the >sparql("…") omnibar verb echoes results. Residual backlog (none blocking, ranked): shared export/ingest mapping module, RDF-star edge metadata (the substantive next step), CONSTRUCT→graphlet, results pane, Turtle/N-Quads I/O, JSON-LD-in-view (Path A), synced-mirror store, federation/UPDATE/HDT.

  • petgraph_rdf_planplanned: make the petgraph kernel losslessly RDF-projectable + SPARQL-queryable, keeping petgraph as the single truth/runtime and RDF as an on-demand projection (never a held second authority — a perf benchmark, crates/probes/rdf-kernel-bench/ (historical citation) , measured held-RDF-truth at ≈11x memory / 19x load / 18x mutate with an identical hot path, so the migration plan's RocksDB-sidecar flip is rejected). It defines a Mere RDF projection profile (content-world facts in, experience/runtime out). P1 carries the profile via statement records inside pair-local EdgePayload buckets (logical multigraph, one statement per fact; pair adjacency remains the petgraph hot path and visual edge-collapse is the default view owned by node-representation/orrery) + typed/lang literals on NodeProperty + named-graph scope + reifier-node agent-IRI provenance; P2 lossless dataset_quads projection + standard-vocab mapping + a RDF→kernel→RDF round-trip gate + Turtle/N-Quads I/O; P3 a spareval::QueryableDataset adapter (InternalTerm = interned term-id) so SPARQL runs over the kernel with no held quads, subsuming the ephemeral-store path; P4 (gated on footprint) an interned slotmap kernel. Continues the rdf_native_kernel_feasibility research.

  • native_surface_compositing_planplanned: how the chrome and its modal overlays (context menu, palette, find, settings) composite above embedded native surfaces and the host-composited content layers, so an overlay is never occluded. Root cause (code-verified): a scrying System WebView is a native WebView2 composition visual DWM stacks above meerkat's whole swapchain (scrying_host.rs:437-442), not a texture meerkat draws, so the menu (rendered into the swapchain) is structurally beneath it regardless of the chrome-last, full-window compose order (render.rs:1724, which is correct for textures). The on-top visual is a card-format artifact: a floating card chases the visual every frame (set_offset) and must keep it on-screen for capture; a pelt tile is fixed and shares none of those constraints. Direction (revision 2): the orrery card = a static snapshot texture under the chrome (no live visual in the orrery); a live System WebView = a pelt tile whose WebView2 visual lives on a dedicated off-window host HWND (hidden / clipped), captured continuously via CreateFromVisual and composited as a texture under the chrome at the render.rs:1398 path — meerkat keeps presenting a bare swapchain (no DWM z-ordering, no transparency contract, no composition-tree present, no per-frame set_offset chase). Finding 5: keyboard / text / IME forward by CDP (Input.dispatchKeyEvent / insertText / imeSetComposition), host-driven, independent of HWND focus — so the off-window live tile keeps full input and the revision-1 "P3 keyboard spike" is dropped. Retires the floating live WebView entirely. Owns host-surface layering kind (b) (genuinely-external WebView2) + the snapshot half of (c); genet-rendered content (a) is a DOM subtree (unified-document-host), the orrery gyre scene (d) is a texture (node-representation/orrery). Sibling to unified-document-host (the in-document menu-over-node-cards z-order was fixed there by document order; this layering supersedes that plan's blanket external-texture-migration recipe for the genuinely-external scry case) and node-representation (the snapshot-vs-live split is the compositing half of card = snapshot).

  • document_script_substrate_planaccepted; P0 sync probe green 2026-06-21 (crates/probes/document-script-p0/ (historical citation) ): a capability-scoped, cross-language script + extension contract (DocumentScript, a WIT world) over the WASM Component Model, sitting above genet's JS-shaped ScriptEngine rather than replacing it. P0 proved the contract end to end on a real Component Model boundary (Wasmtime 45 host + direct-Rust document-core guest): per-turn handle-event, mutations out, typed errors, one granted capability. Review pass added §10 "Before P0": legacy web JS stays the existing native Runtime<Nova/Boa> lane (not a Wasm component) and html-document leaves P0/P1, because genet's runtime already runs legacy turn-based via a synchronous ComputedStyleHandler seam and never does true forced reflow (so wrapping it as a component would re-incur the actor-plan P5 engine-confinement cost §2.3 claimed to escape). Two integration kinds (compiled component / interpreter component); profile worlds (document-core / tree-document / html-document / layout-query / canvas / peer-messaging / persistent-storage) over a fake-universal browser interface. Fills the gap actor_constellation_plan deferred as the "future plugin seam": in-process capability confinement of untrusted extensions, the third option between semi-trusted-in-process and OS-subprocess (the P5-descope reasoning targets the engine, not the script, so it does not foreclose this). Supersedes the deferred Extism probe (protocol_architecture_plan). Verified 2026-06-20: WASI 0.3 async shipped 2026-06-11, but CM is Developer Preview + CM 1.0 is gated on two uncommitted browser engines, so native-first (Wasmtime) now, browser-via-AOT-polyfill later. Costs flagged: per-instance runtime multiplication, the per-interaction serialization tax (scene-copy family), and Wasmtime-on-native as an unmade dependency call (a Cranelift JIT in the native process). Reopens Rune on the sandbox-warranty axis (as one adapter, not a first-party placement).

  • document_script_followons_planexecuting 2026-06-23: the spin-out of the four remaining DocumentScript follow-ons after the substrate shipped end-to-end (P0→P2.5 + host permission resolution + the omnibar >attach_script("path") / script_event / detach_script trigger). In order: (1) persistent Session-override store — a script_permissions entry in settings.json feeding the live resolve_attach_permissions so a session-scope document: Deny actually fails an attach (today the live call passes the App default); Graph/Surface scopes deferred; (2) auto-attach — an origin→script binding (user-setting first, mod-manifest "installed extension" later) calling the existing constellation.attach_script path on navigation; (3) render refinements — Resize/Resource re-layout + subresource re-requests for the scripted (ScriptInstance) path, which today only the static StaticDocument path handles; (4) P2.6 AOT (.cwasm + Component::deserialize, codegen off the hot path, first-party only) then the fiber-async fetch capability (sync-WIT fetch as a host async fn suspending the turn's fiber; a net grant defaulting Prompt/Deny). Doubles as the continuation outline (state, seams, file map, commit discipline) to survive a context compaction.

  • node_editor_customization_probeprobe / unsettled: feasibility + design-space map for a per-node editor applet (right-click → "Edit node", later a node facets menu) doing MS-Paint-level sprite editing / bitmap import, whose sprite becomes the node's face texture and shapes its gyre collider hitbox. Feasible: a sprite-as-face is the favicon/snapshot data-URI <img> path (a new Representation::Sprite); bitmap import is the easy on-ramp (the image crate, already a dep); the editor pane composites correctly now the shell z-stack is principled. The hard part is sprite→collider. Frames the hitbox axis (the node's collider derives from its appearance): today fixed ball(NODE_BODY_RADIUS) → step 1 grow with size (approved — the per-node-radius plumbing through gyre's collider + forces + LayoutView) → step 2 a hull/outline from the sprite alpha. Raised off P0-resize: size is a settled scalar knob (shipped); the sprite/editor/customizability is "totally unsettled". Lists the open questions (editor scope, sprite format, collider fidelity, the facets menu, per-node-image persistence, the Representation relationship, scripted/live forms) + a smallest-first step order.

  • settings_lane_consolidation_planSUPERSEDED + archived 2026-08-06 by configuration_ownership_settings_projection_plan: the landed P1-P3 work was meerkat host code (deleted at the Turnstone founding) and the P1 settings-as-nodes model was ruled out by the pane-taxonomy revision; the durable pieces (the pelt SettingsRef lane, the deep-config-vs-quick-gesture line, the diagnostics split) carry forward in the successor. Original: consolidate the redundant config surfaces (the apparatus pane, which conflates settings + diagnostics; the separate single-knob settings overlay; the per-node config scattered in the context menu; the Inspector) into pelt's already-designed but unused Settings lane (ContentSource::Settings(SettingsRef), pelt-core/tile.rs:105, multi-provider). Make the lane THE config surface and retire the others, not add a fourth. Three providers: pelt (global: theme / tab-cap / engines / physics / orrery), node:<id> (the facets menu: per-node representation / size / engine / sprite — the node-editor's home), moot:<id> (community, future). Holds the line: deep config moves to the lane, quick gestures stay in the menu; diagnostics split out (read-only inspection is not config). Phases: P1 host plumbing (the Settings tile-render arm + provider protocol + index spine), P2 the pelt provider + delete the overlay / apparatus-settings, P3 the node: facets provider (carries the node-editor / sprite / hitbox-axis work), P4 diagnostics split + moot. Supersedes the loose "settings → pelt" framing; absorbs the node_editor_customization_probe facets menu. P1 (render arm) + P2 core (overlay + apparatus-settings retired into pelt/*, tab cap on appearance) + P2b (pelt/orrery page) landed + headed-verified 2026-06-21; the menu de-dup spun out to the command-registry plan.

  • configuration_ownership_settings_projection_planC0-C6 landed; shared replacement mechanic added 2026-08-26; C7 deferred by design: the cross-product settings umbrella. Every setting declares scope, movement, mutability, and security; the thing configured owns its typed setting and storage, while providers describe, Cambium renders, and hosts apply. Application, device, persona, session, and artifact stores remain separate. Distillery's third concrete product setting forced pandect::write_bytes_with_backup, a schema-free temp/backup/restore primitive now used by Distillery and Notochord. Knot must migrate from its delete-then-rename path after the WebRTC lane releases its files. C7 remains deferred because Isometry and Cleromancy still lack a forcing personal setting.

  • command_registry_configurable_menus_planplanning (from the settings-lane P2b menu-de-dup decision): today the host has two hardcoded action vocabularies (Command = palette/omnibar, ContextAction = context menu); no action registry/bus exists. Build one command registry in the Zed/VS Code model: every command and setting is a listable, addressable entry (id / label / applicability / invoke) and the single programmatic surface feeding the palette, the context menu, keybindings, and the scripting/automation layer (engine-agnostic; the live automation lane is the rhai omnibar >-shell, which already registers a binding per Command verb; web-content scripting is the separate JS/Nova-Boa lane) — so UI-customization and scriptability are one effort. The context menu becomes a persona-persisted, user-curated subset of commands (config under <persona_id>/settings/ per the persona_model_brief), and the scene-toggle de-dup falls out of the default config. Phases: P1 registry + palette routed through it, P2 every action in the palette, P3 data-driven configurable menu, P4 persona persistence. Settles the registry-vs-pragmatic question (registry, because scripting needs the complete surface). Supersedes the abandoned 2026-05-11_typed_action_bus_plan. Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

  • object_card_planplanning (with Mark); building widget 1: a light, in-canvas per-object action card scoped to the selected graph primitive, holding a customizable, type-scoped set of setting/action widgets (an iOS-Control-Center for graph objects). Renders in the focus-card slot (replacing the snapshot preview when summoned by a context action), deliberately not the context menu (menu = quick gestures, card = config/actions). Unifies three threads: the node facets menu (the node-editor probe, generalized past nodes), the settings-lane per-object provider (node:<id>, the card being the compact in-canvas face of the same data a full settings page renders), and the focus-card slot (a third FocusCardKind). Model: a widget (one control bound to one object setting, drained like the existing button keys), a preset (an ordered widget list defaulted per primitive type), customizable. Phases: P0 widget-1 (the resize-tier stepper − ●●●○○ +, its SIZE_TIERS / step_node_size_tier logic built + unit-tested) in a minimal frame → P1 the widget list + more node widgets → P2 share the node:<id> provider → P3 type presets (edge/field) → P4 customization. Spun out of the node_representation_arrangement_plan resize work. Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

  • swatch_primitive_plan - partially landed; P1/P2/P3a-c done (P3c headed-verified 2026-07-04), P4/P5 partial as of 2026-07-01: builds the swatch primitive from host-generic swatch_view through connections swatch, shape chips, and the remaining edge/visibility/gloss/template phases. Roster/orrery work has advanced cells-as-edges and relation-cell visibility for current (source, target, RelationKind) cells, but the full P4/P5 done conditions remain open: shared element-model edge rendering, per-cell physics/thickness, GraphDefault < GraphViewOverride < SelectionOverride, and spring relaxation are not built. P6 did not land as scoped (reconciled 2026-07-05): the gloss minimap migrated Scene->DOM via the separate, now-archived gloss_scene_to_dom_migration_plan, not this plan's Scope/SwatchInstance component (which itself was never actually built past two bespoke render fns) — a retrofit was scoped and declined as not worth re-deriving shipped, tested work for two consumers; see that plan's 2026-07-05 progress entry. P7 templates remain unstarted.

  • seed_palette_theme_system_plancomplete — T0–T5 + accent harmony, 2026-06-22: re-base register-theme on a small seed palette (primary/secondary/tertiary + neutral + mode) that derives the full ThemeTokenSet, so a theme is ~6 colors not 100+ literals; add user themes (CRUD, fork-on-edit-builtin, per-persona persistence) and mod-authorable theme files (serde ThemeDef, discovery dir — the Zed-grade extensibility bar); a seed-color authoring UI in the pelt appearance page (rainbow HSL sliders + an accent-harmony picker that ties the accents' hue to the base, and contrast-picked on-accent text via best_on). Adopts the shared Merely theming model already shipped in Woodshed (audio_widgets::theme: OKLCH derivation, best_on/mix/contrast, HSL pickers — its doc names Mere a consumer); the color math ports cleanly to Color32 (color-only deps). Everything recolors from the seeds because chrome / orrery / documents already read ThemeTokenSet (the document path is this plan's adoption of the document_style_sheet_plan P5, generalized to the whole shell). Phases T0 derivation engine → T1 seeds→tokens mapping (gate on the contrast validator) → T2 registry on seeds → T3 user themes + CRUD → T4 theme files → T5 authoring UI. §11 decisions: engine port-vs-shared-crate, derivation depth, re-express-vs-keep built-ins, HC handling, theme-file format, override granularity. Builds on apparatus_pane_and_theme_switcher_plan (A1/A2 switcher) + the P3 live-retheme.

  • graph_signals_layer_planplanning (with Mark): one graph signals layer, recomputed on graph mutation (never per frame), feeding three consumers — arrangements, visual encodings, and the gloss lens. Came from wiring the dormant arrangements: petgraph's astar/dijkstra/has_path_connecting/kosaraju_scc are imported-but-unused and cartography::IntelligenceSignals (clusters/affinity/bridges/importance/embeddings) is defined-but-never-computed — the machinery exists, only the producer is missing. Rev 2 corrects rev 1 against a relayed critique (verified): the basic path/SCC/reachability algos are already live in kernel::graph::query (the gap is advanced analyses); the producer is a per-signal cache (generation + dirty bits, cheap-sync / expensive-background, stale-rejection, stable-key rebinding) not a monolithic clock; affinity is a new gyre pairwise force (not CouplingForce, which samples a field per node — keep the streaming adapter until parity); a 2D spectral layout is a SpectralLayout arrangement, not routed circularly through semantic_embedding (reserved for content coords). Consumers: arrangements (community → kanban columns), encodings (centrality → size; community → a ring/halo, since face color is reserved for activation state; the full Projection/overlay plumbing is the bulk of the work), and the gloss swatch as a configurable lens consuming its own ProjectionRequest. Ownership: a new intel/signals owns computation/cache/invalidation; cartography::IntelligenceSignals stays the snapshot contract. The wasmtime-45 async lane is the scriptable-analysis path for the cache's background slot. Phases: P0 kanban/timeline (done) → P1 cheap signals + cache → P2 full Projection plumbing + encoding arbitration → P3 background community → P4 affinity force → P5 spectral arrangement → P6 gloss projection. Spun from the node_representation_arrangement_plan Decision 7. Archived 2026-08-20: complete 2026-06-24 plus the 2026-06-25 polish pass; the stale "P1-P6 open" header corrected on the way out.

  • physics_scenes_and_tangibility_planplanning (with Mark): the build plan for the orrery physics environments research — non-node physics scenes sharing the orrery's rapier world, the tangibility lever, and the two features (living backdrop / interactive scene) + liquid. Core gap: gyre tracks only node bodies (bodies_by_node; sync_nodes reaps to the node set, so scene bodies survive but have no add/iterate/paint API) — so a scene-body concept in gyre is the foundation. The tangibility lever is additive: rapier collision_groups (none set today, gyre/lib.rs:527), flip the node collider's filter (NODE = intangible / NODE|SCENE = interactive; scene-scene independent), per-node or global; gravity_scale(0) floats nodes over a gravity scene; the layout forces must group-filter their cull queries to skip scene bodies. Scene bodies reuse the existing NodeCollider shapes and render in the iso camera plan's ground layer (a faced prop can opt into the billboard path). Content menu, licenses checked: rapier examples2d transplant (drum / card-house / arch / bridge / ball-and-chain / pyramid — Apache-2.0, no new dep since gyre is rapier2d), liquid via salva2d (Apache-2.0, two-way coupling, actor-budgeted), ambient separate sims (particular N-body / nbody-wasm-sim / par-particle-life / sandspiel — verify each), Matter.js as reference. Off-thread on the physics actor with a body/particle cap + is_at_rest pause. Phases: P1 scene-world substrate + intangible living-backdrop MVP → P2 the tangibility lever → P3 scene format + transplant one interactive scene → P4 liquid → P5 ambient separate-sim backdrop. Composes with the isometric_orrery_camera_plan (view) and the scriptable_field_regions_plan (localized scene forces).

  • meaningful_physics_signals_planplanning (with Mark): the meaning phase over the physics_scenes_and_tangibility_plan mechanics — make a physical behaviour carry a true quantity (read at a glance) or afford a real action, never decoration (the no-placebo rule). Two halves: an ambient pulse (the backdrop sims read live runtime/system state — content-fetch / sync / ops / observability — so the field is a calm instrument) and per-node truth (a node body's weight / size / heat reflects facts about that node — Mark's priority). Code-verified signal inventory: real-now per-node = ContentState (Loading/Ready/Failed), degree (out_neighbors/in_neighbors), favicon/state; real-now system = SyncStatus (syncing / ops_received / last_activity_ms, "no placebo"), the observability buffer, steward live-ops, node/edge counts; contract-only (producer owned by graph_signals) = cartography::IntelligenceSignals (importance / affinity / clusters / bridges / embeddings). Key finding: the per-node physical seams already exist (set_node_material / apply_cartography_* / set_node_states), so per-node meaningful physics is a mapping layer, not new physics; the ambient half adds a small AmbientMetrics feed + AmbientSim::set_metrics. Boundary: the graph_signals_layer_plan owns producing graph-structure signals + their non-physics encodings (size, arrangements, gloss, the affinity force); this plan owns the runtime pulse + the physics-binding layer that maps any signal onto a parameter. Captures the design commitments: node physics presets (named / reusable profiles; user picks quantity→parameter; conditional presets), collision-as-ephemeral-relation ("knock twice"), the physics-events × graph-truth confirmation default, and scriptable tags bestowing physical traits (rhai / lua / js / rune) + autotagging. Efficiency: low-frequency metric push, on-change material updates, capped sims, self-throttle under load. Phases: P1 system-pulse MVP (AmbientMetrics → n-body) → P2 per-node content-state → heat → P3 the mapping layer + presets → P4 consume graph_signals (importance = weight, affinity = tension) → P5 collision-relations + scriptable tags.

  • alembic_implementation_planplanning (with Mark; Fleece intent corrected 2026-08-26): the build plan realizing the Alembic memory + engrams architecture seed (the Alembic memory pane, the Athanor distillation daemon, graph engrams). Code-verified that the spine is live: GraphSnapshot to/from, the full eidetic Engram envelope, and eidetic::Store / FjallStore already opened in meerkat (used today for deleted-node tombstones + the content store), so the early work is wiring, not new infrastructure. Net-new: a mere.graph-snapshot/v1 schema + save_graph_engram / open_engram_as_session helpers, the docked Alembic pane (PaneContent::Alembic, Steward-shaped: Recent / Saved / Engrams), the 3-level memory model (short→long promotion via tag/bookmark + configurable eviction), the Athanor armillary daemon (forgetting / consolidation / proposal-emission, R0-bound — never mutates graph truth), and the append-only GraphMutation event log + Timeline. Phases: A graph-engram spine (save/open = the freeze/thaw, on the live store) → B the Alembic pane → C the three memory levels → D Athanor → E event log + Timeline (spun out 2026-07-01, see event_log_timeline_plan). A-D shipped; §E here is now the historical decision record only. Resolved the gating open decisions: redaction (#7 — strip private fields by default, opt-in to include; gates A), settings → Apparatus config (#3), Timeline = orrery scrubber (#6); deferred merge semantics (#1), promote-in-place vs always-distil (#2, lean promote-in-place), event-log shape (#5), the lora lane (#4, its own plan). Fleece Article input remains deferred until the Alembic port has an Article-consuming Athanor path.

