{
  "ok": true,
  "code": "MESH-OK",
  "author": "Aziel Eliab",
  "identity": "Aziel Eliab",
  "kernel": "mesh",
  "mesh_default": "on",
  "presence_ttl_ms": 300000,
  "presence_ttl_applies_to": "{slug}-worker",
  "software_presence_ttl_ms": 300000,
  "software_user_heartbeat": false,
  "membership": {
    "spec": "MESH-MEMBERSHIP-1.0",
    "registered_grace_ms": 1209600000,
    "registered_grace_days": 14,
    "heartbeat_miss_n": 3,
    "default_heartbeat_mode": "idle",
    "heartbeat_intervals": {
      "active": {
        "min_ms": 15000,
        "max_ms": 30000,
        "label": "active ~15–30s"
      },
      "idle": {
        "min_ms": 120000,
        "max_ms": 300000,
        "label": "idle background ~2–5 min"
      },
      "asleep": {
        "min_ms": 900000,
        "max_ms": 1800000,
        "label": "asleep/backgrounded ~15–30 min"
      }
    },
    "stale_after_ms": {
      "active": 90000,
      "idle": 900000,
      "asleep": 5400000
    },
    "software_presence_ttl_ms": 300000,
    "software_user_heartbeat": false,
    "presence_ttl_applies_to": "{slug}-worker",
    "session_seal": "sha256",
    "session_seal_v": "mesh-join-session-v1",
    "signing_key_held": false,
    "stale_counts_as_live": false,
    "fail_closed": true,
    "invent_users": false,
    "leave_deletes": true,
    "note": "Human and other non-worker join sessions stay registered until explicit leave or 14 days after the last beat. Adaptive heartbeat: active 15–30s, idle 2–5 min, asleep 15–30 min. Miss 3 beats and the class is stale, not deleted. One beat restores the declared presence. Stale rows do not count as Live Nodes. {slug}-worker suite-presence still drops after 5 minutes and has no user heartbeat. The session seal is SHA-256 of the canonical join fields. This Worker does not hold a mesh-join signing key. Site viewer rows are hub counts, not invented people."
  },
  "spec": "QNM-BUILD-1.0",
  "companion": "AIH-WP-1.1",
  "name": "Quantum Node Mesh",
  "qnm_s": false,
  "qnm_s_note": "Views, MCP, and downloads do not enter QNM-S.",
  "scores": false,
  "leaderboard": false,
  "phoenix_lock": "local wait / re-seal — no controller hunt; not public hostname resurrection",
  "split_wires": "SPLIT-WIRES-1.0",
  "tick_plane": "presence-tip-hash",
  "tick_ms": {
    "min": 500,
    "max": 1000
  },
  "dwell_s": 777,
  "clocks_share_socket": false,
  "split_wires_short": "pull-only payloads, hash-absolute ingest, equivocation = death of that peer, and two clocks that never share a socket. The 1s loop and the 777s gate stay strangers. Anything less is a delayed epidemic.",
  "cold_copy": "COLD-COPY-1.0",
  "cold_copy_short": "Multiply cold copies. Refuse live body sync. Tip expensive to erase. Unkillable by single-server pull. Hash-absolute refuse. Data outlives creators via content-addressed tips + local verify/append. Pull-only cold copies. Named hosts only.",
  "live_body_sync": false,
  "named_hosts_only": true,
  "re_expand": "RE-EXPAND-1.0",
  "re_expand_short": "Bytes survive, not summaries. Re-expand restores from archive after prev-hash verify. Not mesh from index. Crawlers are extra shelves only. Training residue is rumor.",
  "mesh_from_index": false,
  "summaries_survive": false,
  "reheal": "REHEAL-1.0",
  "reheal_short": "Isolation is the cure. Heal from own last good tip + verified trusted pull, or phoenix-WAIT. Never by listening to neighbors. Allowed: live/locked/isolated/tip-hash. Forbidden: bodies/diffs/vote-to-fix. Neighbor talk-back-to-health is a group hug over a wound.",
  "isolation_is_the_cure": true,
  "neighbor_heal": true,
  "neighbor_heal_is_cite": true,
  "neighbor_heal_exec": false,
  "join_is_presence_only": true,
  "join_is_not_login": true,
  "roster_publishes_exec_urls": false,
  "mesh_mutate_rate_kind": "mesh_mutate",
  "roster_cap": 256,
  "vote_to_fix": false,
  "cross_network_survival": "CROSS-NETWORK-SURVIVAL-1.0",
  "cross_network_survival_short": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault). Under that sentence: die-with-the-pull; split-the-wires; cold-copy survival; re-expand-from-archive; REHEAL.",
  "survival_shelves": [
    "hosts",
    "doi",
    "git",
    "vault"
  ],
  "live_network_is_shelf": false,
  "survival": {
    "spec": "CROSS-NETWORK-SURVIVAL-1.0",
    "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
    "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
    "shelves": [
      "hosts",
      "doi",
      "git",
      "vault"
    ],
    "software_tab": false,
    "fraggate_slug": false,
    "named_hosts_only": true,
    "live_network_is_shelf": false,
    "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
  },
  "survival_tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
  "ban_survival": "BAN-SURVIVAL-1.0",
  "local_node": "qnm-node/",
  "local_node_note": "Full node process is local qnm-node/ (boot/chain/apg/bearers/outbox/phoenix/score/memorial/tethers). Packet-transfer coding design is QNS-CD-1.0 (photon QNS1 1.3 on local qnsd; Worker cites only). Channel plane (wifi / bluetooth / rf / photon) is operator-armed cite — live OS/hardware bearers run on that local process, not Worker-proxied VPN. Parent will roll that package. This runtime is suite rollup + operator enable only.",
  "host_note": "azieleliab.com hosts published software/runtime — not login-recovery, not IP panel, not upload proxy. Node Gate / get_is_node_gate is an operator-armed public mesh cite (2026-09-17), not a login-recovery panel.",
  "qns_cd": {
    "spec": "QNS-CD-1.0",
    "local": "https://github.com/AzielEliab/qnm-node",
    "note": "Photon vias on local qnsd; Worker cites only",
    "photon": "QNS1 1.3",
    "magic": "QNS1",
    "process": "qnsd",
    "bind": "127.0.0.1",
    "companion": [
      "QNM-BUILD-1.0",
      "AIH-WP-1.3"
    ],
    "hub_companion": "AIH-WP-1.1",
    "software_tab": false,
    "fraggate_slug": false,
    "public_proxy": false,
    "emit": false,
    "wipe": false,
    "control_plane": false,
    "loopback_only": true,
    "paper": "docs/designs/QNS-CD-1.0.md",
    "path": "/v1/qns"
  },
  "no_lie": true,
  "no_rewrite": true,
  "rewrite_key": false,
  "lie_to_survive": false,
  "copies_one_tunnel": false,
  "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
  "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
  "nine_laws": {
    "hard_true": true,