  • alembic_tail_and_audit_polish_handoffARCHIVED 2026-06-30 (every item done or already anchored elsewhere). The handoff backlog after the Alembic A–D core shipped (2026-06-24): chrome/pane audit polish (A, all 4 done 2026-06-25), the Alembic tail (B, all 7 done — Athanor idle-cadence P1, by-sessions eviction, engram compose P1-P3 landed 2026-06-30 each in its own worktree + clean-rebuild-verified merge), and the larger spun-out items (C: event log/Timeline, local-models harness) which were already correctly pointing at their own scoping docs. The one item not folded into "done", rkyv engram compaction (B6), is parked in engram_compose_merge_plan.

  • graph_view_curation_and_interaction_planplanned with Mark; shared slices not started: one gated interaction/curation system for root Canvas, bounded Cambium Swatches, mer3ly, and later remote Graphshell projections. Promotes rather than rebuilds the proven seams: Canvas already has Seiche pull/release and relation-cell selection, the exported/tested GraphJournal already has attributed delta replay but still needs session-host wiring, pane view intent already persists hidden cells/camera/focus/strategy, Cambium already has captured drag + a continuous slider, and Isometry is the second Swatch consumer. Six proofs: pull → relation strip + Link card and per-cell curation → fold selection/explicit descendants → source-time adapters + shared scrubber → historically exact mer3ly repository playback (including archived Graphshell and old WebRender lineage) → live/frozen sharing. Keeps source time distinct from Scenotime delivery revisions and keeps recipes/intents outside Sceno. Supersedes the implementation substrate and scrubber portions of the July 1 event-log plan.

  • event_log_timeline_plansuperseded for implementation 2026-08-03; historical decisions retained: Alembic slice E's undo/restore distinctions remain useful, but its proposed new GraphMutation log and discrete SliderSpec scrubber are obsolete. The implemented GraphJournal of attributed CapturedDeltas and Cambium pointer/slider substrate are now the implementation authority through graph_view_curation_and_interaction_plan.

  • graph_write_path_migration_plandone 2026-07-01: finishes the Phase 6.5 single-write-path boundary the kernel declared but never enforced. Every primitive durable mutator on Graph (~52 across six files, plus the get_node_mut/get_edge_mut escape hatches) is now pub(crate); shell/runtime code routes through GraphDelta/apply_graph_delta (extended with 16 variants — navigation/history, tags, body, properties, classifications, derivations, predicates, fields/couplings — plus ergonomic wrappers that keep the funnel). Four writer classes documented at the boundary comment: delta-routed primitives, pub compound kernel ops (from_snapshot, cross_graph::copy_*), pub transient-state exemptions (positions, session counter, lifecycle), and a fixtures cargo feature (dev-deps only) re-exposing raw mutators to ~19 test modules via a GraphFixtures extension trait with call sites unchanged. Migrated production sites in orrery, aether, platen, linked-data ingest, inker statements, and meerkat (web_clip + command_drain body writes); the compiler's E0624 pass caught sites grep had missed, including one production remove_node in meerkat's move-node-across closure. Prerequisite hardening for event_log_timeline_plan's one-function recording hook.

  • persona_transport_unlinkability_plandesign (with Mark); no code yet: the persona-transport privacy model — how a persona's network presence is (un)linkable to you and to your other faces, the modes offered, and how transport couples to tessera standing. Framing axis: reputation is the cost of continuity, anonymity is the cost of starting over, so a persona's transport mode and standing tier are one slider (main = master endpoint + full standing; burner = fresh chain + most-unlinkable transport). Four leaks (NodeId, discovery, IP, timing) named against six adversaries (moot member, directory, relay operator, direct counterparty, home-ISP/subscriber-map, global passive). Grounded: per-persona NodeId is a caller choice (bind takes a keypair); the companion docs now standardize the convention as derive_keypair(BLAKE3('persona' || persona_id)); discovery is off-able + iroh-tickets give discovery-free invites; iroh relays are NAT-fallback not deliberate routing; mesh M1 proves multi-device sync but a persona is a context boundary not a network one — the seam is product ownership, not an iroh limitation. Near-term: Mode 1 (per-persona NodeId + discovery off + ticket-only) + the relay-diversity half-measure. The core: the own-device-cluster family — self-hosted iroh relay + home-egress + WireGuard/headscale glue, where the glue re-origins below iroh so it needs no deliberate-relay API and is buildable today; it hides your current location from peers with zero third-party trust but not your household from your home ISP (location-unlinkability, not anonymity). Sequencing: Mode 1 now → own-cluster-via-WireGuard next, with the device fabric now stated cleanly as identity-level DeviceRoster + persona-level PersonaManifest.egress → mesh-job relay + friend-relay later → Nym research.

  • reticulum_transport_planactive probe: add an optional ReticulumTransport backend to crates/murm/transport using the Beechat Rust reticulum crate. Corrected after source review: identity is a deterministic dual-key derivation from the Mere master seed; discovery is announce-based with a Mere-master-key signed PeerID binding in app_data; stream wrapper is built directly on LinkEvent::Data because v0.1.0's buffer module has no stream abstraction. Limited to bilateral stream connectivity; sync and blobs remain iroh-only.

  • comms_gating_and_key_addressing_planplanning (with Mark); decisions taken 2026-07-06: comms off by default, local and network separately user-gated (generalizing the locked-startup UnlockNow/LockNow seam), join ticket auto-shown on go-online with honest refresh-vs-rotate verbs (a ticket is an addressing hint, not a capability; invite revocation belongs to the sync-admission gate), per-persona transports with several personas online at once (transport plan Mode 1's host surface), then a key-addressed misfin lane (mere/misfin/v1 ALPN over iroh; the cert is already the identity, the LAN IP only routing; LXMF/reticulum as the later store-and-forward tier). Firewall posture verified: the misfin TCP :1958 listener is the only true inbound bind (Windows consent prompt at gesture time; firewalld needs an instruction), p2panda's UDP bind needs nothing. G6 research done up front 2026-07-06 (see the LXMF research brief below): blueprint over protocol — store-and-forward mail as voluntary hosting over iroh, tessera-gated ingestion instead of PoW stamps; protocol-level LXMF stays an optional later bridge. Code deferred until the one-state migration lands. Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

  • lxmf_key_addressed_mail_researchresearch complete 2026-07-06: LXMF ground truth (content-addressed signed messages, 111-byte overhead; opportunistic/direct/propagated delivery; peering propagation nodes = distributed encrypted store; PoW stamps 0-32 bits with ticket exemptions; crypto = RNS 1.3.x X25519/Ed25519/AES-256-CBC, unaudited) plus the Rust-ecosystem finding that changed the calculus: FreeTAK lxmf 0.6.0 (2026-06-30, EPL-2.0, own reticulum-rs stack, partial Python parity with pinned interop evidence) vs the Beechat reticulum 0.1.0 the probe pins (stale since 2025-10). Recommendation C taken: misfin-over-iroh for direct mail, LXMF-the-blueprint (not the protocol) for the offline tier as the mail instance of voluntary hosting, protocol interop as an optional later bridge. (2026-07-24 addendum: retinue's landing re-prices the bridge to a small spec-based codec sibling, sennet posture; the radio business adds two demand arguments — day-one Sideband interop for flashed radios, and LXMF propagation as a managed-network V9 offered role.)

  • persona_wallet_carry_layer_plandesign plus storage, first host-adoption, typed signed-grant, remote-auth grant-issuance, wrapped private-epoch crypto-helper, pairing-transcript helper, pairing ticket/code helper, first Meerkat pairing-host, delegated-device response/SAS preview, enrollment-bundle, and delegatee enrollment-host/bootstrap-preservation slices landed 2026-07-02: companion to the transport plan — the wallet as "Layer 0", the universal carry layer. One model: everything is a signed content-addressed object, so carrying a persona / engram / history = carry the reference + key, let bytes sync. The structural correction is now explicit: the carry layer is split across an identity root and persona roots. Identity-level identity/wallet.json + device-roster.json + per-device grants own the master-seed recovery posture and the "author your devices once as a fabric" reality; each personas/<persona_id>/wallet.json owns only persona-scoped refs and epoch history. Code now exists for that storage seam in session-runtime::wallet_store, Meerkat now seeds/loads it at startup, corrects active_persona on session load, points sync/comms at the shared identity root instead of separate ad hoc seed files, carries a typed local delegated-device identity bridge for remote-auth response generation before the keychain-backed version exists, and now preserves pending/enrolled delegated-device state at startup/session load instead of reseeding copy-mode wallet state over it. session-runtime::wallet_grant gives identity/grants/<device_id>.cbor a typed signed CBOR envelope with signing, verification, stable grant refs, remote-auth issuance that keeps the roster and identity-wallet grant index coherent, XChaCha20 wrap/unwrap helpers for the wrapped private-epoch payloads themselves, deterministic derivation of both the wrapping key and the short auth string from a shared pairing secret plus device identities, a typed pairing ticket/response seam with CBOR QR payloads plus manual pairing-code formatting/parsing, and a typed remote-auth enrollment bundle that carries the signed grant plus persona wallet manifests into delegatee-side restored wallet state. Meerkat now writes pairing artifacts under <mere_root>/pairing/, can mint the delegator-side offer, generate the delegatee-side response artifact from a stable local device identity, preview the SAS before issuance, export the enrollment artifact on accept, and install that artifact on the delegatee side. The remaining bridge is explicit: identity/master.seed and the local delegated-device identity file are still temporary plaintext bridges until the encrypted/keychain handoff lands, and the live implementation seam is now narrower: the actual PAKE exchange, Meerkat host-side QR/SAS flow, per-persona epoch history usage, private-epoch rotation, private.read handoff, and the encrypted seed handoff. Pairing stays two modes, one ceremony (PAKE + short-auth-string, caBLE UX) — remote-auth the default, stated concretely as two payloads: a meadowcap delegation cert plus the wrapped private-lane epoch material the device needs to read encrypted-at-rest private data without receiving the seed. Copy remains the explicit "fully me" path (transfer the 32-byte seed; un-revocable so loss = master rotation). The privacy dial is the existing eidetic PrivacyClass (LocalOnlyTrustedPeersOnlyMootScopedPublicPortable), with one important clarification: LocalOnly is persona-local, not single-device-local. V1 now scopes TrustedPeersOnly wrapping to your own device roster; external-peer wrapping is a later contact-identity lane.

  • operator_presence_overlay_plandesign (with Mark); no presence code yet: live, ephemeral, multi-scale focus presence — a colour-tagged ring around the node an operator is on, descending into the node to highlight the document section they read (Zed-follow, but graph-native). One operator, three sources: an agent (armillary actor / geist), a co-op guest (remote persona), and you — same overlay, same colour-tag, same comet trail. Mostly already rendered: the cartography Overlay channel (ClusterHalo / BridgeEmphasis, position-independent + coloured + multi-consumer) takes a new OperatorFocus variant; agent_harness.rs already exposes AgentObservation.focused_node + the a11y projection (the agent already has a focus, and a document already is a tree of a11y sections); the find-overlay highlights document rects; node colours + selection rings exist. The web-clip inspector is the same primitive one scale down — picking a document element (elementFromPoint + rect + highlight) where your cursor, an agent's focused_node, or a guest's presence are interchangeable sources of {target + rect + coloured highlight}, so inspector + into-node presence + clipping share one element-targeting primitive. The one new piece: an ephemeral presence channel ({operator, colour, scale, target, trail} gossiped/emitted, rendered, expired, never folded into the durable event-DAG — the standard multiplayer-presence shape). Build path: agent-local presence first (no network, rides the harness + overlay today, "watch your AI think in the graph") → into-node a11y-rect highlight → the clip inspector as the local-cursor source → co-op guests over gossip when the co-op lane lands (MW3 fan-out across windows). Open: multi-operator stacked vs blended rings; trail-as-comet vs trail-as-agent-graph (durable, per the agent-as-graph idea); presence-as-privacy-surface (broadcasting your focus is opt-in, a presence-shaped instance of the persona privacy dial); element-anchor stability across re-layout. Permissioned recording spectrum (2026-06-25): visibility is governed, not just live — ephemeral / public-immutable / private / one-way-glass (mods see, members do not), the private/public/ephemeral dial pointed at conduct plus asymmetry, with the constitution owning the policy + the capability gate enforcing who-sees + the event-DAG as the record. A moderation/adjudication substrate (plugs into tessera concord/reciprocity). The line: policy transparent even when data is restricted (no covert surveillance; consent-by-joining). Two grants, not one: your conduct and your agent's activity are separate (guests can't watch your agent by default; a moot may require agent transparency as a charter condition).

  • isometric_orrery_camera_planplanning (with Mark): the 2.5D-isometric rung of the orrery physics environments research — an isometric, orbitable camera with fake height over the existing 2D rapier physics (no rapier3d, no new render lane; full 3D stays its own gated plan). Thesis: today's screen = world*zoom+offset (orrery CameraView types.rs:17, platen Camera scene_paint.rs:85) is the degenerate iso at (yaw=0, tilt=1), so one parameterized planar camera {offset, zoom, yaw, tilt} unifies 2D + 2.5D and the mode toggle is a scalar tween, not a branch. The frame's existing ground layer (underlay edges / fields / demoted dots, inside the camera PushTransform) vs on-screen layer (gnode DOM cards + favicons) maps onto ground-shear (correct: edges lie on the floor) vs upright billboards (cards must not shear) — so a blanket iso matrix is right for the ground, wrong for the cards. Physics untouched (world coords; drag pins via screen_to_world, gyre hit_test world-space). Phases: P0 consolidate the projector (funnel the ~8 open-coded forward world*zoom+offset sites + the one inverse screen_to_world lib.rs:1421 through to_screen/to_world/ground_transform; fix world_viewport cull to 4 corners under yaw; pixel-identical at 2D) → P1 iso ground + upright zoom-scaled billboards at height 0, depth-sorted by per-gnode z-index (RepaintOnly path) → P2 free-cam orbit/tilt + the view.projection.set registry command + view-intent persistence (CameraView/CameraSnapshot gain yaw/tilt, serde-defaulted) → P3 fake height + ground shadows + height-aware pick/drag (height source a setting). Open: orbit gesture binding (lean Alt+drag, keep middle-drag pan), iso tilt preset, LayoutTransform rotation API check.

  • gloss_outline_lens_planplanning (with Mark): a hierarchical djot outline of the graph + a metrics readout as the gloss Navigator's deferred outline form factor (the interaction-model spine's named "gloss-outline / A3", the first notetaking feature). Implements existing design, does not re-design: realizes the gloss_navigator_design G3 outline factor + its §2a DOM-not-Scene decision (the textual outline is the first DOM gloss section, the wedge the Scene-textured minimap/recent later follow), consumes graph_signals_layer_plan P6 for the expensive metrics (centrality/community via the unbuilt intel/signals, never reproduced) with cheap-counts fallback, and registers as the sixth projection under the graph_projections_research contract + gloss no-split rule (a lens within the one Navigator, not a new pane). The pure Graph->view logic (outline_djot/graph_metrics) lands in the crate slice 4 freed up: mere-orrery renamed to glossary at crates/graph/glossary/ (settled 2026-06-23), sibling to linked-data (the human-digest projection beside the machine-interchange one; folding linked-data in considered + declined); drops the dead a11y project_graph. Outline nests by parsed URL structure (host -> path from each node's address) not containment edges — a code check found UrlPath containment is not auto-populated, so reading it would be flat; explicit containment overlays where present. Cheap metrics (counts/degree/components) are free in kernel::graph::query. djot because it is live (jotdown 0.10 / nematic knot engine), so the outline doubles as an editable knot — the notetaking payoff. Phases: P0 the projection crate (rename + outline_djot/graph_metrics behind tests) → P1 the gloss DOM section, shipped + headed-verified 2026-07-01 (rows route SelectNodeByUrl, carry node color/selection) → P1a a11y wiring (new, scoped 2026-07-01) → P2 hierarchy+scope lens (forme::ProjectionLens) + now also settles the depth/breadth-cap open decision (dynamic, viewport-driven row budget; full export stays uncapped) → P3 signals-fed metrics (gated on graph_signals) → P4 knot-ification + curation write-back via assert_relation. Spun from the slice-4 mere-orrery-consumer-less finding (unified_document_host_plan Progress 2026-06-23). Metrics-surface-split decision settled 2026-07-01: gloss keeps bare node/edge/component counts, full breakdown moves to apparatus. Scene->DOM for minimap/recent spun out 2026-07-01 into its own plan (below).

  • gloss_scene_to_dom_migration_planP1-P3 landed, headed-verified, 247/247 tests green (2026-07-01/02): converted the gloss pane's remaining two Scene-textured sections (minimap swatch, recently-visited list) into real DOM, folded into the same unified shell document as the roster and the P1 outline — finishing the migration gloss_outline_lens_plan deferred as its Open Decision #5. Design-reviewed before writing down: a Plan-agent confirmed against the pinned genet commit that xilem-serval has no SVG-like tag (only <external-texture> is special-cased), so embedded-Scene-for-edges is the only viable option, not just the chosen one; the review also caught that frame_a11y_panes.rs's gloss_a11y_tree() reads gloss_node_rects/gloss_recent_rects directly for a11y bounds, making bounds migration a required step of cleanup, not optional. Minimap nodes became real DOM squares (mirroring the orrery's own gnode_view) while edges/community-bridge rings stay a Scene raster embedded via a new <external-texture> (a fresh reserved key disjoint from ORRERY_SCENE_KEY) — the same DOM-backdrop-plus-DOM-gnodes split the orrery pane itself already uses; recent became plain DOM rows. P2 surfaced + fixed two real rendering bugs (a spurious third position: relative level corrupting the whole chrome document; an opaque .gloss-minimap background erasing the edges backdrop). P3 deleted the bespoke Scene hit-test path (gloss_node_at/gloss_recent_at/gloss_leaf_rect, the press.rs branch), folding PaneContent::Gloss into chrome_routed_leaf_at's whole-leaf list. Also fixed the screenshot harness's silent-wrong-window capture bug (two fixes: in-app self-capture off the GPU texture; ffmpeg ddagrab full-desktop fallback) and recorded the chrome_us 100-145ms/frame paint-cost-scales-with-DOM-size finding, now carried forward in the UI polish plan.

  • browser_extension_companion_planplanning (with Mark): deliver Mere as a browser extension / PWA that reuses the portable orrery core (kernel/gyre/aether/arrangements/cartography, code-verified wasm-clean) and the existing render_as_cards DOM-card seam, while a paired native companion node carries what a tab cannot (raw-socket fetch incl. smolweb via errand+nematic→HTML, the full genet/inker engines, iroh p2p, heavy compute). Two render targets composited by the browser: DOM (node cards + smolweb pages) and WebGPU/Canvas2D (the graph underlay only). Drop the "be a browser" stack (genet/inker/pelt/meerkat-host); keep the data/logic core; adapt storage (IndexedDB/OPFS) + scripting (Boa / jco-AOT, no JIT). Activates the dormant federatable eidetic BrowsingMemory/BrowsingTrace as the consented-capture sink (the extension is its natural driver). The companion is a local daemon over localhost, and a permissioned WebTransport ingress (a capability-scoped relay, unlike iroh's dumb holepunch relays) for remote/PWA tabs. Phases P0 wasm-core build (feature-gate the genet gnode pool) → P1 orrery-in-a-tab DOM cards → P2 consented capture → P3 smolweb-in-tab → P4 engram export → P5 companion bridge → P6 p2p via companion → P7 companion-less WebTransport ingress. Targets the orrery crate, not mere-orrery (which is being renamed to glossary). Node/delivery framing superseded 2026-06-24 by orrery_browser_lane_plan (capture-first, favicon-body nodes not DOM cards, gloss sidebar + orrery discrete tab, baseline cross-browser, no-sync v1); the companion / smolweb / p2p / federation half here stands as the forward vision.