    "count": 9,
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "author_id": "https://www.azieleliab.com/#aziel",
    "runtime_id": "https://www.azieleliab.com/runtime#runtime",
    "hashtag_parts": {
      "person": "#aziel",
      "runtime": "#runtime"
    },
    "about": {
      "path": "/about",
      "v1": "/v1/about",
      "identity": "Aziel Eliab",
      "always": true
    },
    "clocks_share_socket": false,
    "live_body_sync": false,
    "isolation_is_the_cure": true,
    "neighbor_heal": true,
    "phoenix_local_only": true,
    "die_with_pull": true,
    "restore_godlock_uk": false,
    "node_gate": true,
    "get_is_node_gate": true,
    "implicit_heal": true,
    "auto_heal": true,
    "network": true,
    "network_cite": "on",
    "anonymity_network": true,
    "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
    "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
    "date": "2026-09-17",
    "operator_armed": true,
    "vpn": true,
    "public_vpn": true,
    "tunnel_concentrator": true,
    "concentrator_slug": "azvpn",
    "concentrator_name": "AZVPN",
    "default_vpn_backend": "azvpn",
    "auto_use": true,
    "auto_bind": true,
    "vpn_auto": {
      "default_vpn_backend": "azvpn",
      "auto_use": true,
      "auto_bind": true,
      "concentrator_slug": "azvpn",
      "concentrator_name": "AZVPN",
      "door": "fraggate",
      "explicit_ops": [
        "describe",
        "open",
        "status",
        "list",
        "close",
        "send",
        "recv",
        "pull",
        "peers",
        "attach"
      ],
      "hooks": {
        "mesh_get": "cite-only",
        "mesh_vpn": "ensure",
        "aznet_pair": "cite-and-ensure-when-paired-or-armed",
        "session_open": "ensure-when-armed",
        "azbrowser_vpn": "ensure"
      },
      "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
      "get_never_opens": true,
      "open": false
    },
    "door": "fraggate",
    "worker_terminates_tunnels": true,
    "worker_terminates_kernel_udp": false,
    "wireguard": false,
    "openvpn": false,
    "l3_exit_pool": false,
    "tor": false,
    "socks": false,
    "origin_hiding": false,
    "kinds": {
      "https_ws": "REAL",
      "fraggate_envelopes": "REAL",
      "websocket_attach": "REAL",
      "wireguard": "SLOT",
      "openvpn": "SLOT",
      "l3_exit_pool": "SLOT",
      "kernel_udp": "SLOT",
      "tun_tap": "SLOT"
    },
    "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
    "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
    "operator_override": {
      "spec": "OPERATOR-OVERRIDE-2026-09-17",
      "date": "2026-09-17",
      "identity": "Aziel Eliab",
      "author": "Aziel Eliab",
      "operator_armed": true,
      "auto_heal": true,
      "implicit_heal": true,
      "node_gate": true,
      "get_is_node_gate": true,
      "neighbor_heal": true,
      "neighbor_heal_is_cite": true,
      "neighbor_heal_exec": false,
      "network": true,
      "network_cite": "on",
      "anonymity_network": true,
      "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
      "vpn": true,
      "public_vpn": true,
      "tunnel_concentrator": true,
      "concentrator_slug": "azvpn",
      "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
      "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
    },
    "papers": {
      "node_mesh": "docs/NODE_MESH.md",
      "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
      "node_ops": "docs/designs/NODE-OPS-1.0.md",
      "qnm_wp": "docs/designs/QNM-WP-1.0.md"
    }
  },
  "author_id": "https://www.azieleliab.com/#aziel",
  "runtime_id": "https://www.azieleliab.com/runtime#runtime",
  "hashtag_parts": {
    "person": "#aziel",
    "runtime": "#runtime"
  },
  "about": {
    "path": "/about",
    "v1": "/v1/about",
    "identity": "Aziel Eliab",
    "author_id": "https://www.azieleliab.com/#aziel",
    "always": true
  },
  "payload_plane": "receiver-pull",
  "tick_ms_min": 500,
  "tick_ms_max": 1000,
  "tick_body": false,
  "tick_diff": false,
  "tick_file": false,
  "tip_content_addressed": true,
  "bodies": false,
  "diffs": false,
  "phoenix_local_only": true,
  "neighbor_phoenix": false,
  "public_hostname_resurrection": false,
  "die_with_pull": true,
  "restore_godlock_uk": false,
  "climb_public_hostname": false,
  "apply_last_packet_on_heartbeat_loss": false,
  "node_gate": true,
  "login_mesh": false,
  "login_recovery": false,
  "ip_panel": false,
  "get_is_node_gate": true,
  "implicit_heal": true,
  "auto_heal": true,
  "heartbeat_loss_isolates": false,
  "apply_last_packet": false,
  "network": true,
  "network_cite": "on",
  "anonymity_network": true,
  "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
  "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
  "date": "2026-09-17",
  "operator_armed": true,
  "vpn": true,
  "public_vpn": true,
  "tunnel_concentrator": true,
  "concentrator_slug": "azvpn",
  "concentrator_name": "AZVPN",
  "default_vpn_backend": "azvpn",
  "auto_use": true,
  "auto_bind": true,
  "vpn_auto": {
    "default_vpn_backend": "azvpn",
    "auto_use": true,
    "auto_bind": true,
    "concentrator_slug": "azvpn",
    "concentrator_name": "AZVPN",
    "door": "fraggate",
    "explicit_ops": [
      "describe",
      "open",
      "status",
      "list",
      "close",
      "send",
      "recv",
      "pull",
      "peers",
      "attach"
    ],
    "hooks": {
      "mesh_get": "cite-only",
      "mesh_vpn": "ensure",
      "aznet_pair": "cite-and-ensure-when-paired-or-armed",
      "session_open": "ensure-when-armed",
      "azbrowser_vpn": "ensure"
    },
    "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
    "get_never_opens": true,
    "open": false
  },
  "door": "fraggate",
  "worker_terminates_tunnels": true,
  "worker_terminates_kernel_udp": false,
  "wireguard": false,
  "openvpn": false,
  "l3_exit_pool": false,
  "tor": false,
  "socks": false,
  "origin_hiding": false,
  "kinds": {
    "https_ws": "REAL",
    "fraggate_envelopes": "REAL",
    "websocket_attach": "REAL",
    "wireguard": "SLOT",
    "openvpn": "SLOT",
    "l3_exit_pool": "SLOT",
    "kernel_udp": "SLOT",
    "tun_tap": "SLOT"
  },
  "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
  "note": "QNM suite rollup is LIVE. Read-only suite-presence is ON by default. nodes counts human mesh users plus cited human uses (USES). live_nodes counts human mesh users plus site_live_viewers. software_nodes is the {slug}-worker roster. Counts only — no QNM-S, no leaderboard. GET never pulls hub /count. Uses are counters. SPORE-1.0: this isolate is powered unless a power-loss signal pauses metabolism.",
  "godlock_is_identity": false,
  "operator_override": {
    "spec": "OPERATOR-OVERRIDE-2026-09-17",
    "date": "2026-09-17",
    "identity": "Aziel Eliab",
    "author": "Aziel Eliab",
    "operator_armed": true,
    "auto_heal": true,
    "implicit_heal": true,
    "node_gate": true,
    "get_is_node_gate": true,
    "neighbor_heal": true,
    "neighbor_heal_is_cite": true,
    "neighbor_heal_exec": false,
    "network": true,
    "network_cite": "on",
    "anonymity_network": true,
    "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
    "vpn": true,
    "public_vpn": true,
    "tunnel_concentrator": true,
    "concentrator_slug": "azvpn",
    "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
    "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
  },
  "papers": {
    "node_mesh": "docs/NODE_MESH.md",
    "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
    "node_ops": "docs/designs/NODE-OPS-1.0.md",
    "qnm_wp": "docs/designs/QNM-WP-1.0.md"
  },
  "channel_plane": {
    "spec": "QNM-CHANNEL-PLANE-1.0",
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "operator_armed": true,
    "plane": "channel",
    "wifi": "on",
    "bluetooth": "on",
    "rf": "on",
    "photon": "on",
    "channels": {
      "wifi": "on",
      "bluetooth": "on",
      "rf": "on",
      "photon": "on"
    },
    "bearer": "suite-presence",
    "worker_bearer": "suite-presence",
    "worker_hardware": false,
    "invented_hardware": false,
    "public_proxy": false,
    "local_process": "qnm-node / qnsd",
    "local": "https://github.com/AzielEliab/qnm-node",
    "local_radio_hooks": {
      "path": "qnm-node/bearers/radio.js",
      "law": "LIVE-when-HW-present / refuse-when-absent",
      "mock": false,
      "worker_hardware": false
    },
    "vpn": true,
    "public_vpn": true,
    "tunnel_concentrator": true,
    "concentrator_slug": "azvpn",
    "default_vpn_backend": "azvpn",
    "auto_use": true,
    "worker_terminates_tunnels": true,
    "worker_terminates_kernel_udp": false,
    "tor": false,
    "socks": false,
    "origin_hiding": false,
    "tunnel": false,
    "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
    "node_mesh": "docs/NODE_MESH.md",
    "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
  },
  "channels": {
    "wifi": "on",
    "bluetooth": "on",
    "rf": "on",
    "photon": "on"
  },
  "wifi": "on",
  "bluetooth": "on",
  "rf": "on",
  "photon": "on",
  "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
  "worker_hardware": false,
  "invented_hardware": false,
  "channel_plane_spec": "QNM-CHANNEL-PLANE-1.0",
  "d2d_carriers": {
    "spec": "D2D-CARRIERS-1.0",
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "plane": "track2-reachability",
    "phase": "B+C+D",
    "phases": {
      "A": "landed",
      "B": "LIVE-when-armed",
      "C": "LIVE-when-session",
      "D": "LIVE-when-three-local-nodes / fixture",
      "E": "scaffold"
    },
    "lan_discovery": "LIVE-when-armed",
    "wifi_discovery": "ARMED-when-HW",
    "bluetooth_discovery": "ARMED-when-HW",
    "rf_discovery": "REFUSE-without-HW",
    "photon_discovery": "REFUSE-without-HW",
    "peer_tunnel": "LIVE-when-session",
    "store_forward": "LIVE-when-three-local-nodes / fixture",
    "store_forward_public": "FG-STUB",
    "worker_runs_store_forward": false,
    "second_device": false,
    "bootstrap_list": "scaffold",
    "needs_starting_address": true,
    "shelf_cite": "scaffold",
    "live_multi_provider": false,
    "cold_shelf_live": false,
    "dns_cut": false,
    "origin_cutover": false,
    "warn5_closed": false,
    "worker_door": "FG-STUB",
    "worker_hardware": false,
    "local_node": "qnm-node",
    "get_never_enables": true,
    "separate_from": "cap7-name",
    "cap7_is_name_plane": true,
    "cap7_public_icann": false,
    "cap7_public_egress": false,
    "mirage_is_azvpn": false,
    "aznet_replaces_internet": false,
    "not_a_second_internet": true,
    "alt_internet_live": false,
    "packet_path_live": false,
    "field_1_0": false,
    "warn5": "STANDS-until-demonstrated",
    "warn5_permanent_stay_off": false,
    "preference": "failover",
    "order": [
      "lan",
      "wifi",
      "bluetooth",
      "rf",
      "photon"
    ],
    "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
    "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
    "status": "NOT-READY",
    "code": "FG-STUB",
    "warn5_until": "demonstrated",
    "warn5_by_design": "separate-from-icann",
    "refuse": {
      "packet": "FG-STUB",
      "radio_absent": "QNM-RADIO-ABSENT",
      "cap7_egress": "MG-NO-IP-EXIT",
      "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
      "bearer": "AZP-BEARER-REFUSE",
      "payload": "AZN-NO-PAYLOAD",
      "route": "MESH-NO-ROUTE",
      "stay_off": "MESH-STAY-OFF",
      "nat": "FED-MESH-NAT-REFUSE"
    },
    "carriers": [
      {
        "order": 1,
        "id": "lan",
        "name": "LAN",
        "op": "d2d_lan",
        "status": "NOT-READY",
        "code": "FG-STUB",
        "packet_live": false,
        "mock": false,
        "functional": true,
        "peer_exchange_demonstrated": false,
        "absent_code": "QNM-RADIO-ABSENT",
        "hw": "lan-interface",
        "discovery": "LIVE-when-armed",
        "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
      },
      {
        "order": 2,
        "id": "wifi",
        "name": "Wi-Fi",
        "op": "d2d_wifi",
        "status": "NOT-READY",
        "code": "FG-STUB",
        "packet_live": false,
        "mock": false,
        "functional": true,
        "peer_exchange_demonstrated": false,
        "absent_code": "QNM-RADIO-ABSENT",
        "hw": "wifi-nm",
        "discovery": "ARMED-when-HW",
        "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
      },
      {
        "order": 3,
        "id": "bluetooth",
        "name": "Bluetooth",
        "op": "d2d_bluetooth",
        "status": "NOT-READY",
        "code": "FG-STUB",
        "packet_live": false,