  • orrery_browser_lane_planplanning / design 2026-06-24: the capture-first reframe of the browser delivery, superseding the companion plan's "orrery-in-a-tab live DOM cards." Thesis: the browser is another host for the orrery the way pelt is (the same window-agnostic component, new host adapter); capture is the product (a private, durable, queryable browsing memory in the Mere data model: snapshots + genet-extract content + nav provenance + the relational-browse link neighborhood), the views secondary. The node is a physical thing, not a document: a DOM object (gyre-positioned element) is not a DOM document (the bad inference that yields cards/snapshots/live-previews-as-nodes); a node is a content-type-coded shape + favicon, sprite-with-adjustable-hull for customization, with the snapshot demoted to an on-select side preview and the page opened in a real tab on click (map vs territory). Cross-browser (Chromium/Gecko/WebKit) is the easy path here precisely because it does not run a web engine in the browser (no Nova/Memory64/SAB/COOP-COEP needed; the browser browses), so the orrery is baseline wasm32 + OPFS + WebGPU/Canvas2D + WebExtension MV3; WebKit's only friction is Safari distribution (Xcode wrap) + WebGPU maturity (Canvas2D fallback), not capability. Form: an extension (capture needs it), three surfaces (background capture, gloss sidebar, orrery discrete tab) over one OPFS store, no native sync in v1. Assembly: reuse orrery + eidetic-core/eidetic-opfs (the browser-side consumer that activates Phase 7, gates a/b/c measured + "pack small blobs") + genet-extract + glossary + netrender; new glue = the browser host adapter (Scene→WebGPU + gyre-positioned node DOM + input + the capture pipeline); drop genet/inker/pelt/host/Nova-Boa/companion. Phases P0 baseline-wasm core (measure bundle size) → P1 capture → P2 gloss sidebar → P3 orrery page → P4 cross-browser packaging. Tracked followups: knot (notetaking via nematic/illume), clipping (selection-grain capture), filesystem shaping for permissioned meerkat read (OPFS is origin-private; a File-System-Access-API export/mirror to a user-granted dir is the sync-less bridge to native), and auto-update (the load-bearing half is data-format migration via the format-versioned engram contract, crucial for native Mere's updater too).

  • orrery_custom_layout_element_planparked / deferred: the unified-document-host plan's Phase-2 cond 1, spun out on that plan's closeout. Makes the orrery a real genet custom-layout element (Mechanism A: a marker-attr layout mode + a per-child (x,y) position concern + a position-only incremental path) so gyre-positioned children carry their position in the layout fragments, retiring the per-consumer accumulated_translate transform add-back. Deferred by design: the interim transform-aware focus ring + the slice-4 DOM-sourced a11y bounds hold the visible behaviour correct without it; un-park when a new orrery-interior consumer (text selection / IME carets / find rects) needs fragment-correct geometry, the per-frame transform-set shows a perf cost, or secondary-orreries wants the element form. Mechanism B (left/top from gyre) rejected (layout-tier = per-frame relayout = the orrery-freeze). Engine-side work; the genet ask is documented.

  • layout_phase_split_probe_planplanned: the unified-document-host plan's pressing slice 5 (documented-only there), spun out on closeout. Build the cascade-vs-box-tree-vs-shaping phase-split probe in genet-layout: a native-release timing harness (cfg-gated out of wasm + the hot path) that times each phase of a cold layout and reports the split. The measurement prerequisite the cross_platform_parallelism_strategy §0 names for the whole parallel-cascade thesis (box-tree build is sequential, capping the win) and the wasmtime-async SSR/edge lane; gates goal 2 (gpui-level baseline perf). Small-Medium, pure measurement. Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

  • native_session_store_planHTTP/session work landed; scripted-cookie wiring landed; active for storage/partition tails: Mere's native session + storage store, surfaced building the verso flip (carrying a login across engines). Cookie convergence now has a shared netfetcher session jar, persona-keyed incremental persistence in the durable store, lossless structured cookie records for verso, and a genet.scripted JarCookieProvider so page JS document.cookie reads/writes the same jar while hiding HttpOnly. Remaining: flush dirty JS-set cookies on host drain, add eidetic-backed (persona, origin) localStorage for the scripted rung, implement flip-back SESSION import, replace the process-global in-memory jar with live per-persona jar selection, and later add top-level-site / Partitioned web-privacy refinements.

  • documentscript_net_hardening_planexecuting 2026-06-23: triage + fixes from an adversarial multi-agent review (21 confirmed findings) of the DocumentScript net.fetch backend + mod-manifest auto-attach. Headline: the net capability as built is "open internet with the user's ambient cookies" (credentialed SSRF + readable cross-origin exfil) — the design gap to close before net is ever user-enabled; treat net.fetch as prototype-only until the credential/origin-scoping fix lands. Landed this pass: net.fetch egress floor (scheme allowlist via is_fetchable, loopback/RFC1918/link-local/CGNAT SSRF block, a 30s overall timeout so a slow fetch can't wedge the tile actor), mod-trust (manifest-capability intersection so a mod gets net only if it declares Network, component-preamble validation, deterministic + deduped binding discovery, userinfo/port-normalized origin matching), and script lifecycle (deactivate on navigation, detach-on-reattach, detach-a-trapped-script). Deferred (tracked §A1/E1–E3): origin-scoped uncredentialed net, true non-blocking fiber suspension, mod install/approval + signing, per-turn fetch rate limit, body-size cap, .cwasm mod discovery, exact HTTP status. Two raised findings refuted (validating the fail-closed origin matcher + the additive content-type WIT change).

  • render_ladder_and_extraction_planpartially integrated in Meerkat; remaining host/storage tails: frames the page-JS lane as a rung on genet's profile ladder, not a static-path replacement, plus the orthogonal analysis/extraction axis. Two axes: (1) the render ladder static → interactive → scripted → fullweb (+ scrying.web WebView fallback) — principled compositions proven by their dependency graph (a static page never pulls script/mozjs; attack-surface + bundle-size + DOM-as-library), selected per-node by the existing inker engine picker (engine_pins); (2) parse-and-extract, no render — a crawler/scraper feeding the eidetic browsing corpus + the flora distillation lane, riding any rung's DOM (static-parse, or headless-scripted-DOM for SPAs). The old "meerkat is static-only today" finding is stale: Meerkat now has an opt-in genet.scripted rung using ScriptedDocument<BoaEngine>, a script fetcher, and document.cookie over the native session jar. Remaining: host-input → DOM-event completeness, durable localStorage backing, broader routing/default-policy decisions, and the extraction profile. Lights up the native session store 6a/6b seams and the relational-browse + eidetic-derivation extraction lane. Grounded in genet's docs/2026-05-12_genet_profile_ladder_plan.md.

  • relational_browse_graphlet_planV1+V2 built; crawl controls shipped + headed-verified 2026-06-25; V3 (eidetic capture) + federation downstream: a bird's-eye relational browse (a page's link neighborhood on the graph canvas, not the tab funnel) as the front-end that feeds the already-built eidetic corpus/index back-end and makes that corpus richer (real negatives in context, the candidate set as the unit, human curation as the label instead of an LLM judge). V1 single-hop link-graph materializer: the one new primitive was a rect-free anchor enumerator over LayoutDom, now built as genet-extract::extract_links (render-free); everything else is an existing pipe (fetch_pageStaticDocument::parse → resolve_href → a GraphContribution of Semantic:Hyperlink edges → ContentUpdate::Contribution → constellation pairs+applies → orrery arranges the cluster). No new contribution type (apply_contribution already maps the hyperlink predicate IRI to a typed sub-kind). V2 second-hop sibling fetch on a dedicated crawl actor (a frontier: depth/fan-out cap, per-host politeness, robots; URLs from an independent-index API or sitemaps, not a scraped SERP). V3 relational capture into eidetic (candidate set + curation decision on BrowsingTrace; supplies the genet-side text-extraction seam the eidetic browsing derivation plan parks as a named trigger). Downstream is cross-linked, not built here: index federation (eidetic Phase 9 consume) leads (built), the flora (federated-LoRA: personal adapters federated to specialize community models/agents, with tessera + moothold/coalition per communal_compute_tiers) lane follows (designed). Settles LoRA-vs-RAG by the two-lane split (index = what's out there now; adapter = how you navigate). V1 (single-hop materializer) + V2 (crawl actor: frontier, robots, sitemap seeding) are built; the crawl controls (>crawl_stop, progress chip, pelt/crawl scope/depth/page-cap/whole-site settings) shipped and were headed-verified 2026-06-25; V3 (eidetic relational capture) is moved to the capture_provenance_consent_plan, which generalizes it into one live record (traversal + candidate-context + provenance + consent) plus the live recorder meerkat lacks today.

  • djot_editor_knot_nodes_planplanning (with Mark): adds the write side to a knot/djot stack that is already read-complete. Owns three threads: the djot editor surface (pure-Rust, one djot parser + curated inner lexers: jotdown 0.10 is the single parse — parse-only, no AST/writer, source text is truth, Engine::render(text/x-knot)Blocks → blocks_to_djot unchanged — feeding both meaning (blocks) and the editor (highlight spans + a container tree from its nested Start/End events for folds/outline/structural-selection). Injection (the headline: a polyglot block's inner rhai/html/svg highlighted in its own language) is a pluggable InjectionLexer registry, one engine, keyed off the fence/lang label: precise built-in lexers (quick-xml [already a nematic dep] svg/xml, html5ever html, rhai's tokenizer scripts), a curated logos pack for broad coverage (a DFA lexer — faster than tree-sitter or any regex engine for the coloring job — pure Rust, wasm-safe, tiny; one small authored lexer per language, since no logos library exists), and logos mods registered at runtime (the "lil mod parser for your concern" path). Injection needs only token coloring, not a tree, so jotdown-plus-logos is the whole pure-Rust, wasm-safe, build-apparatus-free stack. Optional breadth hatch: tree-sitter via syntastica (runtime-c2rust, wasm-safe via c2rust, at its git-build friction or a vendored mere-grammars fork); regex-grade synoptic/syntect [pure Rust on default-fancy] are the other ready-made-library option. An unwired label renders plain. Editor extends the already-multi-line xilem_serval::TextInput; edit on the genet field, preview on inker document-canvas [both already do per-range styled text]. The whole stack builds for wasm32-unknown-unknown like the rest of the app, so there is no PWA/wasm build question; tree-sitter is an optional later branch only if arbitrary-language injection or its error-tolerance is wanted (then tree-sitter-djot v2.0.0 + tree-sitter-c2rust runtime + cc-shimmed grammar; the runtime-grammar wasm feature is a banned wasmtime JIT). gpui/Zed cues lifted: anchors [stable clip-provenance offsets], block decorations [inline web-clip], action/keymap → command registry, undo transactions); the editable knot node (a node whose body is a knot you author in place — decided 2026-06-24: an inline body on Node + PersistedNode variant for the live note path, knot:// AddressKind + eidetic publish deferred to federation so the scheme is never dead); and the web-clip gesture (hover-pick an element on a live scrying tile via execute_script_with_result/elementFromPoint, capture its HTML subtree (semantic tier) + optionally crop its rect from capture_snapshot_png (rendered tier), feed build_clip_knot, spawn a knot node, assert the modeled-but-unwritten ProvenanceSubKind::ClippedFrom edge — its first live writer). Code-verified that both knot engines are registered and djot is the routed text/x-knot default (an early mapper's "experimental/unregistered" claim was wrong). Phases: P1 editable knot round-trips in memory → P2 highlighting + new-note command + inline-body persistence + sniff for md/txt → P3 pure-Rust editor pipe (jotdown container tree → fold/outline/structural-selection; per-language lexer dispatch → injection-highlighted polyglot blocks) + slash/``-completion affordances (eval gated on a host evaluator, inert for received content) → P4 semantic clip→node + consent → P5 on-site cropped-texture swatch tier → P6 (deferred) html5ever fragment fidelity + knot:///engram publish + richer span fidelity. Extends, does not re-scope: the nematic [polyglot (`design_docs/nematic_docs/implementation_strategy/2026-05-08_polyglot_knot_design.md`)/[resolver (`design_docs/nematic_docs/implementation_strategy/2026-06-13_polyglot_block_resolver_plan.md`)/evaluation (`genet/design_docs/archive_docs/2026-09-02/2026-06-12_knot_evaluation_export_plan.md`) plans (vocabulary + HTML/span fidelity = K4), gloss_outline_lens_plan (owns the outline-as-editable-knot payoff at its P4; this editor is the shared writing surface), node_body_face_model_plan (clip swatch kind), command_registry (note/clip actions as command ids), scrying_tile + render_ladder_and_extraction (live tile + extraction axis), and in-the-wings synergy #4 (the new-note wire as the dominant gap). Risk headline: jotdown round-trip is lossy by design; the inline-body schema change is the highest blast radius (isolated to P2); `controls.rs` (696) is already over the 600 LOC ceiling and `djot.rs` is at 571, so every editor layer lands in a new file; the pure-Rust editor builds for wasm32-unknown-unknown like the rest of the app (no PWA/wasm build question); the injection engine is `logos` (a DFA lexer, the fastest pure-Rust option, wasm-safe, no build apparatus, since injection needs only coloring), so the cost is authoring/maintaining a small lexer set rather than consuming a grammar library; an unwired language renders plain, tree-sitter (`syntastica` c2rust) is the optional breadth hatch at its build-friction cost, and the registry + curated lexers are net-new code Mere owns.

  • federation_interop_planscoped, not started: two federation-interop mechanisms from the borrowed-ideas brief, scoped at Mark's direction before the knot-editor resume because both are load-bearing and retrofit-painful. (1) Engram schema lenses (Cambria): bidirectional JSON lenses between engram SchemaRef versions so peers on different schemas read each other's engrams (the shipped alembic core has no schema-evolution path); a (from,to) lens registry beside the engram schema registry, consulted at the sync/projection boundary, inert when no chain resolves. (2) Capability-scoped subgraph sharing: object-capability tokens (Meadowcap / UCAN / Keyhive, p2panda-dependent) for "peer X may read subgraph S, revocably" with no server; scope = a graph-cluster namespace, dovetails Tessera + the tier framework, revocation via epoch/key-rotation. Explicitly the federation capability sense, distinct from the in-app capability-gate catalogue + DocumentScript confinement. Lenses lead (engram-local, unit-testable); capability sharing follows (needs p2panda + a borrow decision). Design-level only.

  • mcp_native_graph_planscoped, future, not yet: MCP (Model Context Protocol) as Mere's agent boundary, both directions, from the borrowed-ideas brief. Expose: Mere as an MCP server offering the graph (nodes/edges/queries/crawl/clip) as tools + resources, riding the existing command registry ActionRegistry as the tool set (the harness already runs over Command::ALL), mutating tools behind the capability spine + consent + provenance-on-every-mutation. Consume: agent nodes + the harness gain an MCP client to reach external servers; read scope can reuse the federation_interop capability work. Expose leads (higher-value, rides the command registry, no new agent runtime). Design-level, no work scheduled.

  • illume_text_lexer_planplanning; two pieces shipped: promote the knot editor's highlight core to a standalone, crates.io-only sibling crate, illume (a pure-Rust, wasm-safe lightweight text lexer + highlighter: jotdown djot + the logos pack + the InjectionLexer registry + prose-entity passes for URL / @mention / #tag), serving the editor and all host text (omnibar, comms). Three-piece architecture: illume (lexer: text → (range, SyntaxKind) spans) + tinct (palette: SyntaxRole → contrast-gated colour derived from theme seeds; tincture's necessary published name, since tincture is already taken on crates.io by another OKLCH crate) + genet styled_textarea (renderer: styled <span> runs). The host owns the SyntaxKindSyntaxRole seam, keeping illume and tinct independent of each other. Motivated by the omnibar / TUI-comfort north-star: the lexer is the legibility layer for a keyboard-driven interface (omnibar = its first non-editor consumer, text as a first-class surface), sharpening the control rule to "drive and read the whole thing from the omnibar." Shipped: tinct's syntax module (perceptual contrast-gated palette, tincture 03661ce) + genet's styled_textarea (genet 6a3ceace). Captures the #1 (colours derived, not hardcoded) / #2 (one style-aware field body) / #3 (KnotEditor → stateless deriver, host owns the buffer) resolutions. Remaining: illume rename + entity passes, the bridge (editor then omnibar), the deriver refactor, extraction + publish.

  • capture_provenance_consent_planplanning (from the 2026-06-26 cross-cutting state audit); no code yet: the keystone the larger browsing-data vision is missing, one live capture record carrying where you went, what you chose among, where it came from, and what may leave. The audit found (against code) that nothing in the running app writes a BrowsingTrace (zero meerkat callers of record_traversal/save_trace/project_lineage): the eidetic sink + schema (E1-E4) are built, the live tap is not. Phases (done-conditions): C1 the live recorder (meerkat navigation/crawl tap → durable trace, LocalOnly, honors an incognito exclusion from day one) → C2 candidate-context (the candidate set + decision, absorbed from relational-browse V3; the V1 neighborhood is its observation point) → C3 Provenance-family edge writers (ClippedFrom/ExcerptedFrom/etc, defined in graph-kernel but written by nothing live; one mechanism, three payoffs: tessera pricing, legality, index legibility) → C4 consent + retention + forget + a federatability class (the privacy membrane no plan owns; apply_quota keep-N is all that exists) → C5 route genet-extract::extract_text/main_text into eidetic-search (the parked text-extraction trigger, now fired). Threads the membrane fields from the first traversal because they are free at write-time and unrecoverable in bulk later. Absorbs relational_browse V3; activates the eidetic derivation page-text trigger + E1 granularity question; feeds (does not build) Phase 9 consume, the flora/geist lane, tessera pricing, and dovetails the mcp_native_graph "provenance-on-every-mutation" + consent spine. Naming resolved 2026-07-12: fauna is the shared-engram catalog; flora is federated LoRA.

  • tracing_reach_and_quality_planplanning; no code: spun out of the system_diagnostics_and_accessibility_plan (D0–D8 landed). The spine is built but near-sighted and lossy: tracing_layer.rs::interesting_target forwards only meerkat/frame/uxtree targets, and StructuredPayloadField.name: &'static str forces an 11-name field whitelist (other names collapse to "field"). Survey: the first-party components are dark (armillary/graph/intel/mesh/moot/verso-scry/verso-genet/import/eidetic at 0 tracing calls; inker/murm/persona/orrery a handful). Two axes weighted equally: reach (broaden the bridge registry-driven + instrument the dark crates) and quality (lossless owned field names, typed channels for load-bearing spans, correlation via op/origin id + span parentage, per-phase timing, level discipline + registry sampling, error-chain capture, #[instrument] ergonomics). Phases: T1 bridge fix (lossless names + registry/config-driven targets — the first slice, self-contained to register-diagnostics + tracing_layer.rs) → T2 actor substrate (armillary + content/fetch/sync/comms started→succeeded|failed spans) → T3 engine/content passes (cascade/layout/paint timing; doubles as the parallelism perf signal) → T4 correlation → T5 sampling + error chains + a ring-dump dev-loop escape hatch. Gotcha: the &'static str→Cow change ripples through the donor channel schemas (whole-crate compile); chrome-hot files (Mark's concurrent work) instrumented last. Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

  • chrome_bar_refinement_planP1–P4 landed + verified headed (2026-06-26); P5 remains. Plus two follow-on asks this session (context-menu edge-flip; UI scaling = baseline + Ctrl-zoom, with auto-DPI spun out → ui_dpi_scaling_plan). Polish pass over the toolbar / shellbar / Steward-Apparatus split. Five moves, decisions locked 2026-06-26: P1 rehome the omnibar sync-chip ("tessera: idle") into Steward (live plane) and add an at-rest Sync trace section to Apparatus, sharpening the live-vs-at-rest axis from the peripheral panes docP2 turn Steward's active_operations() count+6-row truncation into a real process/actor list with per-row verbs → P3 fix shellbar button centering + missing glyphs (left-stick + one tofu box in the 2026-06-24 shot; runtime-verify genet flex-item sizing vs font coverage of ///) → P4 move the host-drawn session switcher out of the shellbar bottom into the toolbar as hybrid chips + +N ⌄ overflow (DOM, not cached rects) → P5 replace the + pill with a segmented +node|+tile|+field group (drops "Add session"), collapsing to a split-button when crowded. Touches views.rs/render.rs/pane_data.rs/apparatus.rs/main.rs; tests.rs button/div counts move. Cross-links shellbar_plan + apparatus_pane_and_theme_switcher_plan.

  • ui_dpi_scaling_planplanning; no code: true auto-DPI, spun out of the chrome-bar UI-scaling pass (which shipped the user-zoom half). Key finding: meerkat is a physical-pixel app (window created with PhysicalSize, chrome laid out + rasterized at physical px, scale_factor never read), so folding scale_factor into the chrome scale over-sized it — correct density, wrong frame (the window was physically small). Insight: chrome auto-DPI is not a full logical-px migration — it's (1) size the window in LogicalSize + (2) fold scale_factor into ui_scale (the wiring built+reverted in the chrome-bar pass, restored here). Phases: D1 chrome auto-DPI (meerkat-only, no genet change) → D2 content/orrery DPR, which needs a genet/netrender render-scale seam (D2a supersample-at-compose, recommended) or a full device_pixel_ratio in genet-layout (D2b, later) → D3 per-monitor live re-fold + reconcile with orrery zoom. Open: window-size persistence (logical vs physical), per-window DPI vs shared user_zoom, supersample fill cost.