        "mock": false,
        "functional": true,
        "peer_exchange_demonstrated": false,
        "absent_code": "QNM-RADIO-ABSENT",
        "hw": "bluez",
        "discovery": "ARMED-when-HW",
        "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
      },
      {
        "order": 4,
        "id": "rf",
        "name": "RF",
        "op": "d2d_rf",
        "status": "NOT-READY",
        "code": "FG-STUB",
        "packet_live": false,
        "mock": false,
        "functional": true,
        "peer_exchange_demonstrated": false,
        "absent_code": "QNM-RADIO-ABSENT",
        "hw": "rf-beyond-wifi-bt",
        "discovery": "REFUSE-without-HW",
        "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
      },
      {
        "order": 5,
        "id": "photon",
        "name": "Photon",
        "op": "d2d_photon",
        "status": "NOT-READY",
        "code": "FG-STUB",
        "packet_live": false,
        "mock": false,
        "functional": true,
        "peer_exchange_demonstrated": false,
        "absent_code": "QNM-RADIO-ABSENT",
        "hw": "camera-flash",
        "discovery": "REFUSE-without-HW",
        "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
      }
    ],
    "security": {
      "isolation": "single-node security-awareness",
      "phoenix": "local wait / re-seal",
      "mesh_fenced_to_loopback": false,
      "forced_loopback": false,
      "loopback_isolation": false
    },
    "paper": "docs/designs/D2D-CARRIERS-1.0.md",
    "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
  },
  "d2d_status": "NOT-READY",
  "d2d_code": "FG-STUB",
  "packet_path_live": false,
  "alt_internet_live": false,
  "d2d_spec": "D2D-CARRIERS-1.0",
  "op": "status",
  "enabled": true,
  "radios": "on",
  "open_world_awareness": {
    "spec": "OPEN-WORLD-AWARENESS-1.0",
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "open_world_awareness": true,
    "bind": "0.0.0.0",
    "all_interfaces": true,
    "law": "LIVE",
    "status": "live-when-configured",
    "live": false,
    "socket": "live-when-configured",
    "worker_socket": false,
    "qnm_node_bind": "live-when-configured",
    "mock": false,
    "forced_loopback": false,
    "loopback_isolation": false,
    "forced_loopback_is_mesh_fence": false,
    "loopback_isolation_is_mesh_fence": false,
    "mesh_fenced_to_loopback": false,
    "public_egress_ip": false,
    "residential": false,
    "cf_geo_exit": false,
    "cf_geo_exit_pool": false,
    "sticky_public_ip": false,
    "packet_forward": false,
    "packet_forwarding": false,
    "public_icann": false,
    "cap7_is_icann": false,
    "replaces_internet": false,
    "not_a_second_internet": true,
    "hosted_vpn": false,
    "payload_host": false,
    "vpn_hop": false,
    "wireguard": false,
    "openvpn": false,
    "l3_exit": false,
    "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
  },
  "spore": {
    "spec": "SPORE-1.0",
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "person_id": "https://www.azieleliab.com/#aziel",
    "kind": "law",
    "rule": "Last-resort failsafe after live fronts and cold-shelf mutual backup. Power or network loss pauses execution. No pretend-live metabolism. Append-only ChainLock / AKM / receipt DNA stays on cold shelves, local nodes, and tip packs. Resume on power. Wipe resistance is every remaining copy. Plane B/C stay SLOT until attested. Physical wipe only. Does not replace BAN-SURVIVAL or COLD-MULTI-SHELF.",
    "tip": "SPORE-1.0: last-resort failsafe. pause / preserve / wait / physical-wipe-only. Not a replacement for cold shelves. No electricity is PAUSE, not death. Dormant nodes do not invent live heartbeats. On restore, reconcile forward — no rewrite of history.",
    "mode": "live",
    "metabolism": "on",
    "pause": false,
    "preserve": true,
    "wait": false,
    "physical_wipe_only": true,
    "invented_heartbeats": false,
    "failsafe": true,
    "last_resort": true,
    "replaces_cold_shelves": false,
    "replaces_ban_survival": false,
    "cold_shelves_intact": true,
    "mutual_backup_intact": true,
    "faces": [
      "pause",
      "preserve",
      "wait",
      "physical-wipe-only"
    ],
    "serves": "aznet",
    "naming_lock": {
      "sidenet": "aznet",
      "display": "AZNet",
      "spec": "AZN-WP-0.1",
      "separate_brand": false,
      "serves": "aznet",
      "phase": "P3"
    },
    "l0": {
      "layer": 0,
      "id": "aznet",
      "spec": "AZN-WP-0.1",
      "display": "AZNet",
      "role": "silent verification side-net",
      "status": "unbroken",
      "hosts_payloads": false,
      "software_tab": true,
      "changed_by_origin_cutover": false,
      "note": "L0 is the existing AZNet product (AZN-WP-0.1). Survival layers serve it. This cite does not rename, replace, or retarget L0."
    },
    "stack": [
      {
        "layer": 1,
        "id": "live-fronts",
        "spec": "BAN-SURVIVAL-1.0",
        "role": "failover",
        "includes": [
          "cap-7",
          "calling-name",
          "live-node-api"
        ],
        "serves": "aznet"
      },
      {
        "layer": 2,
        "id": "cold-shelves",
        "spec": "COLD-MULTI-SHELF-1.0",
        "role": "mutual-backup",
        "mutual_backup_with": "BAN-SURVIVAL-1.0",
        "plane_b": "slot",
        "plane_c": "slot",
        "replaced": false,
        "failed": false,
        "serves": "aznet"
      },
      {
        "layer": 3,
        "id": "spore",
        "spec": "SPORE-1.0",
        "role": "failsafe",
        "last_resort": true,
        "replaces_cold_shelves": false,
        "replaces_ban_survival": false,
        "serves": "aznet"
      }
    ],
    "re_cold_store": {
      "hook": "RE-COLD-STORE",
      "allowed": true,
      "trigger": "cold-shelves-wiped-or-failed",
      "active": false,
      "shelves_failed": false,
      "shelves_intact": true,
      "invent_live": false,
      "invent_hash": false,
      "invent_receipt": false,
      "invent_destination": false,
      "public_inventory_required": false,
      "destinations": [],
      "opaque_placement": true,
      "note": "When cold stores are wiped or fail, the mesh may re-cold-store DNA wherever available. Never invent LIVE stores, hashes, receipts, or destinations. No required public inventory. Does not claim a wipe is happening now."
    },
    "dna": {
      "chainlock": "append-only tips; no rewrite key",
      "akm": "belief_is_not_truth; memory_get append-only; memory_resolve additive on restore",
      "receipts": "hash still verifies",
      "cold_shelves": "COLD-MULTI-SHELF-1.0 planes A/B/C",
      "local_nodes": "qnm-node + tip packs; bytes↔hash",
      "cap7_aznet": "factory duplication cite LIVE; standard internet does not reach Cap-7"
    },
    "resume": "memory_resolve-additive",
    "rewrite": false,
    "plane_a": "live",
    "plane_b": "slot",
    "plane_c": "slot",
    "doi": null,
    "honesty": {
      "hash_verify_pass_is_not_live": true,
      "do_not_paint_slot_as_live": true,
      "invented_live": false,
      "zenodo_live": false,
      "power_off_is_not_wipe": true,
      "shelves_not_replaced": true,
      "shelves_not_marked_failed": true
    },
    "lamb_lens": {
      "after": "fraggate",
      "policy": "MASTER-33-LL-1.0",
      "v": "LL-1.0",
      "author": "Aziel Eliab",
      "peace": true,
      "clarity": true,
      "service": true,
      "software_tab": false,
      "door": false,
      "note": "Peace: pause metabolism. Clarity: honest dormant vs live. Service: preserve append-only DNA."
    },
    "umbrella": "CROSS-NETWORK-SURVIVAL-1.0",
    "survival_tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
    "ban_survival": "BAN-SURVIVAL-1.0",
    "cold_multi_shelf": "COLD-MULTI-SHELF-1.0",
    "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
    "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
    "signal": null,
    "software_tab": false,
    "fraggate_slug": false,
    "paper": "docs/designs/SPORE-1.0.md",
    "remain_off_untouched": true,
    "visible_1520": false
  },
  "bearers": [
    "suite-presence"
  ],
  "rollup": {
    "locked": 0,
    "isolated": 0,
    "mesh": 36,
    "active": 41,
    "inactive": 0,
    "software": {
      "live": 41,
      "locked": 0,
      "isolated": 0,
      "stale": 0
    },
    "instances": {
      "live": 0,
      "locked": 0,
      "isolated": 0,
      "stale": 0
    },
    "human": {
      "live": 0,
      "locked": 0,
      "isolated": 0,
      "stale": 0
    },
    "handles": {
      "live": 0,
      "locked": 0,
      "isolated": 0,
      "stale": 0
    },
    "ephemeral": {
      "live": 0,
      "locked": 0,
      "isolated": 0,
      "stale": 0
    },
    "named": {
      "live": 0,
      "locked": 0,
      "isolated": 0,
      "stale": 0
    },
    "all": {
      "live": 41,
      "locked": 0,
      "isolated": 0,
      "stale": 0
    },
    "public_live_nodes": "mesh",
    "roster_presence_note": "Public Live Nodes is rollup.mesh (same number as live_nodes). rollup.live is not published. rollup.all.live and rollup.active count roster rows with presence=live on every plane, including {slug}-worker. That count is not the Live Nodes pill. Softwares presence=live is rollup.software.live.",
    "nodes": 54375
  },
  "nodes": 54375,
  "live_nodes": 36,
  "live_nodes_plane": "human-mesh-users-site-viewers",
  "nodes_plane": "human-mesh-users-uses",
  "human_mesh_users": 0,
  "registered_humans": 0,
  "registered_nodes": 0,
  "stale_nodes": 0,
  "stale_humans": 0,
  "registered_note": "registered_nodes and registered_humans count durable non-worker sessions inside the grace window, including stale. They are not Live Nodes. live_nodes counts recent human beats (live or locked, not stale, not isolated) plus site_live_viewers. {slug}-worker rows are software_nodes and are not registered_nodes. Do not invent users.",
  "human_nodes": 0,
  "human_live_nodes": 0,
  "human_locked_nodes": 0,
  "human_isolated_nodes": 0,
  "human_uses": 54375,
  "human_uses_kv": true,
  "human_uses_complete": true,
  "human_uses_source": "uses.total",
  "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
  "site_live_viewers": 36,
  "site_registered_viewers": 40,
  "site_registered_viewers_components": {
    "godlock.uk": 1,
    "azieleliab.com": 3,
    "azielcorpuslibrary.net": 36
  },
  "site_registered_viewers_note": "site_registered_viewers is the last hub-reported count still inside the grace window, including stale hosts. It is not Live Nodes. site_live_viewers counts only a fresh beat. A stale host contributes 0 to Live Nodes. Do not invent viewers.",
  "site_live_viewers_plane": "hub-human-page-presence",
  "site_live_viewers_components": {
    "godlock.uk": 0,
    "azieleliab.com": 0,
    "azielcorpuslibrary.net": 36
  },
  "site_live_viewers_hosts": [
    "godlock.uk",
    "azieleliab.com",
    "azielcorpuslibrary.net"
  ],
  "site_live_viewers_excluded_hosts": [
    "hedidntjump.com"
  ],
  "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
  "site_live_viewers_pull": false,
  "site_live_viewers_complete": true,
  "site_live_viewers_fail_closed": true,
  "site_live_viewers_read": "single-key",
  "live_nodes_generation": 247683,
  "live_nodes_tip": "247683:0:godlock.uk=0,azieleliab.com=0,azielcorpuslibrary.net=36",
  "live_nodes_sealed_at": "2026-10-04T09:40:03.751Z",
  "site_presence_contract": {
    "method": "POST",
    "path": "/v1/mesh/site-presence",
    "alias": "/v1/mesh/site-heartbeat",
    "fraggate": {
      "slug": "mesh",
      "op": "site-presence"
    },
    "body": {
      "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
      "viewers": "non-negative integer concurrent human page sessions (0..10000)",
      "kind": "human-page"
    },
    "ttl_ms": 900000,
    "registered_grace_ms": 1209600000,
    "default_heartbeat_mode": "idle",
    "heartbeat_mode": "active | idle | asleep",
    "stale_keeps_registered": true,
    "stale_counts_as_live": false,
    "allowed_hosts": [
      "godlock.uk",
      "azieleliab.com",
      "azielcorpuslibrary.net"
    ],
    "excluded_hosts": [
      "hedidntjump.com"
    ],
    "refused_kinds": [
      "bot",
      "bots",
      "crawler",
      "software",
      "softwares",
      "download",
      "downloads",
      "instance",
      "mcp"
    ],
    "pull_hub_count": false,
    "invent": false,
    "fail_closed": true,
    "read": "single-key",
    "paint": "live_nodes",
    "local_recompute": false,
    "radios": "not required — hub ingest, not a TX join",
    "rate_kind": "mesh_mutate",
    "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
  },
  "live_nodes_components": {
    "human_mesh_users": 0,