  • smolweb_host_integration_planplanning (with Mark); meerkat code deferred to a clean window (concurrent meerkat edits live). Render a focused smolweb capsule in the host through the genet lane — the native smolweb-views render shipped in pelt (pelt_desktop::SmolwebDocument: errand parse → gemtext/gopher/feed views → ScriptedDom → genet-layout → Scene; scroll + chrome-browser link nav + per-site/App theming) — not the block-card reader. Two lanes (settled, Mark's call A = per-surface automatic): focused tile = genet lane, orrery card = block lane (nematic → Block); not two LODs of one render. Fits as-is: the content actor already ships a Send Scene off-thread and already dispatches a genet lane for HTML (is_genet_html_lane/StaticDocument), so the smolweb branch slots beside it; SmolwebDocument is Rc-based but stays on the actor thread (only the Scene crosses, like the blessed genet cascade). Phases: P1 the lane (enable pelt-desktop/smolweb+errand; route smolweb content → SmolwebDocument.frame(), retained for scroll) → P2 host theme (tinct → SmolwebTheme::App) → P3 input (scroll + link-click → node-nav) → P4 optional activation rung. Builds on native_smolweb_rendering_plan (design_docs/nematic_docs/implementation_strategy/2026-06-27_native_smolweb_rendering_plan.md); extends render_ladder_and_extraction_plan.

  • meerkat_cli_tooling_plancomplete for the local tooling slice (2026-06-29): renames the local target cache to C:/t/meerkat-target, replaces broad Cargo paths overrides with source-specific local patches, clears the inherited parent-config leak that forced xilem_core from crates/xilem-woodshed (historical citation) , and adds scripts/meerkat.ps1 plus check-meerkat.ps1, test-roster.ps1, and drive-meerkat.ps1.

  • ui_polish_plan: planning; findings verified headed 2026-07-01. Five grounded findings: ui_scale reaches only the chrome sheet (pelt tile tabs, orrery gnodes, and canvas labels never scale; canvas zoom repositions without magnifying), tile tab text clips at the tab's top edge against the toolbar, the session chip wraps into a big filled pill where the shellbar switcher had graph thumbnails, window controls overpaint +tile/+field at higher zoom, and the RepaintOnly paint-list cost that scales with shell-document size (documented; fix is a genet-layout plan). Phases: P1 thumbnail session chips, P2 scale the pelt tile surface, P3 fix tab clipping at the root, P4 toolbar overflow correctness, P5 canvas text scaling policy as a setting. Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

  • gnode_pool_planplanning (with Mark): stop the focused-pane gnode path's per-frame waste and reconform it to the data-oriented doctrine (clauses 5/6). Audit findings: the path is snapshot-and-diff where gyre's deltas should fold forward (full Vec<OrreryGnode> rebuilt per frame, whole-world PartialEq, view re-run re-deriving the mutation set gyre already knew); stable kind-data re-derived per frame (verified: favicon_data_uri PNG-encodes per node per frame, uncached); hovered in the snapshot means mouse motion invalidates the world. The conforming shape already runs in the secondary panes (the orrery's in-scene id→DomNodeId pool, value→value writes, RepaintOnly by construction); this plan lifts it into the shell document as a host-managed pool, keeping the unified-document wins (one a11y tree, hit-test, theming). Honest scope: recovers meerkat-side waste; chrome_us stays dominated by genet-layout's paint emission (ui_polish finding 5) until that fix lands — complementary halves of the same clause-6 restoration. Phases: P0 instrument (doctrine §6.3 integers) → P1 stop the bleeding (favicon/label caches, &'static str color, hover out of the equality) → P2 the host_pool seam in xilem_serval (view builds the container, host owns its children; splice-safety test is the deliverable) → P3 the pool (hot/stable column split, membership reconcile, per-frame fold by table compare, styling to sheet classes — which also makes gnodes ui_scale-reachable) → P4 retire the snapshot + re-scope the keyed plan to roster/list/gloss → P5 measure vs baseline, feed the residual to the genet-layout plan. Supersedes the keyed plan's orrery consumer (its roster/list scope stands; Keyed wiring in flight concurrently, P4 coordinates).

  • misfin_standalone_promotion_plancomplete 2026-07-04, archived: promoted crates/murm/misfin (historical citation) to the standalone mark-ik/misfin repo, completed to spec prototype B (public async send client with pinning + 2048 enforcement, full 19-code MisfinStatus, server-side cert-identity extraction with per-identity TOFU pins + 63 on changed fingerprints, 62 on expired certs, 59 on over-long/non-UTF-8 requests, gemmail compose + §4.2 reply helper, explicit-root identity API dropping the graphshell config path, misfin CLI so cargo install misfin works). 35 tests + headed CLI smoke green; workspace swapped to a branch-tracked git dep, meerkat/comms verified. Stewardship posture: not the reference implementation; crates.io name transfers to lem on request. 0.0.2/0.0.3 published 2026-07-04 (0.0.3: selectable TLS provider + cert chains); errand 0.1.2 delegates misfin send, spartan, and nex to the spec crates. Standing watches: misfin(C), name transfer to lem on request.

  • keyed_view_sequence_planscoped, no code: spun out of a node/card architecture conversation. Verified gap: xilem-core's ViewSequence impl for Vec<Seq> diffs positionally (index, generation), not by identity — no keyed/map-backed sequence exists in the crate (matches real upstream Xilem's own tradeoff, not a genet oversight). Consequence: any Vec<ShellView>/Vec<RosterView>/etc built by .iter().map(..).collect() — the orrery gnode list, roster tables, list panes, the gloss minimap — misdiffs whenever membership changes anywhere but the tail (routine for the orrery: panning moves nodes on/off screen at arbitrary positions). Does not fix the dominant chrome_us paint-cost finding (ui_polish_plan finding 5) — paint-list emission is insensitive to mutation count either way; this is a correctness + view-diff-layer efficiency fix, kept as a separate line item. No xilem-core edit required (ViewSequence/ElementSplice/AppendVec are public, implementable for a new local type under the orphan rule) — recommended home is a new Keyed<K,V> primitive in xilem_serval (reusable across the roster/gloss/list-pane call sites), not meerkat-local. Phases: P1 the Keyed<K,V> impl → P2 first consumer (orrery gnode list) → P3 roll out to roster/list-pane/gloss → P4 (deferred, gated on the paint-cost fix) an ElementSplice move/reorder primitive, since today's splice has none and a reordered key still costs a delete+reinsert.

mere_docs/technical_architecture/

  • workspace_topology_status — supercrate-naming snapshot; §1–5 are pre-flip receipts, §7 (graphshell dissolution) + §8 (canvas-ir/graph-layout review) are current.

  • mere_composition_spinethe spine: truth → arrangement (forme) → projection (platen) → surface (verso) → engine (inker), with the three persistence scopes. (Host/realization rows pre-flip; 2026-06-10 correction banner. Verso's disposition: see the verso_docs charter.)

  • statements_over_schema_stance — the stance on statement/triple-shaped data over rigid schemas.

  • statement_kernel_briefcanonical model: the kernel as a statement store. Every edge family is a predicate-keyed statement whose meaning drives its ramifications (nature content-vs-experience / behavior / durability / RDF-projectability); the dividing line is recorded fact (a statement, accumulates) vs derived/live state (positions, focus, gyre bodies, recomputed each frame, never stored), which is what keeps petgraph the hot-path runtime. Accumulating statements are a GC/compaction concern bounded to event/experience statements, unified as per-predicate lifecycle policy (durable-keep / session-drop / rollup-to-aggregate / prune-if-rejected / distill-to-engram) — the model behind the kernel's existing EdgeMetrics rollup-eviction, RelationDurability Session/Durable, ClassificationStatus accept/reject, and the eidetic/armillary memory tiers; referential-integrity, federation-as-retraction, and term-dict compaction subtleties flagged. The accumulated cross-silo corpus (browsing + files + docs + notes) is valuable as a private, temporal, provenanced eidetic dataset that grounds personal intelligence, value living in the asserted/distilled layers (not the raw log), back-loaded, quality- and UX-gated. Completes the statements-over-schema stance; spine under petgraph_rdf_plan.

  • cartography_aether_layout_seam — how cartography + arrangements (projection) relate to gyre (physics); gyre is not a cartography strategy; the Projection bridge.

  • spatial_compute_planthe ratified GPU regime, founded and completed 2026-08-18: tensor programs (Burn/CubeCL) beside explicit GPU programs (rust-gpu as plain wgpu compute), render consumers as tenants, ownership by advanced state, host as frame conductor, padded 3D, the SpatialBufferLease promoted only after a second consumer, nexus as quarry. Gates P1 through P4, all closed; P1, P2, the Burn handoff, and P3 all landed 2026-08-18, and P4 is decided: narrowed, not extracted (no crate, because both consumers are probes rather than shipped code; the convention is written in the plan, slot stability is ruled as a free list with per-slot generations and no compaction without an epoch bump, and the epoch is enforced in code with a positive control: pixels changed across a forced slab regrow fall from 10.86% to 0.00% when the re-attach is skipped). The two-consumer evidence: the wing probe (paredros/probes/ambience-lease) draws 20k resident motes through renderling at 3.6 ms with z carrying real extent, and shows the consumers are asymmetric (renderling cannot bind the buffer, needing an adapter kernel into its own slab plus a destination descriptor the draft lease lacked); P2's residency spike landed the same day (crates/probes/resident-graph (historical citation) : 50k bodies at 12.8 ms resident vs 318 ms CPU Barnes-Hut force pass, four-byte per-frame readback, tenancy-seam second consumer), and the Burn handoff with it: quint's tensor pass writes the resident forces buffer through device-local copies (equivalence to the kernel 1e-6; the 24x gap and the [n,n] memory wall validate the two-regime taxonomy; the seam grew TenantNeeds::greedy for JIT tenants, netrender 1ce733be6).

  • field_system_extraction — the field system as a kernel primitive, and the decomposition of graph-canvas into the orrery/* family. Amended 2026-08-18: settled positions are projections calculated from data, not data; arrangements is the deterministic lane and seiche the live force physics, so GPU evaluation in conatus is a performance choice rather than a fenced tier. Names the three ways a projection quietly becomes data, and the one surviving hard requirement (device unity, not determinism). Second amendment same day: physics proposes, the record disposes; an explicit commitment (gesture or standing rule) may promote a contact event into a recorded fact while the trajectory stays a projection; tactile CPU tier (rapier) and field GPU tier (quint/burn) named as coexisting on one canvas.

  • peripheral_panes_architecture — the peripheral-pane slot (gloss/apparatus/roster) and the donor-harvest-per-pane shapes.

  • alembic_memory_and_engrams — the alembic memory model + engrams; the armillary distillation daemon.

  • interaction_model_spine, the interaction-model spine: the one fetch→render→represent→arrange→interact→semantic pipeline over the definitely-support formats (smolweb, djot, linked-data, p2p, local-media), one owner per stage, with the four orrery plans (unified-document-host, node-representation, window-composition, field-regions) as non-overlapping layers it cross-refs. Sibling to the composition spine (which stays the arrangement ontology); draws the scope line (definitely-support now vs the later Genet/WPT track). Written 2026-06-18 to stop the plan-cluster drift.

  • generic_graph_substrate_planthe data-plane promotion (planning; decisions locked 2026-07-08): mere's graph model generalized into a standalone Graph<N, E> substrate, chartulary (aliased chart), on a stack of muniment (bytes) → codicil (edit log spine) → chartulary → stemma (lineage, from node-lineage) → scholia (RDF, from linked-data). Fully generic core (one required Identified bound, capability traits unlock features), fresh minimal core with mere re-basing last, one history spine (codicil authority, snapshots as muniment materializations). Consumers: isometry, woodshed, strophe, mere. Phases G0 (skeleton, done) → G1 (spine, done) → G2 stemma → G3 first consumer → G4 scholia → G5 mere re-base.

  • g5_mere_rebase_progressgraph adoption landed: Mere's graph is now chartulary::Graph<Node, EdgePayload>; history-over-spine and analytics retargeting remain.

  • mere_as_the_unifying_graph — vision record for the graph-substrate program and the role of its already-landed pieces.

  • moots_as_smolweb_publishers — architecture analysis of Moot publication and Knot's relation to smolweb; execution continues in the Moot plan.

  • tactile_tier_planfounded with T1–T3 landed: the CPU Rapier half of the tactile/field two-tier ruling and its commitment-event vocabulary.

  • facet_signaling_and_control_loopsfacets as a signaling medium (design round 2026-08-16; targets 1 through 3 landed 2026-08-18): facets are participant-to-participant communication through nodes, not node-to-node awareness (a Container is passive; the actors all pass the gate), so neighbor-awareness stays with edges, fields, and signals. Interior signaling (inside one graph, one journal and one revision counter, so protocol and control loops are affordable) is separated from exterior marks (across graphs, no shared clock, so deposits must be idempotent and survive unread) — the endocrine/stigmergy split, with the membrane already real in code because FacetStore lives inside GraphLog and its snapshot. Rules why a decaying signal is not a decaying tag (there is no tag edit, so a tag rewrites the whole node per tick; and tags export as schema:keywords, so decay and non-projection are one decision). Discrete shelf life now uses chartulary's generic revision-indexed ExpiringFacet<T> and Pandect's explicit read_expiring_facet; expiry is a read predicate, never mutation, and a recorded cascade replays identically across the boundary. Falling concentration still belongs to the field layer. Closes the verified control-loop gap at actuation: declared minimum change and interval bound a behavior-defined scalar before a slow limit cycle can grow journal history; accepted state persists across restart. Facet grants also landed: Cap::Facet is dot-segment namespaced and the gate requires it alongside node scope. Target 4 remains open behind a real threshold-crossing consumer.

  • signet_trust_plane_planthe trust-plane promotion, companion to the graph substrate plan (planning 2026-07-08; spine founded): identity / p2p / local-social generalized out of mere as the second substrate, parallel to the data plane. Spine is personae — one crate for identity and carry (master Ed25519 + BLAKE3 derivation + vault + sealed records + passphrase/OS-store unlock, plus seed carry, device roster, capability grants, epoch history, root refs). The earlier signet split (identity + a separate carry crate) collapsed into personae: signet was taken on crates.io, personae is free and truer, and "a persona is the carry layer's root-of-trust instance". personae 0.1.0 published 2026-07-08 (MIT/Apache, edition 2024) with the identity core promoted from persona/identity; carry layer folds in. Stack: personae → murm/retinue/misfin (wire+comms) → moot/tessera/kith (standing+membership). Two seams join the planes: the seal seam over muniment (PayloadSealer, the gap #2 eidetic::seal prototype — muniment holds bytes, personae owns the epoch key) and the sync gate over codicil (moot/tessera/kith admission gates codicil-log replication over murm). Phases: S0 carry-layer lift → S1 seal joint → S2 identity core (DONE, the founding) → S3 first non-mere consumer → S4 sync gate → S5 mere re-base. (File keeps its signet name; content is personae.) Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

  • graph_object_roster_detail_cards_plan - in progress; roster/card + relation-cell visibility slices landed 2026-06-30: turns the Roster into the durable graph-object control surface for Nodes / Links / Graphlets / Fields, with in-roster cards for Link, Graphlet, Field, and Facet subjects. Link depth now addresses current (source, target, RelationKind) cells across roster rows, Link Card row actions, canvas relation-cell overlay/picking, connections-swatch routing/filtering, and view-intent visibility persistence. The plan now carries a working map for current state, next moves, sidequests, synergies, contradictions, and pitfalls. Remaining tail: gyre topology/springs still endpoint-pair scoped, true parallel edge instances remain out of scope, and deeper graphlet selector/family editing still needs the graphlet/swatch control surface. Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.

mere_docs/research/

Several older briefs here carry a 2026-06-09 rename-key banner (pre-pivot crate names as receipts).