    "site_live_viewers": 36,
    "human_uses_excluded": true,
    "software_nodes_excluded": true,
    "instance_nodes_excluded": true,
    "bots_excluded": true,
    "downloads_excluded": true,
    "hedidntjump_excluded": true,
    "stale_excluded": true,
    "registered_excluded": true,
    "invent_users": false
  },
  "nodes_components": {
    "human_mesh_users": 0,
    "human_uses": 54375,
    "software_nodes_excluded": true,
    "instance_nodes_excluded": true,
    "invent_users": false
  },
  "active_nodes": 41,
  "inactive_nodes": 0,
  "locked_nodes": 0,
  "isolated_nodes": 0,
  "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
  "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
  "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
  "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
  "ephemeral_nodes": 0,
  "ephemeral_live_nodes": 0,
  "software_nodes": 41,
  "software_live_nodes": 41,
  "software_locked_nodes": 0,
  "software_isolated_nodes": 0,
  "instance_nodes": 0,
  "instance_live_nodes": 0,
  "instance_locked_nodes": 0,
  "instance_isolated_nodes": 0,
  "products_present": [
    "4dmap",
    "ark",
    "azai",
    "azbot",
    "azbrowser",
    "azchat",
    "azclce",
    "azcoherence",
    "azhub",
    "aziel-corpus",
    "azieltether",
    "azinterface",
    "azmail",
    "aznet",
    "azos",
    "azvpn",
    "chronolock",
    "codelock",
    "decisiongate",
    "embryolock",
    "employeelock",
    "foldlock",
    "forgereceipts",
    "glossafilter",
    "godlock",
    "mialock",
    "miragegrid",
    "mmconsensus",
    "peacelock",
    "postking",
    "shadowlock",
    "spectrallock",
    "staticclock",
    "temporallock",
    "toolbench",
    "trajectorylock",
    "veillock",
    "vibelock",
    "whistlelock",
    "zkattest",
    "zsolver"
  ],
  "products": [
    "4dmap",
    "ark",
    "azai",
    "azbot",
    "azbrowser",
    "azchat",
    "azclce",
    "azcoherence",
    "azhub",
    "aziel-corpus",
    "azieltether",
    "azinterface",
    "azmail",
    "aznet",
    "azos",
    "azvpn",
    "chronolock",
    "codelock",
    "decisiongate",
    "embryolock",
    "employeelock",
    "foldlock",
    "forgereceipts",
    "glossafilter",
    "godlock",
    "mialock",
    "miragegrid",
    "mmconsensus",
    "peacelock",
    "postking",
    "shadowlock",
    "spectrallock",
    "staticclock",
    "temporallock",
    "toolbench",
    "trajectorylock",
    "veillock",
    "vibelock",
    "whistlelock",
    "zkattest",
    "zsolver"
  ],
  "store": "USES",
  "store_note": "USES KV under mesh| keys (no placeholder namespace ids).",
  "anon_broadcast": "Anon-broadcast is a local sibling of qnm-node/ (text→TTS→desk MP4→metadata-culled file + SHA-256). Style tool. Never a publish path. Not an upload proxy. Not origin-hiding. Operator keeps the file. Not a Softwares-tab product. Not a QNM publish channel. Not a loopback fence of the mesh.",
  "azmail_note": "AZMail mesh_* stays product-local (anonymous mail ring). This surface is QNM rollup + read-only suite-presence, not that ring and not an account mesh.",
  "suite_presence": "on",
  "get_never_enables": true,
  "security": {
    "model": "single-node-security-awareness",
    "isolates": "bad-peer-or-self",
    "mesh_fenced_to_loopback": false,
    "forced_loopback": false,
    "loopback_isolation": false,
    "forced_loopback_is_mesh_fence": false,
    "loopback_isolation_is_mesh_fence": false,
    "phoenix": "local-wait-reseal",
    "phoenix_lock": true,
    "public_hostname_resurrection": false,
    "loopback_bearer": "L1-optional",
    "operator_locks": [
      {
        "n": 1,
        "id": "single-node-security-awareness",
        "status": "LIVE",
        "mesh_fenced_to_loopback": false
      },
      {
        "n": 2,
        "id": "phoenix-reboot-loop",
        "status": "LIVE",
        "phoenix": "local-wait-reseal",
        "phoenix_lock": true,
        "public_hostname_resurrection": false
      },
      {
        "n": 3,
        "id": "open-world-awareness",
        "status": "live-when-configured",
        "law": "LIVE",
        "bind": "0.0.0.0",
        "worker_socket": false,
        "forced_loopback_is_mesh_fence": false,
        "loopback_isolation_is_mesh_fence": false
      }
    ],
    "open_world_awareness": {
      "spec": "OPEN-WORLD-AWARENESS-1.0",
      "author": "Aziel Eliab",
      "identity": "Aziel Eliab",
      "open_world_awareness": true,
      "bind": "0.0.0.0",
      "all_interfaces": true,
      "law": "LIVE",
      "status": "live-when-configured",
      "live": false,
      "socket": "live-when-configured",
      "worker_socket": false,
      "qnm_node_bind": "live-when-configured",
      "mock": false,
      "forced_loopback": false,
      "loopback_isolation": false,
      "forced_loopback_is_mesh_fence": false,
      "loopback_isolation_is_mesh_fence": false,
      "mesh_fenced_to_loopback": false,
      "public_egress_ip": false,
      "residential": false,
      "cf_geo_exit": false,
      "cf_geo_exit_pool": false,
      "sticky_public_ip": false,
      "packet_forward": false,
      "packet_forwarding": false,
      "public_icann": false,
      "cap7_is_icann": false,
      "replaces_internet": false,
      "not_a_second_internet": true,
      "hosted_vpn": false,
      "payload_host": false,
      "vpn_hop": false,
      "wireguard": false,
      "openvpn": false,
      "l3_exit": false,
      "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
    },
    "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
  },
  "peer_bearers": {
    "spec": "FED-MESH-1.0",
    "layer": "L1",
    "default_layer": "L0",
    "opt_in": true,
    "replaces_l0": false,
    "layers": {
      "model": "stack",
      "fork": false,
      "default": "L0",
      "this_pr": "L1",
      "name": "AZnet",
      "aznet_replaces_internet": false,
      "not_a_second_internet": true,
      "get_never_enables": true,
      "softwares_frozen": true,
      "softwares_count": 42,
      "L0": {
        "id": "L0",
        "role": "default",
        "must_keep": true,
        "replaces": false,
        "opt_in": false,
        "path": "Cloudflare Worker, FragGate single door, MCP/OpenAPI/Glama, Softwares 42, HTTPS relay, human UI",
        "note": "Current public path. Unconfigured clients stay here. A direct URL and extra relays are not required."
      },
      "L1": {
        "id": "L1",
        "role": "optional",
        "opt_in": true,
        "default": false,
        "replaces_l0": false,
        "when": "configured",
        "adds": [
          "direct-lan",
          "loopback",
          "multi-relay",
          "FED-MESH-NAT-REFUSE"
        ],
        "note": "Optional peer bearers. Used when a direct URL or an extra relay is configured. NAT hole-punch is refused. Default behavior stays L0."
      },
      "L2": {
        "id": "L2",
        "role": "factory",
        "this_pr": true,
        "replaces_l0": false,
        "factory_exec": true,
        "factory_status": "live",
        "plane": "cap7",
        "dns_publish": false,
        "public_icann": false,
        "public_egress_ip": false,
        "packet_egress": false,
        "adds": "Cap-7 factory exec (geo-target, session-stick, egress-rotate) and the AZNet/AZBrowser pair hook",
        "note": "Cap-7 factory exec is LIVE on the Cap-7 plane. Not a public resolver. Not a public egress IP. public_icann stays false."
      },
      "L3": {
        "id": "L3",
        "role": "registry",
        "this_pr": true,
        "replaces_l0": false,
        "home_origin": "slot",
        "cold_shelves": "slot",
        "adds": "home-origin and cold-shelf registry; phoenix stays local wait / re-seal"
      },
      "L4": {
        "id": "L4",
        "role": "stub",
        "this_pr": true,
        "replaces_l0": false,
        "full_os": false,
        "softwares_ui": false,
        "adds": "AZ-OS three layers by need and an offline stub that uses L0 when a relay is configured"
      }
    },
    "name": "AZnet",
    "not_a_second_internet": true,
    "aznet_replaces_internet": false,
    "public_icann": false,
    "icann_dns": false,
    "radio_phy": false,
    "worker_hardware": false,
    "hole_punch": false,
    "nat_refuse": "FED-MESH-NAT-REFUSE",
    "relay_fallback": true,
    "worker_is_one_relay": true,
    "protocol_requires_this_worker": false,
    "get_never_enables": true,
    "health_check": "GET /v1/mesh/relay",
    "direct_transport": "same signed envelope on loopback or a configured LAN URL; relay is the fallback",
    "modes": [
      {
        "id": "relay-https",
        "title": "Relay HTTPS",
        "transport": "https",
        "hole_punch": false,
        "public_icann": false,
        "radio_phy": false,
        "worker_hardware": false,
        "get_never_enables": true,
        "note": "Signed envelopes to an https relay the node already has. The Worker is one relay. TLS still shows routing metadata."
      },
      {
        "id": "direct-lan",
        "title": "Direct / LAN URL",
        "transport": "configured-url",
        "hole_punch": false,
        "public_icann": false,
        "radio_phy": false,
        "worker_hardware": false,
        "get_never_enables": true,
        "note": "Same signed envelope on a configured LAN URL, or a configured https direct URL the node already has. This Worker does not discover a LAN."
      },
      {
        "id": "loopback",
        "title": "Loopback",
        "transport": "loopback",
        "hole_punch": false,
        "public_icann": false,
        "radio_phy": false,
        "worker_hardware": false,
        "get_never_enables": true,
        "note": "127.0.0.1, localhost, or ::1. Tests and a local node. The Worker never fetches 127.0.0.1."
      }
    ],
    "survival": {
      "spec": "CROSS-NETWORK-SURVIVAL-1.0",
      "cold_multi_shelf": "COLD-MULTI-SHELF-1.0",
      "reheal": "REHEAL-1.0",
      "model": "stack",
      "fork": false,
      "single_method": false,
      "plane_a_is_one_tunnel": true,
      "independent_requirement_met": false,
      "do_not_paint_slot_as_live": true,
      "replaces_l0": false,
      "default": "L0",
      "default_live": "cf-worker-edge",
      "l0_live": true,
      "l1_live": false,
      "name": "AZnet",
      "aznet_replaces_internet": false,
      "not_a_second_internet": true,
      "get_never_enables": true,
      "softwares_frozen": true,
      "softwares_count": 42,
      "no_fan": true,
      "doi": null,
      "cid": null,
      "invented_doi": false,
      "invented_cid": false,
      "zenodo_live": false,
      "runtime_is_shelf": false,
      "methods": [
        {
          "n": 1,
          "id": "cf-worker-edge",
          "layer": "L0",
          "status": "live",
          "live": true,
          "configured": true,
          "implemented": true,
          "opt_in": false,
          "this_pr": false,
          "replaces_l0": false,
          "probed": false,
          "reachability_claimed": false,
          "note": "Cloudflare Worker edge. FragGate, MCP/OpenAPI/Glama, Softwares 42, the HTTPS relay, and the human UI. This is the default path."
        },
        {
          "n": 2,
          "id": "multi-relay",
          "layer": "L1",
          "status": "live-when-configured",
          "live": false,
          "configured": false,
          "implemented": true,
          "opt_in": true,
          "this_pr": true,
          "replaces_l0": false,
          "probed": false,
          "reachability_claimed": false,
          "relay_count": 0,
          "note": "Extra QNM relays. LIVE only when more than one relay URL is named. One relay stays L0. Each relay keeps that handle's sequence. Naming a URL is not a probe."
        },
        {
          "n": 3,
          "id": "direct-lan",
          "layer": "L1",
          "status": "live-when-configured",
          "live": false,
          "configured": false,
          "implemented": true,
          "opt_in": true,
          "this_pr": true,
          "mode": null,
          "nat_punch": "refuse",
          "nat_refuse": "FED-MESH-NAT-REFUSE",
          "hole_punch": false,
          "replaces_l0": false,
          "probed": false,
          "reachability_claimed": false,
          "note": "Configured direct or LAN URL, or loopback. LIVE only when that URL is named and classifies. NAT hole-punch is refused. The Worker does not discover a LAN. Classification is not a reachability claim."
        },
        {
          "n": 4,
          "id": "cap7-mesh-dns",
          "layer": "L2",
          "status": "live",
          "live": true,
          "configured": true,
          "implemented": true,
          "factory_exec": true,
          "factory_status": "live",
          "plane": "cap7",
          "this_pr": true,
          "replaces_l0": false,
          "dns_publish": false,
          "public_icann": false,
          "public_egress_ip": false,
          "packet_egress": false,
          "icann_dns": false,
          "resolves_to_hub": false,
          "mesh_only": true,
          "not_a_second_internet": true,
          "cite_status": "live",
          "ops": [
            "geo-target",
            "session-stick",
            "egress-rotate"
          ],
          "worker_live": true,
          "hosted": true,
          "hosted_vpn": false,
          "miragegrid_pr_landed": true,
          "worker_egress": "https://miragegrid.vibelock.workers.dev/v1/egress",
          "worker_planned": "https://miragegrid.vibelock.workers.dev/v1/planned",
          "residential": false,
          "cf_geo_exit_pool": false,
          "sticky_public_ip": false,
          "packet_forwarding": false,
          "azvpn": false,
          "note": "Cap-7 mesh-name factory exec is LIVE on FragGate. geo-target, session-stick, and egress-rotate run on the Cap-7 plane (region label, sticky mesh node and factory land, land rotate among 7 sites). cite_status alone is not this factory status. The public MirageGrid Worker Cap-7 control plane is LIVE (https://miragegrid.vibelock.workers.dev/v1/egress and https://miragegrid.vibelock.workers.dev/v1/planned). They are not a public egress IP, not a residential IP, not a Cloudflare geo-exit pool, not a sticky public IP, not packet forwarding, not ICANN DNS, and not AZVPN. Not a public resolver. AZNet pairs with AZBrowser through FragGate."