  • frontier_sync_over_reticulum_briefresearch with rulings (2026-09-01, with Mark): what p2panda sync over a Reticulum link looks like. Verified against the tree: carrier, bulk transfer, operation format, ingest, bundle and courier store all exist and are carrier-neutral; the only missing piece is a reconciliation a non-iroh carrier can use, since JoinedSpace builds LogSync over iroh plus gossip. Finding: for per-author logs a frontier vector is an exact reconciliation in one message, so RBSR (the 2026-06-21 brief's "lean pairwise RBSR nobody has built") is the wrong tool; p2panda's Have already is one, fat and badly driven. Rulings: keep p2panda's LogSync messages, drive them statelessly over retinue's request lane; compact author ids from the moot roster; home is stickleback beside JoinedSpace, murm supplies the carrier, gemot the roster; operation carriage (unchanged bytes vs shadow header) is a spike keyed to retinue's MC0; scopes V10 of the low-power plan. Three session shapes on one vocabulary: live link, eager push, courier drop via outrider.
  • browser_native_webrtc_carrier_proberesearch complete 2026-08-25, Luggage boundary added 2026-08-26: a headed Chromium-to-native ping physically proves the WebRTC data-channel route, and a separate external consumer proves Notochord/Personae's sans-I/O admission core compiles for Wasm with explicit JavaScript randomness features. Rules direct WebRTC + Notochord as the first carrier; derives private-invite redemption and host-signed DTLS-fingerprint binding; and assigns release identity to Luggage through ReleaseRefV1, a signed content manifest separated from disposable byte locators, exact browser-bundle verification, and explicit publisher adoption. Records the honest ceiling that an ordinary first visit still trusts the mer3ly.net HTTPS origin to deliver the verifier.
  • local_intelligence_integration_research — Burn-first statistical intelligence; tier ladder; embeddings shipped at intel/embed, generative/agentic deferred. (banner.)
  • cartography_layer_brief — cartography as the non-destructive projection layer (now orrery/cartography); strategy catalogue. (banner.)
  • geist_models_brief — personal + moot-trained LoRA adapters as engrams; LoRA stacking keystone; tessera-as-compute-credit (tier-3+).
  • local_models_harness_brief — the runtime + harness direction, refreshed after ESP: InferenceProvider, the deterministic stub, own Burn decoder, Eidetic loading, cancellation, Armillary actor, and native host receipt are landed in esp::infer; esp::embed holds the adjacent embedding seam. The wasm execution claim is routed to the headed D2 browser probe, while immutable model sessions and AdapterLoader remain gated on one real adapter. Training, marketplace, and governance stay owned by their Geist/resource-coordination lanes.
  • agent_harness_brief — the run loop between the two seams that already exist: the local_models_harness brain seam (InferenceProvider) and the landed D7 hands seam (agent_harness.rs: typed AgentObservation / AgentAction::Invoke(id)). One armillary actor per run (assemble context → infer streaming → parse/gate/dispatch → record; a real, stoppable Steward op). Core commitments: one tool vocabulary (the model's tool list = the observation's enabled_actions over registry ids; three rings: registry actions, scoped graph reads, outbound MCP; never a parallel catalog) and runs as graph material (run = engram: transcript + actions + terminal state; provenance edge on every mutation; Athanor proposal/apply for batch changes). Two duty cycles over one loop: interactive session (user present, per-action consent, session-as-node) and standing agent node (pre-granted scope, proposal/apply default, results as provenanced edges). Remote API models = just another InferenceProvider backend (provider choice, not architecture). Loop is portable + host-free behind a host-adapter trait; first slice is stub-driven (call representation → scripted-stub provider driving the D7 harness → run engram + provenance), no model required. Open: constrained decode for small local models, context budget, standing-agent triggers, the interactive surface, multi-agent.
  • browser_multiplexer_framing — the builder-facing "Mere multiplexes durable graph sessions" framing; identity matrix; session manifest. (banner.)
  • engine_peers_and_scrying_library_brief — engine taxonomy: mere is the manager, engines are content functions, scrying is a library not a peer. (banner.)
  • memory_tiers_brief — short-term vs long-term memory partition; consolidation into engrams is an affirmative gesture.
  • tearout_operations_brief — the leaf / branch / fork tear-out trichotomy, gesture model, and identity semantics. (banner.)
  • capability_gate_catalogue_brief — the capability-gate catalogue the action bus + permission spine consume.
  • daemon_split_research_brief — whether/when to split a separate daemon process from per-window clients (research; no v1 implementation).
  • persona_model_brief — one-human-many-personas; what a persona owns; persona switch as a session-boundary moment.
  • graphshell_harvest_brief — concept inventory pulled from the donor graphshell docs. (Canonical donor concept-index per DOC_POLICY; banner.)
  • graphshell_docs_full_harvest — the full sweep of the 633 donor docs (what to pull, where it lived). (Canonical donor index per DOC_POLICY.)
  • understory_orrery_graduation_brief — how/when to evaluate forest-rs/understory against the orrery element. (banner.)
  • nonstandard_browsing_profiles_brief — Willow/Iroh-Willow/NextGraph/W3C survey; the derived-RDF projection boundary; optional host-level browsing profiles.
  • two_natured_kernel_brief — the kernel's two natures (data + space); the aether (field-algebra) / gyre (rapier) naming; Coupling as a force, not a 7th edge family.
  • murm_p2p_landscape_brief — orientation survey of the whole p2p program + external landscape verdicts. (Pivot now executed; banner.)
  • resource_coordination_brief — split map for the five resource-coordination lanes: personal mesh substrate, lease scheduler, kith capability sharing, bounty verification economy, and communal compute/model hosting.
  • communal_compute_tiers_brief — authority for the communal-compute/model-hosting lane after the 2026-06-30 split: volunteer-computing lessons, moot → moothold → coalition compute commons, time-bank as a constitution preset, LCZero-style data/eval loops, and late Petals-shaped async hosting.
  • edge_system_audit — code-verified audit of edge generation/management. The kernel model is complete (assert_relation, 6 families, a SemanticSubKind vocabulary incl. UserGrouped), multi-node selection + edge pick/hide already exist; reconciled 2026-06-15: create / retract / traverse between two existing nodes all shipped (assert_selected_relation, Command::AssertEdge/RetractEdge, context menu, >relate/>unrelate, roster click); the original "no way to draw an edge" framing is stale (top-of-doc banner corrects it). The one remaining gap is the discoverable relation-kind picker (Tier A in the in-the-wings audit; the SemanticSubKind map exists, the context menu hardcodes UserGrouped).
  • contact_identity_model_brief — the them side of identity (pairs with the persona brief's me): contacts are key-rooted (petname → stable key → endpoints, kith/kin), WebFinger is one endpoint resolver not the identity, the NIP-05-shaped key resolver must return (webfinger is de-nostr'd), contacts are persona-scoped; plus the SHARP-comparison stances (keep @ not #; hashcash via the reserved misfin code 64; ephemeral murm-native + misfin-local) and the misfind daemon split.
  • in_the_wings_and_browser_bar_audit — code-verified 10-agent sweep of built-but-unwired capabilities (every claim file:line + a crates/meerkat (historical citation) caller check) plus the browser table-stakes gaps plus a 5-lane roadmap. Two dominant shapes: duplicate substrate (8 cases where the federation-faithful half lost the live path to a session-local half) and dev-example-only chains (import/embed/eidetic-search gated behind missing dep edges). Tier-A glue-only sidequests (JSON-LD export, recover-node, relation-kind picker, tessera score/ticket) where the dep edge already exists; the §5 foundational pitfall (pages baked into one GPU texture → the large-page blocker + no find-in-page + no selection + capped scroll, all one fix); five synergies; §3 corrects four stale plan headlines (edge create/retract, OpenGraphBeside/far-B, omnibar shell, theme A2 all shipped).
  • rdf_native_kernel_feasibilityresearch, decision-pending: should the kernel's content storage become RDF-native (option 3) vs today's typed-petgraph-truth-with-lossy-RDF-export (option 1) or a separate RocksDB Oxigraph store as authority (option 2, rejected). Key feasibility findings: spareval's QueryableDataset trait lets the kernel be the SPARQL-queryable store with no Oxigraph Store / no RocksDB; the change-surface is contained behind the kernel's public API (~5 direct petgraph sites outside graph-kernel, all arrangement adapters); pure-Rust in-memory store as a fallback; rdf-canon exists but unstable (defer canon/signing); reifier-node form for RDF 1.2 metadata; persistence stays the kernel's own (no RocksDB, wasm-uniform). Design = content RDF dataset in named graphs + derived adjacency index + typed experience side-tables, public API unchanged. Gated on a 3-probe spike whose hot-path perf benchmark (RDF-backed+index vs petgraph at 1k/10k/50k) is the decision point.
  • w3c_standards_architecture_review — mines the full W3C/WHATWG corpus for stack architecture (extends the genet viewport-scope doc's "family travels together" method platform-wide). Part I, platform spine (S1-S13, mostly ADOPT: cheap now, brutal retrofits later): Fetch as the one loader algebra every security feature patches; origin as a kernel-grade type + partition-all-state-by-default (never build the unpartitioned model); streaming parse + preload scanner; navigables/session-history as the frametree model; WebIDL-first bindings for the Nova/Boa script lane + the wasm64 receipt (memory64 everywhere but Safari validates the vano bet); WebCodecs-shaped codec seam; font-matching/UAX contracts; timer-throttling tiers as the card-freeze substrate; crashed-frame contract for live cards + SurfaceEngine honesty. Part II, chrome/product (C1-C10): moveBefore names + tests splice survival (cross-document moves = deliberate divergence); container style() queries as the LOD axis + node-identity custom properties + @layer theming; top layer + anchor positioning + custom-highlight painting (= palette/menus/find-in-page, the §5 baked-texture exit); UA form controls as xilem_serval views (ElementInternals-contracted, base-select-shaped); content-visibility card virtualization + view-transition card morphs + WebGPU-canvas external-surface seam; EditContext shape for IME; graph-adjacency prerender; HTML-AAM→AccessKit once. SKIP on the record (EME-for-now, WebGL in favor of WebGPU-first, Houdini worklets, fenced frames, XSLT, mutation events). WPT subsets as done-condition currency, WebDriver BiDi as the automation seam; 9-step consumer-pulled priority order; shipping statuses web-verified 2026-07-05.
  • xilem_serval_directions_brief — the seven load-bearing xilem_serval ideas from the 2026-07-05 session, on the record as directions (not a plan). Four absorbed by the standards review (LOD-in-the-cascade C2, overlay-roots C3, UA-widgets-as-views C4, mutation-log→MutationObserver C8); three deliberately beyond the platform: one runner, N windows, each a lens-projection (sync becomes structural; cross-window tear-out = our divergence past moveBefore), extensions as lens + view (capability-scoped lens is the sandbox; WebExtensions collision noted and fenced), dual-target chrome via xilem_web (held open by keeping view code on standard DOM/CSS idioms, not by code). Ideas 1+2+3 ≈ meerkat's remaining chrome architecture.
  • cross_platform_parallelism_strategystrategy synthesis: the cross-platform (incl. browser) parallelism + performance plan for genet / netrender / pelt / meerkat / mere against the empirical ~100 ms / 578 KB cold-layout cost. Three real levers — Web Workers + SAB + atomics (Rayon shim; in-browser CPU parallelism), wgpu → WebGPU (GPU rasterize; vello compute), WASM SIMD (wide; per-frame inner loops, wrong axis for cold layout) — and one distraction: WASI is out for the browser by its own charter. Decisive finding: the browser target forks — SAB-threaded parallel cascade is a PWA/app-lane capability only; the open-web-browsing lane cannot use it (COOP/COEP require-corp is incompatible with loading uncontrolled third-party content; Safari lacks credentialless). Lever order: off-main-thread (do first, header-free but pays a per-frame scene-serialization cost on web + needs a Serialize DTO pass that doesn't exist) → incremental → SAB-Rayon (prove native-first on pelt; the style.rs Cell→atomic race fix is unlanded and only native-verifiable; the 2–3.5x figure is borrowed native-Quantum-CSS, never run in wasm by anyone — Blitz ships Stylo single-threaded on web). netrender is least in the way (structurally web-aware, never compiled for web; blockers = absent webgpu manifest feature + max_inter_stage_shader_variables:28 vs baseline 16). Names the §0 prerequisite (a cascade-vs-box-tree phase breakdown of the 100 ms bounds the whole parallel thesis) and three easy-to-miss porting taxes beyond fonts: clock panics (web_time), randomness (getrandom/uuid), and the embedded-fallback-font requirement.
  • graph_projections_researchresearch / design probe: five new projections (whole surfaces/modes that read graph truth a particular way, distinct from arrangements = layouts inside the orrery, and from forme::ProjectionLens = which edge family is load-bearing). Trail (replay the branching node-lineage visit tree via a time-ribbon + scrubber; the full surface behind the existing Trail shellbar button), Claim map (the research session as a stance graph over the Semantic argument sub-kinds Supports/Contradicts/Questions/Cites + decay_progress; an orrery mode, most novel, makes the relation-kind picker worth finishing), Provenance trail (show-your-work derivation tree over the zero-consumer Provenance family + content store; gated on Provenance write gestures existing), Facet matrix (a pivot table over the built-but-unsurfaced kernel facet_projection PMEST map; cheapest, a gloss lens), Neighborhoods (named topic islands + bridges as a consumer surface of the same-day graph_signals_layer_plan, not a second producer). All obey the projection contract (read over truth, no root, curation writes back via assert_relation, representation orthogonal) and the gloss Navigator no-split rule (3 of 5 are orrery modes / gloss lenses, only Trail + Provenance earn panes). Cheapest-first: Facets → Trail → Claim map → Neighborhoods → Provenance; each spins out to its own plan when picked up.
  • projection_engine_prior_art_briefresearch brief (with Mark; two same-day adversarial critiques verified + applied): the destination — mere's distinctive subsystem is a projection compiler and runtime for interactive surfaces (source data + relationships + signals + settings → select/derive → channel-map → solve placement → interactive scene → gestures back as authorized intents), with turnstone composing its surfaces beside genet's document-engine surfaces over the shared scene/raster/compositor substrate. Today = separate working lanes with a verified ceiling: ProjectionRequest hard-requires kernel::Graph, Projection = one NodeKey → point+radius, project_canvas_strategy discards all but positions and has no turnstone caller, ProjectionLens unconsumed at visible_walk; meanwhile isometry (Overmap::layout, overmap.rs:123) and woodshed (related_swatch, stage.rs:48) already hand-roll layouts into cambium's GraphCanvasSwatch — the consumer pull. Six prior-art lanes with lessons (Vega-Lite channels-as-serializable-values = engrams/packs; MPS writes return to the authority that owns the fact; GT cheap per-content-class views = facet bundle's job; Pad++ LOD/region lenses; deck.gl-over-MapLibre thin-adapter geographic; spatial-hypertext VKB placement-recognizer). The model: three structures kept distinct — source data (products own native truth; engine holds stable refs) / projection graph (per-view selection + derived relationships, e.g. grid adjacency without authoring truth) / projection scene (instances with source-ref + instance id, parent coordinate space, transform + footprint point/rect/polygon/path, representation slot glyph→card→sprite→live-pane→snapshot→nested, size constraints, layer/LOD, hit shape + actions); the representation measures, the projection places (a browser pane sits in a phyllotaxis spiral without the engine learning web rendering); one source object may appear as several instances; TreeGeometry keeps its solver but emits the same scene contract. Five primitives, one gesture: frame / group / region / field / pin stay distinct types; drawing a hull composes group+region+optional field, carry = rigid→spring→ContainmentWall→visual dial, Apparatus hull section, silhouette + group hull share polygon editing but not meaning. 3D: 2D-first, shipped 2.5D height-by-degree is the counterexample to "never layout-invented z", full 3D task-and-display-gated. Crate direction — the scenograph family (named 2026-07-21, all free on crates.io): family repo scenograph with sceno (core: refs/scores/channels/spaces/footprints/scenes/intents, product-free) + scenomise (choreography/layout: arrangements + subdivision/tiling/geo transforms) + scenotime (runtime: incremental eval, caching, signal generations, scene diffs) + scenograph (bevy-style facade); stage vocabulary score → choreography → inhabited scene (doc-level; UI copy stays plain); cartography becomes mere's graph adapter; cambium swatch consumes scenes; graphshell = the family's remote lens (destination ruled 2026-07-22: wasm-first thin client for web/mobile over p2p — scores out, scene diffs back, intents through the participant gate; consumers isometry-web / radio companion / remote turnstone lens; gated behind proof 4 + scenotime diffs), never the engine umbrella; no-shared-core doctrine reconciled netrender-style (shared output contract, sources stay behind adapters); hocket's timeline projection gated by its own arrange-view canary. Burn = stamped signal producer (model id/generation/confidence/provenance/observed-at; cached+invalidated by runtime; suggestions become truth only via accepted action; engine runs without ML). Five proofs: wire catalog through turnstone (smoke) → portable scene contract → browser-pane phyllotaxis with recency LOD → isometry consumes contract (deletes its force layout) → fixture-driven geographic, live radio facts when they exist. Done = the same serialized projection settings drive a mere pane spiral and an isometry map with neither portable crate depending on either product.
  • orrery_physics_environments_researchresearch / design probe: open-source physically-defined scenes as interactive orrery backgrounds, grounded in gyre = rapier2d 0.22. Nodes share the scene's world (scene bodies are non-NodeKey bodies in the same Simulation). A tangibility dial (interactive = nodes affect the scene / intangible = nodes pass through but still collide with each other) maps onto rapier collision_groups by flipping the node collider's filter mask — additive, since gyre sets no groups today; per-node or global; nodes float over a gravity scene via per-body gravity_scale(0). Two features (Mark): a living backdrop (ambient, cheap, default-intangible — passive rapier bodies, or a separate N-body / particle-life / CA sim painted behind; gyre already has Barnes-Hut) vs an interactive scene (a shared physical place — transplant rapier's own examples2d corpus since gyre is rapier; liquid via salva SPH two-way coupling, actor-budgeted). The dimensional hotswitch (2D / 2.5D / 3D) is its own future plan: it decomposes into physics-dimensionality (rapier2d vs rapier3d, separate crates, LockedAxes for planar) vs camera-projection (ortho / isometric / perspective), and the 2D render stack (scene_paint → netrender → vello) is why full 3D needs a new render lane (via compose_external_texture) while 2.5D isometric is the cheap in-stack rung. All Apache-2.0 deps (gyre is MPL); preserve attribution on transplanted scene code. Cheapest-first: tangibility dial → passive backdrop → ambient sim → interactive scene → liquid → hotswitch. The two features + the hotswitch each spin out to implementation_strategy/ when committed.
  • browserenginekit_architecture_briefresearch / external-framework reference: inspection of Apple's BrowserEngineKit (the framework a non-WebKit engine must adopt on iOS 17.4+ / iPadOS 18+; EU/Japan DMA-gated, owned-engine; macOS exempt) + what it means for Mere. BEK mandates a four-process split over XPC: browser host (GUI), networking extension (URLSession/sockets), web-content extension (parse / JS / DOM, strictest sandbox, JIT-gated), rendering extension (Metal, hard memory cap + content-attributed memory). Concrete API: WebContentProcess / NetworkingProcess / RenderingProcess (+ WebContent/Networking/RenderingExtension protocols + opaque *ExtensionConfiguration), a capability-grant model (BEProcessCapability / BEProcessCapabilityGrant, BEWebContentFilter), BEExtensionProcess vending XPC, cross-process a11y (BEAccessibilityRemoteElement), and the JIT W^X mechanism (be_memory_inline_jit_restrict_rwx_to_rw/rx_with_witness(), PAC via BE_JIT_WRITE_PROTECT_TAG, entitlements com.apple.security.cs.allow-jit + …kernel.extended-virtual-addressing). Key finding: Mere's actor constellation already mirrors BEK's host / net / content / render split, so the model is process-portable (each actor → a BEK extension, the actor bus → XPC, the flat-Scene hop → the content→render XPC hop); BEK's capability grants ≈ the DocumentScript capability scoping (BEK gives both layers: OS processes + in-process WASM-component confinement); JIT flips per target (granted on BEK, so the no-JIT decision is web-only). Strategic fork: BEK = ship genet as a sovereign iOS engine, distinct from + heavier than the browser-extension / PWA companion path, and entitlement-gated (not a default). Reference for whenever the iOS sovereign-engine lane is scoped; no code.
  • offgrid_lora_transports_brief — can Mere reach off-grid radio? The decisive split: Reticulum is an embeddable transport (maps onto the existing Transport trait — destination-hash PeerID, aspect ALPN, LinkAsyncRead+AsyncWrite stream; LoRa via RNode; Rust impl reticulum-rs), while Meshtastic and MeshCore are bridge targets (client-of-node appliances → Pattern B mere-bridge-*, carrying the murm/announce slice, not sync). Two code-verified seam facts bound it all: the bilateral Transport trait is already transport-agnostic, but sync bypasses it to iroh's sync_parts() -> (Endpoint, Gossip), so a new transport rides the bilateral lane while sync needs a separate lift. Shared hard limit: a ~200–465-byte LoRa payload world rules out gossip/RBSR/blob sync over any of them. Recommended first probe = a bilateral-lane ReticulumTransport; Meshtastic/MeshCore bridges for reach, behind it.
  • workspace_state_overview_briefcross-cutting state snapshot (2026-07-01, doc-verified): where-we're-at / headed / sidequests / pitfalls / synergies / contradictions across the whole workspace; successor to the 2026-06-15 in-the-wings audit as a baseline for the next audit. Headlines: capture C1 + the 13x13-window headed-verify blocker are the two items most other work queues behind; the dominant contradiction shape is built-but-unwired (signals/provenance/trace/tracing all have machinery before producers).
  • orrery_graph_intelligence_plan (implementation_strategy) — burn brief Lane 5: graph intelligence in the orrery. P1-P4 mechanisms landed. Force pass: aether::forces::repulsion (tensorized N-body on burn, ndarray/wgpu, naive-Rust correctness anchor) is wired into gyre via a burn-free RepulsionSolver closure seam (Simulation::set_repulsion_solver + threshold; gyre stays burn-free, host builds the closure from aether::forces::repulsion_wgpu). Isolated GPU beats naive CPU 17× at 4k, but the real in-context gyre-tick win is 1.4-2× at 2k-16k (gyre's cutoff + rapier's step floor — honest correction to the isolated number), and it only activates above ~1000 nodes. Semantic arrangement (P4): embed::affinity::affinity_pairs bridges an embedding VectorIndex to gyre's existing AffinitySpring clustering signal (top-K nearest, clamped-cosine weight), tested end-to-end at the seam. P5 landed — live meerkat wiring (content-affinity half): Orrery::set_content_affinity (a burn-free injected signal superseding structural Jaccard under the existing toggle; dirty-gated, empty-inert, reverts on None), a new burn-free embed::LexicalEmbeddingProvider (feature-hashing lexical similarity — the honest light default vs the meaningless whole-string hashed one), and a meerkat content_affinity driver (embeds title+tags, revision + 750ms-throttle recompute, injects in render_orrery_scene, focused pane) behind an off-by-default content-affinity feature. 3+7+4 tests; default meerkat build unchanged. P6 landed — blended affinity + content-text enrichment: structural and content affinity now combine via an AffinityBlend mode (default noisy-OR 1−(1−s)(1−c); ContentOnly/StructuralOnly retained), the merge a pure blend_affinity_pairs before the single gyre force; node_text folds in each node's literal property descriptions (schema/OG — content already on the node, no cache/consent). Orrery suite 90/90. Also: HashedEmbeddingProviderStubEmbeddingProvider (it was meaningless-by-design; deprecated alias kept), D1 re-scoped as a 3-consumer decision. Lexical now, BERT (semantic-embeddings) the upgrade; raw-page-body embedding + the O(N²) index lift want the off-thread embedding actor; P3's live force-pass injection held (niche).
  • intel_vector_index_burn_lift_plan (implementation_strategy)Path A landed; implementation now in esp::embed: the exact batched-cosine Burn kernel ships behind index-burn / index-burn-wgpu, with measured crossover and CPU/WGPU parity. Path B HNSW remains a later algorithmic lift when a consumer proves the need.
  • node_image_externalization_plan (implementation_strategy)planned, not started: move Node's inline preview imagery (thumbnail_png + favicon_rgba) out of the kernel truth into the durable content-addressed blob store, keeping a ~40 B ImageRef (BLAKE3 hash + dims) in the node. Motivated by the petgraph-RDF Phase 4 footprint probe (inline images = 64% of live graph heap at 50k nodes, vs ~1% a term dictionary could reclaim). Reuse-not-invent: the exact pattern page bodies already use (eidetic::Store + content_store + pollster::block_on on the held store), content-addressed like engrams (dedup shared favicons, iroh-sync-portable), GC'd as an Athanor orphan-sweep pass (R0 propose/apply). Framing: preview imagery is experience, not truth, so it belongs in a bounded render cache, not in every node forever. Authored Node::body stays inline (truth, must sync/fork). Six phases (store+ref → kernel swap+migration → write sites → render resolver+bounded cache → orphan GC → re-measure); done-conditions target ~553→low-200s MiB at 50k. Risk: wasm/OPFS resolve is genuinely async (native block_on stays; wasm prefetches).
  • inference_provider_plan (implementation_strategy)core landed; implementation now in esp::infer: InferenceProvider, capability matching, deterministic StubInferenceProvider, the Armillary streaming actor, the own Burn llama-family decoder, Eidetic ManifestId loading, cancellation, sampling, CPU/WGPU parity, and the TinyLlama measurement receipt. Endpoint remains a later host-led lane; P4's headed-browser half moved to the D2 probe below.
  • browser_model_ceiling_probe_plan (implementation_strategy)scoped, independent evidence lane: run a real Eidetic model artifact through IndexedDB reopen/integrity, ESP loading, Burn WGPU, and a dedicated Web Worker in a headed browser; record cold/warm timings, the full byte/tensor copy ladder, first token and throughput, cancellation/restart, storage persistence, and UI frame impact in browser-model-probe.json. A configurable model sweep identifies the limiting layer; eager ResolvedModel byte ownership must not be mislabeled as the model ceiling.
  • burn_0_22_migration_plan (implementation_strategy)production remains on 0.22.0-pre.2; pre.3 audited 2026-08-26; stable closure release-gated: a bounded published-source ESP WGPU probe passes on 0.22.0-pre.3. At a future repin, the cubecl-runtime packaging patch can retire; Mere's burn-cubecl same-allocation fix and burn-remote lifecycle/pump-close fix still need rebasing. Distillery source compatibility was not reached because a shared Genet checkout lock blocked before rustc; Fusion/autotune remains unsupported. Pre.3's LoRA fixes and Burnpack streaming merit focused follow-ups but are not grounds for an automatic prerelease repin.
  • burn_wgpu_flip_plan (implementation_strategy) — Lane 1 spin-out of the burn utilization brief: bert-wgpu feature in embed + wiring aether's field-burn-wgpu, ndarray↔wgpu parity tests, CPU-vs-GPU timing receipts, the burn-0.21 existing-device init verification (D1 input), and wasm build receipts.
  • burn_utilization_briefdirection brief, all five lanes endorsed: how far burn goes and what "shape the app around it" commits to. Code-verified footprint (embed's full BERT + aether's field lowering, all ndarray-CPU today; gyre burn-free by design), then five lanes in leverage order: L1 turn burn-wgpu on (+ the D1 shared-device-with-netrender decision), L2 burn-remote-over-iroh as the fleet compute protocol (gated on the post-0.21 release), L3 burn-first InferenceProvider (the browser-reaching backend), L4 on-device training/LoRA (burn's moat; adapters-as-engrams), L5 orrery graph intelligence (semantic arrangement, similarity edges, tensorized force pass via aether). Three commitments: columnar hot data, burn only behind the provider/field seams, one early device policy. Orthogonal to the 60fps frame-budget work except D1's queue contention.
  • receipt_artifacts_replication_plan (implementation_strategy)planned, not executed: receipts (scenario receipts, captures, screenshots + their provenance manifests) become content-addressed artifacts in the personal graph, replicated across the owner's devices by the stack itself. Encodes the dogfood-over-adopt ruling (Syncthing declined: the stack intends to own this capability, so adopting a mature tool would deter the dogfooding; mature tools stay technique donors). A receipt = a chartulary container whose facets carry remote-receipt.ps1's manifest fields, blobs by blake3 in muniment (cross-machine dedup for free), replication = the resident host's existing PersonalSyncHost + transfer staging, provenance append-only via codicil. Code-verified: pairing/sync/staging live, mesh M2 shipped (incl. esp.embed.lexical/v1, so the esp plan's first-MeshResource step is real). R0 ingest module (in the resident host lane, module-before-crate) → R1 replicate (hash-verified on arrival) → R2 remote-receipt.ps1 auto-ingests (screenshot unification falls out) → R3 a turnstone receipts lens. Tier-1 own-devices only; explicitly NOT a generic synced folder.
  • esp_consolidation_plan (implementation_strategy)E0-E4, D2 browser matrix, immutable ModelSession, and real PEFT LoRA receipt complete; training artifact boundary landed 2026-08-26: ESP owns the consolidated inference/embedding bodies and model/tensor execution. Eidetic now owns validated, immutable TrainingCorpus and EvalReport payloads with disjoint training/held-out partitions and adapter provenance checks. The next forcing step is one deterministic local ranking or recall fixture that beats its unchanged baseline; only then should Distillery add a trainer resource. Endpoint inference, stacked adapters, portable remote checkpoints, and communal training remain gated.
  • borrowed_ideas_briefresearch / idea harvest: ideas worth borrowing from adjacent projects (spatial canvases, local-first p2p, agentic tools), filtered through Mere's spatial+p2p+agentic nature and Mark's curation of a longer brainstorm; the architecture-level companion to the carve grammar harvest in the djot-editor plan. Per axis plus crossings, each with its source and a net-new / already-scoped / dependency status: plex re-centering (TheBrain; resolved 2026-06-25 as one escalating "Center": camera-center default, then hold-to-gather for the soft radial relayout, hard relayout deferred; rides a small selectable-collapsing-menu-row upgrade), Cambria schema lenses (engram schema-drift over federation; home = alembic plan), capability-scoped subgraph sharing (p2panda-dependent; rides the persona / federation plans), MCP-native graph, speculative branches + provenance (a pull-request-for-your-graph paired with assert-on-every-agent-mutation), live query regions (Tinderbox made spatial; drawn connections filtered by the active edge config, ties to graph_signals_layer), multiplayer presence (already scoped, see operator_presence_overlay), and the living document (live Potluck blocks / Peritext CRDT / Burn-wgpu semantic neighbors). Cheap-first: the =query polyglot block, provenance-on-agent-actions, the rung-1 camera center.
  • shared_engram_commons_briefdirection note (2026-07-24; both decisions answered 2026-07-27): the communal graph is a profile over the existing substrate, not an engine. Deterministic multi-writer convergence, fold-time authority, group-key rotation, epoch retention, message mutation, facet edits, Knot-owned text merge, encrypted chat, and carrier-byte identity now have executable receipts. Outrider owns the LXMF boundary codec; calls have a separate product plan. Direct-PHY RF passed on real T114 and Heltec V4 hardware.
  • knot_lane_brief - position revised and cuts 1-3 implemented 2026-08-20: Knot's product floor is a standalone-capable Djot editor on a graph substrate with local-first, git-like peer replication. .knot and text/vnd.knot remain compatibility spellings rather than a new format promise. Clip evidence is retained as separately fetched content-addressed bytes; Djot carries portable references and observation metadata; structural merge remains source-preserving and conservative; CMUdict-backed rhyme and meter stay derived lenses. The process-ownership finding is now ruled: one logical device resident owns persona-vault authoring, sync, and content, with the implementation sequence in the device resident consolidation plan. An external prior-art section (2026-08-28, Ink & Switch) reads Upwelling's draft/stack findings against the collaboration model (titled drafts as the review unit; their anti-features as cautions), Backstitch as cut 2's thesis on scene files, and Potluck as the user-authored generalization of cut 3's lenses — none changing a cut's semantics.

Recovered donor research (2026-08-16)

Eight donor docs recovered from the git history of the archived graphshell repo (Code/archive/graphshell, whose design_docs/ tree is deleted at HEAD), where the 2026-07-23 repo consolidation had orphaned them. Each carries a provenance header naming its original donor path and source commit. None of this was ever implemented. It is research, not direction, and it speaks the retired Verse vocabulary. The companion three smolweb browser docs went to Turnstone's design_docs/ instead.

  • verse_graph_contribution_protocol_v0_1VGCP v0.1 (donor verse_docs/technical_architecture/, commit 6ab4c22f): the protocol authority that replaced VDIP. Entry/Visit/Owner projection boundary; structural verifiable-by-fetch edges rather than behavioral ones; per-protocol canonicalization profiles; BLAKE3 + CIDv1; privacy-filter-before-sign ordering; Ed25519 to did:key identity with Genesis/Threshold/Delegated rule systems and revocation as a read-time projection. This is the full text behind the full docs harvest §7 row that summarized it.
  • verse_distributed_index_protocol_v0_1VDIP v0.1 (donor archive_docs/checkpoint_2026-04-17/, commit 6ab4c22f): VGCP's predecessor, archived on the same day it was superseded. Signed immutable content-addressed graphlets, community admission and revocation semantics, search and ranking over accepted artifacts, with transport kept out of the normative layer. Filename normalized from ..._v0.1.md.
  • modern_yacy_gap_analysis — (donor verse_docs/research/, commit 1208e352): why a YaCy-style global word DHT was rejected, and Federated Index Exchange proposed instead: portable mergeable Tantivy segments published as content-addressed blobs, plus the query-protocol and ranking gaps that follow from it.
  • libp2p_nostr_synergy_for_verse — (donor verse_docs/research/, commit f36fc49b): names the control plane / data plane split (Nostr carries small signed events that reference CIDs; libp2p delivers the bytes behind those CIDs) and works through its consequences and seams. Carries the donor's repo-wide MPL-2.0 notice verbatim, unreviewed against this repo's MIT/Apache posture.
  • storage_economy_and_indices — (donor verse_docs/research/, commit 1208e352): proof-of-access as active service rather than passive storage: sharding, signed access receipts, minting, and provenance metadata carried on an otherwise fungible token. Precursor to the donor's proof_of_access_ledger_spec.md.
  • freenet_takeaways_for_verse — (donor verse_docs/research/, commit 04d68365): a short external pattern review of Freenet. The durable takeaways are splitting shared-state logic from private-identity logic, and keeping capability surfaces narrow per mod or provider.
  • aspirational_protocols_and_tools — (donor verse_docs/research/, commit 9a6526a7): the widest early survey. IPFS/GunDB/libp2p/iroh, Tor/I2P/DoH, syndication, Wasm mods, vector search, local inference, CRDTs, WARC, plus a protocol-handler-trait and opt-in registry sketch. Begins at its own section 2; no section 1 was ever committed.
  • donor_docs_search_findings_summary — (donor verse_docs/research/SEARCH_FINDINGS_SUMMARY.md, commit 04d68365): a ten-topic survey of 27 donor docs written 2026-02-04, worth keeping for its decision record: CRDT/OT not planned for MVP, DOM serialization explicitly avoided, sanitization plus Servo sandboxing for untrusted node data, YaCy-style search deferred to phase 3+, ghost nodes low priority. Its internal links are mostly dead. Dated here from its own date line; the donor filename was undated.

Recovered donor research, second pass (2026-08-18)

Four more donor docs from the same archived repo, this time from its graphshell_docs/research/ tree rather than verse_docs/. All four were orphaned by the same 2026-07-23 consolidation and were indexed nowhere. Same terms as the block above: provenance header on each, none of it implemented, research rather than direction, donor vocabulary throughout (Graphshell is the old browser product, not the remote projection host that took the name back on 2026-07-22; Middlenet is now Nematic; Verse is retired). The companion smolnet pair went to Turnstone's design_docs/.

  • middlenet_vision_synthesis — (donor graphshell_docs/research/, commit 401e2fcc): the big one, and the closest thing the donor had to a whole-product statement of the graph-first browser thesis. Consolidates the owner's vision, three rounds of critique, and a broad small-internet protocol inventory into one document that deliberately separates current commitments from plausible directions from speculative ideas, and closes with an explicit non-conclusions list. Carries a 2026-04-09 implementation baseline noting what had actually landed by then. Its durable claims: the host-envelope model is foundational, the real gaps are identity/addressability/trust UX rather than exotic protocols, and the honest near-term framing is a graph-first browser and portable smolweb document engine rather than a full browser waiting on a JIT. Section 10 organizes protocols by user job rather than by name, which is the part that reads least dated.
  • tool_comparison_product_lessons — (donor graphshell_docs/research/, commit 401e2fcc): the competitor survey behind several founding decisions. TheBrain, Obsidian, Notion, Logseq, Anytype, Tinderbox, Roam, BrainTool, plus TouchGraph and Gource as historical precedent. Its thesis is that the graph view is decorative in every competitor, that it degrades at scale in all of them, and that manual categorization is the tax that causes abandonment. Wider than the later borrowed_ideas_brief, which is the current treatment of overlapping ground. Ends with a table of open product questions, several still open (first-launch graph state, inbox/scratch capture, sub-node addressing for clips).
  • linked_data_over_middlenet_relevance_note — (donor graphshell_docs/research/, commit 401e2fcc): assesses sophia_rs and chaykin. Rules Linked Data in as an enrichment, interchange, and examination lane and out as the canonical internal truth model, with an explicit should-borrow / should-not-borrow split. The negative half anticipates rdf_native_kernel_feasibility, which takes up the same question later.
  • tabfs_tablab_graphshell_relevance_note — (donor graphshell_docs/research/, commit 401e2fcc): sibling note of the same day, on TabFS and TabLab. Keeps the interface idea and not the implementation: browser state should be queryable rather than trapped in UI chrome, with tabs, requests, cookies, console output, and history as inspectable objects. Rules a filesystem mount out as a core app model and names the authority boundaries any such surface would need (cookies, JS evaluation, archive export). Relevant to the automatability lane, not to the canvas.

Recovered donor research, third pass (2026-08-18)

The two Middlenet architecture specs, from the donor's graphshell_docs/technical_architecture/ tree rather than its research tree. They are filed as research here for the same reason the second-pass docs are: nothing in them survives in the code, so they record a road not taken rather than this repo's architecture. Same terms as the blocks above. Recovering them closes the last named cross-references the earlier passes left dangling, from the vision synthesis beside them and from three documents in Turnstone's design_docs/. Their third-pass companions went to Turnstone: the smolnet admission-bar audit, the RSS feed graph model, and the smolweb HTML contract.

  • middlenet_engine_spec — (donor graphshell_docs/technical_architecture/, commit 401e2fcc): names Middlenet as the content space between smallnet and the full web (RSS/Atom, static HTML, Markdown, reader-mode HTTP, plus the smallnet protocols) and specifies a portable WASM engine to serve it across five host envelopes. Its durable half is the rendering strategy: parse every protocol to one canonical semantic document model first and treat HTML as a second lane, which is the shape the stack did adopt, with inker holding the document model and nematic holding the parsers. Its dead half is the packaging: one portable Middlenet engine crate, Blitz DOM plus Stylo plus Taffy painted through a WebRender fork, and a Boa JS tier for light interactivity. Also carries a four-tier protocol coverage table and a security preference hierarchy that picks the encrypted protocol wherever two overlap, which is the rule the trust ladder ended up expressing.
  • middlenet_lane_architecture_spec — (donor graphshell_docs/technical_architecture/, commit 401e2fcc): the crate split and lane model beneath that engine. Three lanes (Direct, HTML, Servo) plus a faithful-source mode, selected per request against HostCapabilities, over four invariants worth keeping: canonical semantic truth is renderer-independent, lanes are replaceable execution strategies, host plumbing is shared, and choosing the full-web lane is an intended outcome rather than a failure. Read its 2026-04-20 implementation note with care. It is the one part of the file reporting landed code rather than intent, and the four crates it reports (middlenet-core, -adapters, -render, -engine) exist nowhere in the current tree, so that slice lived and died in the donor.

mere_docs/design/

  • commons_profile_v1executable profile 2026-07-27: the first communal graph, Knot-document, and encrypted-chat contract. It fixes stable Personae-root authority with Servitor capability checks, pending/effective/revoked projection, explicit p2panda Data Encryption profiles, automated safe epoch retention, immutable message edit/delete facts, facet-grained graph edits, Knot-owned bounded text merge, and partial-history behavior. Outrider keeps LXMF at the boundary; Direct-PHY carrier identity passed on real T114 and Heltec V4 hardware.
  • pane_ux_design_pass_brief — the five-gap pane-UX target (drag-rearrange, frame split, click hierarchy, context menus). (gpui-era; largely realized; merge-then-archive into the frame taxonomy; banner.)
  • gloss_navigator_design — gloss = the Navigator: one configurable summary surface across scope (document ↔ graph ↔ graphlet) and form factor (outline ↔ swatch). §2a (2026-06-22) elevates the swatch to a portable, embeddable primitive — a scoped, condition-filtered graph-element view usable in a node facet pane, a menu, a djot script block, or an orrery card, with gloss as one consumer (half the point of the gloss). Renders as chrome-understood DOM (genet lays out / themes / hit-tests / exposes it), not an opaque netrender::Scene element — so it flows, themes, and embeds; cartography supplies only the geometry, a node swatch's sprite is a DOM <img> (no netrender image primitive), and the existing Scene-based gloss minimap is a candidate to migrate to the DOM swatch. §2b (2026-06-23) resolves the swatch as the Navigator itself: configured by (scope, layout, lens, mode, filters), with scope a containment zoom (node ⊂ graphlet ⊂ graph, node added at the floor) and view ↔ edit an orthogonal toggle (drag handles mutate the scoped element — hull at node scope, membership/layout at graphlet, positions/edges at graph). Names a variant library (layout: minimap/radial/astroid/timeline/kanban/spectral/outline; lens: content-peek/signal-heatmap/facet/the research surfaces; compositional: diff/sparkline/stacked). The gloss is the variant switcher over that space (one surface, no split); the facet/djot/menu are fixed picks; the node facet shape editor is variant #1. One shared library across gloss + facet + djot + menu + the orrery (all ride cartography).
  • graph_roster_and_frame_taxonomy — the graph roster (graph manifest) + the surface/frame taxonomy (orrery/gloss/roster/apparatus/workbench/shellbar); §4 shellbar decision.
  • graphlet_derivation_from_selection — select nodes → reveal latent edges → read the shape (9 canonical detectors over a chosen EdgeProjectionSpec) → crystallize. The read-side sibling of edge creation: reveal/derive/project/frontier are pure read over graph truth; only crystallize writes (one GraphletRef + an Arrangement or Containment edge). Substrate mostly exists (SelectionOverride projection, shapes, binding, reconciliation); the gap is the shape classifier + canvas choreography. Default projection = all-families with the dominant shape pre-ranked.
  • scope_model_reconciliation — decision record (no code) reconciling the scope/graphlet model across four docs after a review found the build + docs had drifted. Does not re-derive the model (gloss_navigator_design §1–§3 is canonical: one Navigator never split, scope = node ⊂ graphlet ⊂ graph, the swatch primitive, graphlets as rule-defined views incl. chronological). Rulings: (1) the wiring build instanced (window-per-graphlet) where the model says scope the one Navigator (arrows + X) — correction; (2) latent graphlets live in forme GraphletRefcloses gloss §8; (3) terminology — graphlet = named scope, it selects not makes nodes, crawl-frontier vs Frontier-kind; (4) derivation preview = the swatch primitive scoped to the selection (kind-preview + edge/scene/theme preset, light in-canvas anchor), not an orrery mutation; (5) traversal always threads → Corridor is the fallback shape, Loose-set rare; (6) the shape classifier is the unbuilt gap, forward derivation (kind→members) is built; (7) relational-browse mints a Linked graphlet (open decision). Open: scope-first-class commit, the relational-browse mint, the in-canvas anchor, classifier ranking strength.
  • node_card_summoning_design: the node-vs-card ontology and the card summoning model. A node is an object (physics body + hull, DOM object for tabbing/a11y) that references addressed things; it is not a document and not a card (the browser-lane plan's thesis is anti-conflation, not anti-card; recorded after a session misread it). Its rendered body is a gnode — one primitive, two render tiers (chrome DOM or in-scene Scene), never a card. Names the card family (preview/snapshot, unvisited fallback, connections swatch, object card, facet + roster detail cards) and its summoning: selection summons the default card (single = preview beside the node, multi = connections swatch), right-click reaches the rest, cycling between a selection's cards is an open idea; aspiration = cards converge on embeddable node control surfaces like the roster's. §5: the rename landed in code 2026-07-02 (OrreryCardOrreryGnode, node_card_viewgnode_view, .node-card.gnode, render_as_cardsrender_gnodes_as_dom, across meerkat/orrery/platen, compiles + 344+85+88 tests green) with banners/fixes pushed to the citing plans. Snapshot-deposit gap (§4, still open): the card re-renders cacheable lanes and shows nothing for scry-tier sites; deposit real pixels on tile close/blur per lane.
  • one_state_n_windows_design — windows as projections: one runner, one app state, each OS window's view function a lens over it, so multi-window synced panels stop being a sync feature (nothing to sync when there is one state). Verified against the live code: today is N doms + N runners + N ShellStates with per-frame chrome_update mirroring and spawn-time chip seeding (the thing to delete). Resolves the topology fork in the thesis toward one forest dom (N window-root elements, per-window layout sessions at their own viewport/DPI, mutation routing by root containment — render_chrome_scene's partition logic is the miniature), because ScriptedDom NodeIds are per-arena and graft_subtree is intra-session, so DOM/layout identity across a tear-out requires one dom. Tear-out = insert_before re-parent; honest claim is "keeps identity + internal state, relayout scoped," not "keeps layout." The mechanism split (§5, reframed same-day): execution is the DOM standard Node.moveBefore() (Chromium early 2025; atomic move preserving iframe/animation/focus state — the graft contract as a standard, and it throws cross-document, ratifying the forest topology), implemented in genet per repos/genet/docs/2026-07-05_movebefore_dom_standard_plan.md (WPT suite already on disk + wired into ports/genet-wpt, expectations "fail" → flips are the done conditions; also fixes insert_before's silent in-tree detach); recognition stays view-layer (portable keyed bookkeeping so a cross-parent key survival lowers to one move_beforekeyed.rs is sibling-scoped and degrades reorders to teardown+build today). Trichotomy (leaf/sticky-note/rekey) becomes plain state operations. Sequenced by done conditions: state split → multi-projection runner → forest dom → portable adoption over moveBefore. Landed so far (2026-07-06): the moveBefore engine slices S1-S5 (genet plan; incl. PortableKeyed + the ctx nursery + (node,path) handler reconciliation — a cross-parent keyed move preserves element/node/state/handlers with one atomic Moved) and step 2's framework half (GenetMultiRunner: one state + N RunnerTree projections, stable ids, dispatch-in-A-updates-B receipts in tests.rs::multi; GenetAppRunner API unchanged). Step 2 (meerkat migration) done 2026-07-07 — Slices 0-3 landed + verified headless (302 tests) and headed; plan archived to archive_docs/2026-07-07_one_state_migration/. Still open: the forest dom (step 3), tiles as portable children (step 4).
  • swatch_primitive_design — the swatch elevated from gloss §2a/§2b's "standalone component" into the fourth graph primitive: the canvas itself (node/edge/field are content, the swatch is the container), so the orrery is the root swatch (scope = whole graph), one curation among many, not a privileged truth surface. Two planes: shared truth (nodes/edges/fields, changed only by assert/retract/delete) vs per-instance curation (scope, layout, lens, hidden cells, camera, selection, mode); hiding is not deleting, and a swatch is a tearout-style view-instance generalizing the per-window WindowView isolation. Resolves DOM-vs-Scene by splitting the element model (semantic placed elements id/kind/rect/z, carrying hit-test + theming + a11y) from rasterization (DOM box / Scene / img, an LOD + context choice the orrery already makes); embedder context sets the LOD ceiling. Factoring: one shared view layer + pluggable geometry and edit strategies keyed by scope. Cells-as-edges (Mark, 2026-06-27): the addressable edge is a (source, target, RelationSelector) cell (relations already distinct in EdgePayload's family sidecars), no storage change; the work is un-collapsing the "one line per pair" render into fanned per-cell edges with per-cell weight + hit-test (= the deferred per-edge selection), aligning with petgraph-rdf's "multi-edge is truth, collapse is an experience-LOD setting." Visibility = forme's default + non-propagating override stack (GraphDefault < GraphViewOverride < SelectionOverride); a per-instance hide stays local, hiding relaxes the spring in that instance only (Mark), membership stays on truth. Templates = gloss §2b's variant library made first-class (named, saveable, per-persona), lock = config-lock not interaction-lock (user-toggleable, reset-to-default the rope back), parametric vs bound scope binding; the generic engine for purpose-built graph UIs (settings/filesystem = locked swatches, gloss = unlocked, node editor = locked). §10 maps each existing fragment (swatch.rs body editor, gloss minimap, object card, connections-swatch TODO, instance machinery, the unbuilt classifier) to its owning plan. No code this session.

mere_docs/testing/

  • burn_0_22_prerelease_closure — the green 0.22.0-pre.2 production row and bounded pre.3 audit; stable release remains the repin gate.
  • browser_model_ceiling_receipt — MiniLM artifact and worker corridor passed, while BrowserWebGpu failed the numerical gate.
  • browser_decoder_receipt — headed decoder lifecycle row passed, including CPU/ESP/BrowserWebGpu exact output, cancellation, teardown, and recovery.
  • browser_model_matrix_receipt — configured D2c embedding matrix passed; the upper embedding boundary exceeded the 438 MB E5-base row.
  • distillery_remote_minilm_receipt — two application-owned endpoints ran the pinned MiniLM workload through Burn Remote.
  • model_session_peft_lora_receipt — clean-source receipt for pinned SmolLM2 plus its PEFT LoRA adapter.
  • flora_tulpa_standing_receiptpassed 2026-08-31: signed three-peer Standing, FLORA, and Tulpa replication; exact heterogeneous-rank FLoRA stacking from reversed arrival order; candidate publication and frozen-electorate adoption; fulfilled commitment; three-store restart and deterministic replay. Records 1/1 integrated, 11/11 Distillery, and 122/122 Gemot tests, plus the corrected Genet pin and direct root-checkout rerun; rerun green 2026-09-02 on the rebased stack together with the Djinn Distillery lane receipts (CPU 2/2, lane 4/4, GPU 1/1), with the windows-msvc Canvas link workaround recorded.
  • headed_automation_plan — the two automation subsystems (in-process agent_harness, headless/deterministic/assert-on-state, the 302 tests; external Win32 PowerShell drivers, headed/visual, scry-shots/*.ps1) and a scheme to unify them under one scenario vocabulary = the registry command ids agent_invoke already uses. Fixed this session (surfaced by the Slice 3 headed check): the dead pelt-shots\harness.ps1 base every driver sourced (→ canonical testing\mere\scripts\mk-harness.ps1 with the EnumWindows largest-for-pid finder + self-capture + ddagrab), the stale exe path + C:\t\meerkat-target target-dir override (→ default repos/mere/target), and the self-capture dead in ChromeRasterPlan::Partitioned (→ fall back to chrome_base_tex in render/paint.rs). Proposes a MEERKAT_SCENARIO self-drive mode so one scenario runs headless (assert) or headed (self-drive + capture) with no OS-input focus race. The Slice 3 flip's headed check (primary + slim leaf both render from one GenetMultiRunner) ran on the new base.

cambium_docs/ — the desktop host and scene family

Area root founded 2026-09-03, ruled by Mark. Cambium (Genet-native reactive GUI toolkit: Meristem's reactive core, Genet DOM backend, Sprigging custom leaves, Workbench composition, the Cambium scene family) landed in this repository the same day (platform boundary plan, P2) and its docs had scattered two ways: the two live plans that moved with it sat in mere_docs/implementation_strategy/ as a two-document lodger, and crates/cambium/docs/ (historical citation) was exactly the member-crate scatter core §4 forbids — invisible to this index, the same defect the 2026-08-24 collapse fixed everywhere else. Both problems close together: everything below moved by git mv (history preserved) into this area root.

cambium_docs/implementation_strategy/

  • fact_visualization_leaves_planV0-V2 landed: consumer-pulled Cambium/Sprigging contracts for a read-only multi-mark angle strip, a read-only dimension line, and a controlled range scrubber with labelled pins. Geometry stays generic and application values, labels, units, provenance, and persistence stay in DOM and product state. Cleromancy's Chart surface is the first consumer of all three.
  • host_ui_zoom_planplan, in progress: one effective layout scale for host chrome, so a Cambium desktop application can be scaled by the application or by the user instead of shipping a fixed layout. Z0-Z4 landed in genet before the 2026-09-03 move; Z5 landed in isometry with its design figure open. Founded when isometry's host migration put a panel laid out for 820 logical pixels on a display offering 752, and it is the host half of the ui_zoom application setting mere's configuration-ownership plan already names and no host applied.
  • workbench_component_planplan, W1-W4 landed; W5 opened 2026-09-04 (Turnstone's panes as tiles, ruled by Mark: serde + a float layer in workbench, a close × and active marking on tab_strip, then Turnstone's compositor walks the shared tree): Workbench is the reusable workspace-organization component — presentation-grade split tree, tab stacks, stable tile identities, arrangement commands, and host effects such as a tearout request — and owns none of browser sessions, graph arrangements, source data, OS windows, or projection definitions. Pelt and Graphshell are parallel hosts; Forme stays durable graph-arrangement authority and Platen compiles a Forme arrangement into a Workbench presentation. W4 captured native Pelt acceptance/cancellation receipts, a headed Graphshell save/mutate/reload receipt, and a Woodshed open-lane consumer. The plan calls it "Genet's" component; the boundary plan reclassed it as application composition, which is Mere's, without changing what it owns.
  • component_catalog_growth_planactive: the ordered expansion and promotion rules for crates/cambium/cambium/examples/component_catalog.rs, Cambium's executable acceptance surface — coverage sequencing, ARIA-pattern targets (combobox, listbox, menu, tabs, radio group, toolbar, toggle button, disclosure, accordion, tree view), and the promotion bar a new component clears before it counts as covered.
  • serval_as_host_xilem_serval_planstrong through Stages 0-7, landed: the founding host-backend plan — serval (Cambium's predecessor name) as the application host with xilem_core reused as a third reactive backend beside Masonry and xilem_web. Retains its original xilem-serval vocabulary for commit-era searchability (component and package names below are current: cambium is the Genet backend, meristem the reactive core, sprigging the custom-leaf library).
  • event_model_convergence_plan — pins the divergence between serval's two capture→target→bubble dispatchers with evidence and defines the one propagation/cancellation contract both must satisfy; retains original xilem-serval vocabulary (see the plan above).
  • chisel_widget_leaf_design — first design pass for a small, sharp custom-paint widget-leaf layer (knobs, meters, waveforms, graph canvases) as first-class elements without a second UI engine; landed as Sprigging's leaf contract. Retains the working name chisel.
  • chisel_widget_catalog — companion catalog + build order mapping what each xilem-serval consumer needs against the leaf contract; landed as Sprigging's glyph catalog (GraphCanvas, Meter, Knob). Retains the working name chisel.

cambium_docs/technical_architecture/

  • cambium_architecture — the ownership rule: Meristem owns reactive diffing/messages/view identity, Cambium owns application views/controls/composition/Genet adapters, Sprigging owns retained custom-leaf state and arrangement helpers, Genet owns DOM/style/layout/paint/input/a11y/browser behavior; the dependency direction is one-way (applications → Cambium → Genet seams), and Genet engine crates must stay free of Cambium/Meristem/Sprigging deps. Moved here 2026-09-03 from crates/cambium/ARCHITECTURE.md (historical citation) as a design document, not crate orientation (the crate's own README.md/CHANGELOG.md stayed put).
  • component-catalog — the coverage rule for the executable component catalog: the ordered table of covered contracts (button/checkbox/switch, hover target, radio group, select, slider, text fields, pane shell + settings form) and their acceptance evidence.
  • genet-compatibility — the verified Genet seam-package set Cambium consumes, the source-vs-registry state of the Cambium stack (meristem, sprigging, cambium, cambium-nematic, cambium-winit, cambium-winit-a11y), the <custom-leaf> / <chisel-leaf> compatibility alias, and the one-way dependency direction rule.
  • graph-canvas-swatchgraph_canvas_swatch, a bounded 260×128 instance of Sprigging's GraphCanvas for a Related panel or preview card: the GraphCanvasSubgraph/GraphViewport contract, node-kind-stays-opaque rule, and the host-owned LeafRegistry rebuild discipline.
  • namespace-claims — the crates.io names claimed 2026-07-13 for this workspace (cambium, meristem, sprigging, genet, genet-stylo) plus cambium-nematic (claimed and released 2026-07-14); a claimed name establishes ownership, not release readiness.
  • upstream-xilem — the Xilem provenance and patch ledger: recorded extraction/upstream commit bases, the three semantic ElementSplice patches (hoist_pending/extract_pending/adopt_pending), the 2026-08-12 scope cut (public trait count 16→10), and the reconciliation-not-re-vendoring update policy against the mark-ik/xilem remote.

cambium_docs/testing/

  • local-genet-development — how to redirect Cambium's Genet seam dependencies to a local Genet checkout for testing unpublished changes via an uncommitted .cargo/config.toml; the two standing rules the hard way (a patch table must name every package the graph pulls from that source, and no workspace member may appear in it — cambium, sprigging, workbench, mere-surface-api and the rest of the landed family are permanently excluded).
  • component catalog receipts — the two committed self-contained HTML captures (420px narrow, 900px regular viewport) generated from the live component catalog and compared byte-for-byte by committed_receipts_match_the_live_catalog; regenerate with cargo run -p cambium --example component_catalog -- --write-receipts.

inker_docs/ — the engine controller

Area root, gone to genet 2026-08-24 with its subject and back 2026-09-03 with it, at the same name and with its history (platform boundary plan, P3). It describes crates/inker/: inker, document-canvas, the scrying/graft/weld engine adapters.

inker_docs/research/

  • web_surface_contract_assessment (assessment 2026-09-03; extraction recommended after repair, not before: separates Graft's native-resource custody, a neutral one-surface protocol, and Inker's host orchestration; keeps the current triplet publication unblocked while requiring correlated async commands, one real ordered event queue, instance-truthful capabilities, explicit frame-transport outcomes, and the owned Graft boundary before a public contract is extracted. It gates the stronger claim that Scry, Weld, and Graft already form one interchangeable browser platform.)

inker_docs/implementation_strategy/

  • engine_picker_and_pluggability_plan (Phases 0–3 shipped + verified — route → activate → manage → pick. The user-facing engine picker as an inker affordance, distinct from verso's flip; the three-level pluggability model (in-build / registered-but-off / active via is_available = contains && enabled), a global default with per-session override, and the two content tiers as the two registries — glass/black-box, wasm/native. No-handler fallback and local-file ingestion are in scope but not yet shipped (Phase 4). Remaining: Phase 4 (no-handler and local files), Phase 2b (per-host and per-session), Phase 5 (the verso flip). Page capture P1 landed 2026-08-30: Inker defines correlated viewport-only capture requests/results, but no engine yet claims support. Its progress log names meerkat, which was deleted 2026-07-18; read those as the Turnstone/mere hosts. Its body's components/inker/... (historical citation) paths are genet's; the code is crates/inker/ here.)

nematic_docs/ — the smolweb engine and knot composition

Same round trip as inker_docs/ above. It describes crates/nematic/ (nematic, illume) and crates/system/errand. Seven documents came back where eight left: genet archived the knot evaluation/export plan on 2026-09-02 and it stays in genet/design_docs/archive_docs/2026-09-02/, cited by path.

nematic_docs/implementation_strategy/

  • polyglot_knot_design (implemented 2026-05-08/09, retained as design rationale and format spec: extends the nematic.knot note format from frontmatter-plus-markdown to a polyglot composition where every other nematic.* protocol's blocks embed fenced-code-block-style and round-trip back to the source protocol's syntax.)
  • polyglot_block_resolver_plan (planned: collapse the three separate passes — expand_fenced_blocks, resolve_transclusions, evaluate_blocks, each with its own dispatch and trust handling — into one registry that resolves any fenced block by its tag, and the new resolver kinds that makes pluggable: graph/eidetic query blocks, diagram DSLs, sandboxed wasm blocks.)
  • native_smolweb_rendering_plan (planning (with Mark): render every smolweb format natively and idiomatically rather than flattening it into one model. The two-family model — document family (djot/markdown/reader-HTML, native Block) versus smolweb family (gemtext/gopher/feed/scroll/misfin, a per-format AST, views shared with the host because they avoid Block). Its §5 crate-home diagram is superseded by the smolweb home decision; crate homes read through that.)
  • smolweb_fidelity_plan (planning (with Mark): recovers the spec-faithfulness the flavour-neutral pipeline collapses. Key code-verified finding — the losses are at the parse ASTs, not the box rendering, so the fix is richer ASTs rather than a different render regime. Three workstreams: enrich the parse ASTs; produce trust at the transport and carry it through the native lane, which currently drops DocumentTrustState; and bespoke rendering only where the line model is not box-shaped, gopher's fixed-width typed column being the clear case. WS1's enrichment lands wherever the grammar lives at the time — if a grammar has moved to a smolweb crate, the enrichment goes there.)

verso_docs/ — rendering surfaces and the engine flip

Same round trip again. It describes the engine flip, which since 2026-09-05 is the flip module of crates/inker/inker (api, orchestrator, scry, and the genet-donor feature); the verso-tile crate it had been was folded in because the flip is the dynamic counterpart of inker's per-address multiplexer and the crate had one external consumer. The docs keep their own root because the charter is a separate argument.

verso_docs/technical_architecture/

  • compatibility_view_charter (charter decision (Mark, 2026-06-10), pre-implementation: verso reborn as the engine-flip / compatibility-view seam — portable view-state carriers and the one-hop invariant, minted at the first genet→scrying flip.)

verso_docs/implementation_strategy/

  • genet_scrying_flipcarrier_plan (design resolved; verso-api plus the genet donor primitives shipped 2026-06-23: the first flip. The plan's crate layering — verso-api plus per-engine verso-genet/verso-scry/verso-weld/verso-graft adapters plus a verso orchestrator — was consolidated into the single verso-tile crate on 2026-07-09 (modules api, flip, scry, and the genet-donor feature); read the plan's crate names as that crate's modules, and its components/verso-tile (historical citation) path as crates/inker/inker/src/flip/ here. Host-wired and feature-gated with no engine stacking; FlipDonor/FlipBack/FlipReceiver encode no-chain in the types. Gated on the inker picker's Phase 4.)

Component areas (collapsed from member crates 2026-08-24)

  • eidetic_docs/ (muniment)muniment_founding_proposal (the seam, the two stores, the codec; P0 done) · redb_opfs_feasibility_plan (active, 2026-08-22: two-engine single-threaded feasibility strongly evidenced; adoption and crash-atomic creation open. Can redb 4.2 run over an OPFS sync-access handle as a muniment backend in a dedicated worker, keeping redb's storage contract and recovery guarantees, with no unsafe thread claim and no browser authority above the seam? Bounded to a probe before the production backend selection; production muniment untouched. Harness at ports/muniment-opfs-probe/ (standalone workspace, MPL-2.0). Proven: stock redb 4.2 compiles for wasm32-unknown-unknown with zero host imports and runs over OPFS in a worker; the Send + Sync bound is met with no unsafe by a realm-qualified worker-local handle registry (the value redb owns holds no JS value, and a cross-thread lookup fails closed); 964 native + 727 browser fault/kill trials with 0 unrecoverable; ownership refusal/takeover/reload deterministic; the same redb file round-trips native↔browser with matching digests; staged creation crash-tested at every real write/resize/sync index (127 trials/engine), 0 unopenable stubs; atomic promotion not established — the move() trials are promotion-boundary kills whose window the harness cannot confine to the rename, and only atomic outcomes have been observed (evidence, not proof; no spec guarantee). Corrected after review: the first pass claimed COMPLETE and recommended against adoption from a totals reading of the benchmark — phase data shows redb is ~8× slower on unbatched durable writes but 9–369× faster on indexed reads (window scans 0.6 ms vs 221.5 ms), so the axis is read/write mix and batching, not a scalar; a log_batched workload matching stickleback::insert_operation's real one-apply-per-operation shape was added. Corrected again after a second review, which found five more defects each of which made a result look stronger than it was: lane 6's sweep silently truncated to 40 of 108 writes and never tested the rename at all; provenance missed the compiled-in muniment source and mislabelled SHA-256 as blake3 (and the --locked workaround was unnecessary — cargo reads config from the working directory, so building from C:\t works and the real lockfile is now hashed); close() still failed open across realms; the native verify skipped its digest check on the one route it guards; and the read benchmark measured muniment's own full-scan adapter rather than IndexedDB. A third backend (IDBKeyRange + getAllKeys) now gives the fair baseline: correcting it moves the numbers but not the conclusion — a range-query adapter is 1.6–1.8× faster on scan-heavy work and ~1.0× elsewhere, while redb stays 19–40× faster than IndexedDB used properly, which prices a third option (fix the shipping adapter) as worth doing but not a substitute. A third review then found four more: the "killed in flight" claim was not established by the harness; the aggregate provenance hash was stale because it was taken over inputs the same run then regenerated; the two engines had benchmarked concurrently on one host, so precise ratios are not decision-grade (runs are now sequential, and the conclusion is scoped to muniment's current Backend contract — one transaction and one get() per key); and the range adapter's prefix + U+10FFFF bound silently omitted keys under IndexedDB's UTF-16 ordering, exposing a genuine seam conflict — muniment's scan is specified in Rust code-point order, IndexedDB orders by UTF-16 code unit, and the two disagree outside the BMP, so no range query can honour the contract there. Bounds fixed, an ASCII key contract added that refuses rather than mis-selects, divergence asserted in tests. A fourth pass then made the benchmark grade itself: the two IndexedDB backends share identical write code, so their write phases are a control that measures only error — and it reports a noise floor of 2.44× (Chromium) / 1.44× (Firefox). Filtered against it, redb's 26–112× indexed-read advantage over range-query IndexedDB holds on both engines by more than an order of magnitude (the finding to lean on), while the third pass's 1.6–1.8× adapter-overhead figure sat below the floor and is withdrawn, along with the "large blobs nearly meet" claim; the write penalty is directionally certain (much worse on Chromium) but unpinned. A genuinely idle host proved unobtainable on this machine, so anything finer than an order of magnitude needs a quieter one. A fifth pass tightened three more: the ASCII key contract was enforced only on scan/list, so a non-ASCII key could enter via put/apply and surface through list("") in IndexedDB's order (now enforced on every key-bearing op, with apply prevalidating the whole batch, plus a browser test); the promotion lane recorded names_stabilized without gating ok on it; and "noise floor" overstated three samples — the benchmark now reports worst-observed ratios beside medians and interleaves repeats. Re-run on a cleared host the control tightened to 0.88–1.11×, never disjoint (from 2.44×), which revised the headline numbers: redb reads faster in every observed repeat across two sequential runs — medians 21–46×, worst single repeat 7.2× (quote the worst, not the median; the first concurrent run's 26–112× overstated it); writes 4.7–10.9× (Chromium) / 1.7–5.0× (Firefox) slower; and the adapter-overhead figure remains unpinned after four attempts (quoted at 1.2×, 1.8×, 2.6×, 3.7× and not always separable) — real in direction, confined to scan-heavy workloads, well under an order of magnitude. A sixth pass then fixed three more: the adapter pricing bypassed the harness's own worst-observed rule; "identical code agrees within ~12%" was read off medians and is false (paired repeats span 0.81–1.11×, and up to 0.70–1.86× on a busy host, so the control is not a calibrated constant); and the browser contract gate read get/list errors as absence/empty instead of failing closed. Landed in cc40c24f (102-file sweep); the fifth-pass fixes are a follow-on. Two-engine replication: Chromium 151 and Firefox 153 run the same lanes from a byte-identical harness (matching source and wasm hashes) and agree on every correctness result — but they diverge on two things previously assumed universal: Chromium's ~2.1 s forcible worker-termination grace is Chromium's alone (Firefox kills in ~91 ms), and the redb/IndexedDB write ratio differs ~3× by engine (4.1× Firefox vs 11.3× Chromium on the shipping shape; parity on large blobs under Firefox, where redb also reads faster). Standing gap: Safari/WKWebView are not run and cannot be driven from this machine. Ends in adopt / fork / reject, against a named consumer's read/write mix and a target-engine weighting.)

Knot effects correction, 2026-07-27: the evaluation/export plan (genet/design_docs/archive_docs/2026-09-02/2026-06-12_knot_evaluation_export_plan.md) has landed exporters plus the pure transclusion/evaluation seams and their Rhai/Lua proofs. The Knot effect bridge, anonymous HTTP/read-only smolweb providers, sanitized HTML fragment lane, and consent surface are live. The sealed derived cache remains open. Pure transforms live in Genet; Knot owns document policy and caches; the Graphshell/Turnstone product surface presents authorized intents. The older summary below overstates product completion.

  • eidetic_docs/eidetic_design_pass (the four-layer memory stack design; mostly built; banner) · eidetic_deferred_phases_plan (the deferred Phases 7-9: OPFS store, browsing memory, search index — spun out of the completed layered-stack plan; umbrella for what stays gated) · eidetic_browsing_derivation_plan (active: Phase 8 + Phase 9's producer half — trace codicils, BrowsingMemory, real-history import, eidetic-search BM25 + hybrid recall + reports; shell surfacing gated on the reshape) · chartulary_g0 (G0 landed: the container/facet substrate) · chartulary_g1 (G1 landed: the edit spine) · chartulary_g2 (G2 landed: fork and lineage) · codicil_founding_proposal (historical proposal for the generic log now folded into muniment::Journal) · scholia_founding_proposal (historical founding; implementation now chartulary::rdf). · eidetic_review_brief (2026-09-04, P5 companion: member-by-member census of the family with line counts, verified in code; the search lane measured — eidetic-search moved to crates/intel/eidetic-search the same day, its tantivy tree is 117 unique packages against 19 without it, and turnstone, the only production consumer, re-mints the whole index on every recorded traversal and never opens one from disk, so TrailIndex::open, top_domains, visits_histogram, rebuild_with_text and all of spec.rs have no consumer; page-body text is never indexed because nothing supplies text_for. Recommends replacing the lexical half with an in-tree BM25 behind the same Hit/fuse surface unless a durable index is wanted, with four named criteria for keeping tantivy; argues against SQLite FTS5 on the links = "sqlite3" conflict and the wasm/OPFS lane. Duplication found: one visited page materializes five times, three transition enums, five url+title shapes, and two independent RDF projectionschartulary::rdf (335 lines, zero consumers) beside mere-linked-data (3,739 lines, no chartulary dependency) mapping the same two schema.org constants. Dead within the family: the lineage feature is enabled by nothing, muniment::ZipBackend (502 lines) and PostcardCodec have no consumers, hagiograph is 26 lines of reservation. Five unsurfaced features (trail reports, TraceEvent::candidates as free training pairs, project_lineage for graphshell, zip export, causal/forked graph journals) and eight numbered questions for Mark.) · lighter_recall_and_standards_ledger_brief (2026-09-07, brainstorm with Mark on the review brief's conclusion: the engine argument holds, but page-body indexing was built and headed-verified in meerkat (C5, 2026-06-28) and lost when turnstone obviated it, and the search wiring plan's 2026-08-26 note that the host supplies page text is false at HEAD (traces carry url and title only). Reframes durability as a cache policy over a derived projection; surveys bm25, probly-search, tinysearch and FTS5 against an in-tree BM25 with one shared tokenizer; proposes frecency from the transition kinds and dwell_ms already in the trace as the cheapest large win, page identity by content fingerprint, and genet's content report and a11y tree as the field-weighted schema. Seeds a standards-to-features ledger (WPT directory, census count, what adhering means, what mere unlocks) and proposes founding it in genet beside the census. Six questions for Mark.)
  • armillary_docs/armillary_founding_proposal (promotes crates/armillary to a standalone crate; unlike the vates and sibylla foundings this is a complete port, not a seam plus a stub).
  • dramatis_docs/personae_founding (founded: the identity core ported verbatim from mere's persona/identity; builds and tests standalone, 32 tests + doctest, and mere keeps its in-tree copy until a deliberate re-base) · personae_across_the_suite (vision / architecture brief: the identity spine of the Merely apps, sitting above the mere-side docs that hold the mechanics) · gaz_founding_plan (M0 landed, M1 persistence next: the contact layer standalone — record model, persona-scoped book, storage over muniment, then the resolver adapters) · ssh_ca_projection_plan (T1–T5 landed 2026-08-12, the same day it was drafted; drafted after the wgpu-weld parity sweep paid the cost of SSH access by hand).
  • intel_docs/feature_target_matrix (the E0 portability receipt for the Vates and Sibylla consolidation; native Windows and wasm32-unknown-unknown; Burn 0.22 prerelease matrix re-run 2026-08-20) · sibylla_README (the local-embedding and semantic-retrieval seam: one EmbeddingProvider trait, a SimilarityMetric per output space, and a pure-Rust retrieval core) · vates_README (the local-model inference seam: one streaming-first InferenceProvider trait, capability descriptors, and a deterministic CannedProvider that exercises the pipeline without a GPU) · index_burn_lift_plan (batched cosine as a matmul; P1 kernel + parity, P2 crossover measured. Historical home — the landed implementation moved unchanged to esp::embed::index_burn on 2026-08-09) · sibylla_founding_proposal and vates_founding_proposal (both superseded 2026-08-09: the implementations now live under esp::embed and esp::infer, and the standalone packages are deprecated compatibility shims. Retained as the historical boundary arguments).
  • scenograph_docs/scene_contract_note (historical 0.0.3 release baseline, landed and consumed: written as rationale for the P2 type sketch before mere wired onto it; mere, isometry and graphshell now all consume the contract) · scenotime_epoch_diff_note (landed and verified locally as the Scenograph half of Graphshell G2: SceneSnapshot wraps a dense sceno::Scene in an explicit SceneEpoch and Revision, over stable source/space/item/relation/region tables).
  • inker_docs/, nematic_docs/, verso_docs/ — back from genet 2026-09-03. They left on 2026-08-24 because their subject lived in genet; the subject moved here under the platform boundary plan's P3 and the roots came with it, at the same names and with their history. They now have full sections of their own above, and are indexed only here. The eighth document, the knot evaluation/export plan, was archived in genet on 2026-09-02 and stays at genet/design_docs/archive_docs/2026-09-02/2026-06-12_knot_evaluation_export_plan.md, cited by path per DOC_POLICY §5.
  • moothold_docs/flora_tulpa_standing_plan (complete 2026-08-31: Standing migration, frozen-electorate Tulpa adoption, exact FLoRA social and tensor contracts, privacy boundaries, and the integrated adoption receipt) · irc_mod_plan (IRC as the first T1 protocol mod) · moot_object_m1_plan (active continuation 2026-09-06: historical M1 plus community collections, author-offline publishing, Fleece/Eidetic preservation, derived search, application co-op, and addressed mesh delivery) · bounty_verification_economy_plan (historical Tessera wording; outer-ring resource economy and verification receipts) · boundary_identity_and_grant_composition (design-session findings: grants live at the data layer so validity is honored-here-now; casts + cross-transport linkage policy; exercise vs transfer as separate rights; moot-as-denizen under suzerainty; provenance vs legibility; the transport-tier counterpart is retinue's 2026-08-09 mesh-scaling doc) · radio_scopes_as_moots (ratified 2026-08-12: retinue's civic-deployment scopes are moots — governance host-side, boards verify a cold signed policy artifact; miscible membership, suzerainty as consent-for-carriage, cast economics metering corroboration; the partition merge rule is now consumed by retinue CV4; corroboration envelope unifies with petition/pin shapes as the default design). (tessera_plan archived 2026-06-09.) Archived 2026-09-02 — retired by the active-tree audit (subject deleted or abandoned); open points extracted to the archived-plan tails.
  • murm_docs/MURM_AS_BILATERAL (murm's bilateral-comms role + boundaries; banner: substrate pivoted to p2panda).

archive_docs/ — superseded checkpoints (DOC_POLICY §4)

  • 2026-05-09_engine_layer_complete/ — the 2026-05-06 graphshell migration plan + donor inventory.
  • 2026-06-04_resource_coordination_merge/ — the 2026-06-03 resource-banking + compute-mesh briefs (merged into the resource-coordination brief).
  • 2026-06-09_completed_plans/ — 21 docs: 17 shipped plans swept on completion (DOC_POLICY §8) plus 4 executed decision-records/roadmaps from the held set (genet_as_host_evaluation, adoption_roadmap, p2panda_substrate_spike_plan, tessera_plan). See its README. Two plans had a live tail spun out first: eidetic Phases 7-9 and workbench staging.
  • 2026-06-09_pivot_superseded/ — 21 docs obsoleted by the meerkat/genet-as-host, p2panda, and graph-canvas-dissolution pivots (incl. the superseded Xilem-host rescaffold); see its README.
  • 2026-06-10_completed_plans/ — the genet-as-host flip plan, closed with a final-state entry (P0-P3 + P5-core shipped; P4 re-homed to integration plan S6; perf story spun out into the host cheap-path plan).
  • 2026-06-15_completed_plans/ — 3 plans swept on completion during the in-the-wings audit doc-hygiene pass: host_cheap_path (perf chain C0–C5+C4c; chrome 4.3×, frame −40%), mesh_m1 (compute mesh M1; two-machine run landed), omnibar_command_shell (privileged >-shell S0–S4 shipped + verified; the sandboxed knot-note lane is a separate plan). See its README.
  • 2026-08-09_completed_plans/ — 2 plans swept the day they landed (DOC_POLICY §8): personal_mesh_substrate_m2 (bounded execution substrate: versioned job wire, host-enforced namespace, one resource registry, lexical ESP adapter) and mesh_lease_scheduler (M3 leases and owner reclaim). Their combined deferrals were spun out into the live mesh host lanes plan first.
  • 2026-07-07_one_state_migration/ — the meerkat one-state-N-windows migration, COMPLETE + verified 2026-07-07. The migration plan (Slices 0-3: SharedChrome seam → WindowLocal split → the atomic flip to Shell.multi: GenetMultiRunner<AppState, BoxedLogic, ShellView> with WindowView.projection_id; the S0 Rc<RefCell<SharedChrome>> collapsed into owned AppState.shared; ShellState/ShellRunner deleted; genet gained ProjectionId(pub usize)) + its Slice 3 execution sub-plan. Verified headless (302 meerkat + 89 xilem-serval tests) and headed (primary + slim leaf render from the one runner). The forward arc (forest dom = design step 3, portable tiles = step 4) lives in the live one_state_n_windows_design; the headed harness it exercised is the headed_automation_plan.

Current workspace topology

Owner map checked against workspace members on 2026-09-05. The manifest is the full package inventory; the platform boundary plan owns the semantic Mere/Genet split. This table locates the main families without treating a directory or published package name as a separate authority.

Family Path Responsibility
Mere facade crates/mere/ Composed graph library consumed by Turnstone and other hosts.
Graph crates/graph/ Graph kernel, linked-data projection, glossary, and graphlets.
Canvas crates/canvas/ Canvas presentation, Cartography readings, and Pictograph derived faces.
Cambium crates/cambium/ Retained widgets, Meristem, Sprigging, Workbench, Tinct theming, and application host adapters. Its scenes/ family contains Sceno, Scenomise, and Scenotime; widget and scene state remain distinct.
Conatus crates/conatus/ Spatial runtime and portable mechanics: Conatus, Numen, Seiche, Nisus, and Modulus. Products retain rules, source identities, and runtime policy.
System crates/system/ Pandect persistence helpers, resident services, Luggage, Notochord, fetch, Errand transport, surface contracts, document lanes, registries, and shell-state/event contracts.
Inker crates/inker/ Engine selection, document-canvas, Verso tile integration, Knot host integration, and scry/graft/weld adapters. Genet retains raw web-platform behavior.
Nematic crates/nematic/ Smolweb realization and text highlighting through Nematic and Illume; consumes the separately owned transport and theming facilities.
Forme / Platen crates/forme/, crates/platen/ Durable graph-arrangement model and its presentation lowering; generic workspace tiles belong to Cambium's Workbench.
Shell / domain crates/shell/, crates/domain/ Chrome/comms and Apparatus, Gloss, Roster, and Trail view domains.
Eidetic crates/eidetic/ Codicil/content storage, Muniment journals, Chartulary and RDF, Hagiograph, and storage/fetch adapters.
Dramatis crates/dramatis/ Personae identity, Insigne, Gaz contacts, persona picker, and related identity/credential composition.
Intel crates/intel/ ESP inference/embeddings, Eidetic search, signals, Mora dictionary, Sibylla, and Vates.
Stickleback / Murm crates/stickleback/, crates/murm/ Replicated-space storage/transfer machinery and bilateral exchange/transport; owning domains decide semantic authority.
Moot crates/moot/ Gemot community authority and Standing, Commons graph operations, Mooting recognition/storage support, Moothold federation, and Mien.
Mesh crates/mesh/ Shared jobs, leases, retention, and host composition under product policy.
Graphshell crates/graphshell/, ports/graphshell/ Projection client/endpoint/carrier contracts and the reference projection host.
Actors / scripts crates/armillary/, crates/script/, crates/servitor/ Actor runtime, script host adapters, and bounded agent participation.
Import / crawl crates/import/, crates/crawl/ Content ingestion and host-governed acquisition.
Ports / probes ports/, crates/probes/ Runnable products and bounded experiments. Knot Editor's product sources live in its independent repository; Alembic and Athanor live under Distillery.

The 2026-05-19 topology snapshot is historical evidence, not the current path or ownership inventory. For the workspace-root Code/crates/ (vendored libs) ↔ Code/repos/ (own projects) split and the cross-repo rename lineage (servo-wgpu→genet, webrender-wgpu→netrender), see 2026-05-24_external_deps_topology_brief.md.

Working principles

  • Current ownership and next work: the platform-boundary plan owns the Mere/Genet split; graph-browser history does not impose a graph root on every product. Keep each plan's current status and the canonical index consistent with its latest verified progress, distinguishing working-tree proofs, committed implementation, consumer adoption, and published releases. A completed prerequisite triggers a fresh dependent-gate check, not an inferred test pass.

  • Printing-press metaphor organizes the data flow in two threads:

    • Per-node content production: engines (Genet, Nematic, scrying) → inker (selects/orchestrates the engine + routing) → per-node engine output.
    • Per-graph-view workbench arrangement: graph truth (graph/graph-kernel) → forme (locks graph members + edges into the arrangement the view will print) → platen (presses the forme into surface/pane output; platen-view realizes it as genet flex DOM, composited by the host). Verso is not a pipeline stage: it names the engine-flip / compatibility-view seam (see the verso_docs charter).
    • eidetic keeps impressions over time (private local memory; content-addressed codicils); node-lineage records per-owner navigation lineage.
  • In-product vocabulary (tiers mere t1 → moot t2 → moothold t3 → gemot t4): mere is the configurable spatial dataspace an application integrates; orrery is its cosmos-style rendering form; moot is a shared, governed mere; moothold holds moots; gemot is the assembly layer. Codicil is an immutable Eidetic exchange record; Journal is an append-only event sequence; Standing is community-scoped reputation from commitment follow-through; FLORA is federated LoRA; Tulpa is a community-recognized collective artifact and identity; Hagiograph is the memorial and legend layer; fauna is a Moot's catalog of shared artifact references.

  • Avoid retired terms: Verse, Murmuration, Gist, Flock, and the old use of Graphshell as Mere's browser/product name. Graphshell now names the separate remote projection host; see the lexicon brief §5 and the Graphshell plan.

  • One link-derivation discipline: a carrier that cannot authenticate its initiator earns Notochord's 16-byte ingress.shared_link by hashing a canonical transcript — blake3, the domain string raw at the front, then u64 little-endian length prefixes on every field. browser_carrier (the WebExtensions bridge) and webrtc-carrier both derive this way, and both bind through initiator_link_binding rather than inventing a proof shape. A new carrier of this kind follows the same recipe; two recipes for one wire slot is a difference with no reason behind it.

  • Cross-referencing: relative links within design_docs/; cite the donor graphshell content via the harvest indexes / GitHub archive (the local donor repo is gone).

Inheritance from graphshell/design_docs/

The donor graphshell repo was GitHub-archived (read-only) and its local clone deleted 2026-05-27; its 633 design docs were swept into two curated indexes that are the entry points for any remaining pull: the full docs harvest and the concept brief. Fetch detail from the GitHub archive when a slice needs it; the old ../../graphshell/design_docs/ local path no longer resolves.

Recovery note, 2026-08-16. A local archived clone of the donor also sits at Code/archive/graphshell. Its design_docs/ tree is deleted at HEAD, so the docs are reachable only through git history (git show <commit>:<path>); the fullest tree is commit 401e2fcc (2026-04-29, 612 files). Eight donor docs orphaned by the 2026-07-23 repo consolidation were recovered from there into mere_docs/research/ (the recovered-donor-research block above); three smolweb browser docs went to Turnstone's design_docs/. Everything else remains where the two harvest indexes left it.

Second pass, 2026-08-18. Six more, from the donor's graphshell_docs/research/ and verso_docs/research/ trees rather than verse_docs/. Four landed in mere_docs/research/ (the second-pass block above); the smolnet pair went to Turnstone as 2026-03-28_smolnet_dependency_health_audit.md and 2026-04-16_smolnet_capability_model_and_scroll_alignment.md. Each header names the commit the text was taken from (401e2fcc for the four here, b86a3906 and c59149c9 for the Turnstone pair), and all six are byte-identical to their copies at 401e2fcc and to the last donor version of the file, so no later revision was missed. Still unrecovered and still worth a look, all present at 401e2fcc: the donor's verso_docs/research/2026-03-28_smolnet_follow_on_audit.md (the admission-bar audit both smolnet docs lean on) and the two Middlenet architecture specs the vision synthesis and the capability model both cite, graphshell_docs/technical_architecture/2026-03-29_middlenet_engine_spec.md and .../2026-04-16_middlenet_lane_architecture_spec.md.

Specifically, the following live in the GitHub archive (read-only), surfaced via the harvest indexes above: TERMINOLOGY.md (pre-Mere terms), engram_spec.md (the 1100+ line engram spec), VERSO_AS_PEER.md, COMMS_AS_APPLETS.md, coop_session_spec.md, and cable_coop_minichat_spec.md.

Status

Pre-1.0 development. Index compacted in the 2026-06-09 design-docs audit (37 docs archived, entries trimmed to one line each). Older dated briefs may cite pre-topology crate paths as historical receipts; the rename-key banners and the topology table above give the current mapping.

2026-06-15 doc-hygiene pass (alongside the in-the-wings audit): 3 completed plans archived to 2026-06-15_completed_plans/ (host_cheap_path, mesh_m1, omnibar_command_shell); 5 active docs reconciled against the live code where their headlines had gone stale (edge_system_audit, engine_picker §2, multi_graph MG6, window_composition, host_wiring_grabbag). The recurring lesson, per the standing rule to verify against the codebase: a plan's headline or Findings section can lag its own Progress log, so trust the code.