        },
        {
          "n": 5,
          "id": "home-origin",
          "layer": "L3",
          "status": "slot",
          "live": false,
          "configured": false,
          "implemented": false,
          "this_pr": true,
          "replaces_l0": false,
          "cutover": false,
          "shelf_id": "home-origin-mini-pc",
          "spec": "ORIGIN-CUTOVER-1.0",
          "dns_rented": false,
          "live_dns_changed": false,
          "deposited": false,
          "note": "Home-origin / mini-PC behind the edge stays SLOT (ORIGIN-CUTOVER-1.0). No rented DNS, no live DNS change, no deposited bytes. The public path stays L0. The AZNet side-net stays unbroken."
        },
        {
          "n": 6,
          "id": "cold-shelves",
          "layer": "L3",
          "status": "slot",
          "live": false,
          "configured": false,
          "implemented": false,
          "code_ready": true,
          "this_pr": true,
          "replaces_l0": false,
          "re_expand": true,
          "doi": null,
          "cid": null,
          "invented_doi": false,
          "invented_cid": false,
          "no_fan": true,
          "zenodo_live": false,
          "zenodo_refuse": "CNS-ZENODO-NOT-LIVE",
          "doi_refuse": "CNS-NO-TIP-DOI",
          "cid_refuse": "CNS-NO-CID",
          "plane_b": "slot",
          "plane_c": "slot",
          "hash_verify_pass_is_not_live": true,
          "codeberg": {
            "url": "https://codeberg.org/AzielEliab/aziel-lockset-tip",
            "hash_verify": "pass",
            "status": "slot",
            "live": false
          },
          "archive_org": {
            "url": "https://archive.org/details/aziel-lockset-tip",
            "hash_verify": "pass",
            "status": "slot",
            "live": false,
            "same_blast_radius": "archive-org"
          },
          "third_forge": {
            "url": null,
            "status": "slot",
            "live": false,
            "refuse": "CNS-NO-FORGE-MIRROR"
          },
          "gitflic": {
            "url": null,
            "status": "refused",
            "live": false,
            "refuse": "CNS-GITFLIC-EMAIL"
          },
          "usb": {
            "status": "slot",
            "live": false,
            "refuse": "CNS-OPERATOR-ATTEST"
          },
          "note": "Cold shelves for chain re-expand. Codeberg and archive.org hash-verify PASS still SLOT. Third forge URL null (CNS-NO-FORGE-MIRROR). GitFlic refused. USB SLOT. Zenodo is not LIVE. doi null. No invented CID."
        },
        {
          "n": 7,
          "id": "phoenix",
          "layer": "law",
          "spec": "REHEAL-1.0",
          "status": "live",
          "live": true,
          "replaces_l0": false,
          "this_pr": false,
          "controller_hunt": false,
          "vote_to_fix": false,
          "neighbor_vote": false,
          "public_hostname_resurrection": false,
          "note": "Phoenix is local wait / re-seal. No controller hunt. No neighbor vote-to-fix. Isolation is the cure. Not public hostname resurrection."
        }
      ],
      "runtime": {
        "name": "AZnet",
        "slug": "aznet",
        "catalog_label": "AZNet",
        "same_software": true,
        "model": "stack",
        "fork": false,
        "default": "L0",
        "replaces_l0": false,
        "aznet_replaces_internet": false,
        "not_a_second_internet": true,
        "public_icann": false,
        "radio_phy": false,
        "get_never_enables": true,
        "softwares_frozen": true,
        "softwares_count": 42,
        "doi": null,
        "cid": null,
        "L2": {
          "layer": "L2",
          "id": "cap7-mesh-dns",
          "dns_publish": false,
          "status": "live",
          "live": true,
          "factory_exec": true,
          "factory_status": "live",
          "plane": "cap7",
          "worker_live": true,
          "hosted": true,
          "hosted_vpn": false,
          "miragegrid_pr_landed": true,
          "worker_egress": "https://miragegrid.vibelock.workers.dev/v1/egress",
          "worker_planned": "https://miragegrid.vibelock.workers.dev/v1/planned",
          "residential": false,
          "cf_geo_exit_pool": false,
          "sticky_public_ip": false,
          "public_egress_ip": false,
          "packet_egress": false,
          "public_icann": false,
          "resolves_to_hub": false,
          "internet_reachable": false,
          "icann_tld_az": false,
          "standard_internet_reaches_cap7": false,
          "radio_phy": false,
          "replaces_l0": false,
          "cite": {
            "status": "live",
            "path": "/v1/mesh/az-generator",
            "code": "CAP7-CITE",
            "note": "Factory duplication cite stays LIVE. Factory exec is a separate stamp (geo-target, session-stick, egress-rotate). The public MirageGrid Worker Cap-7 control plane is LIVE (https://miragegrid.vibelock.workers.dev/v1/egress and https://miragegrid.vibelock.workers.dev/v1/planned). Not a public resolver. Not a public egress IP. Not a residential IP. Not AZVPN."
          },
          "refuse": {
            "icann": {
              "ok": false,
              "code": "CAP7-RESOLVE-INJECT",
              "public_icann": false
            },
            "register": {
              "ok": false,
              "code": "AZ-GEN-CALL-REFUSED",
              "live_registrar": false
            }
          },
          "aznet_azbrowser": {
            "in_tree": true,
            "spec": "AZN-WP-0.1",
            "peer": "azbrowser",
            "pair_flag": "azbrowser",
            "kind": "functional-order",
            "door": "fraggate",
            "pairing_is_tunnel": false,
            "payload_host": false,
            "public_icann": false,
            "replaces_l0": false,
            "repos": {
              "aznet": "https://github.com/AzielEliab/aznet",
              "azbrowser": "https://github.com/AzielEliab/azbrowser"
            },
            "note": "Functional-order pair with AZBrowser (order/token). Hash continuity / silent side-net. Pairing ≠ tunnel. Pairing is not a VPN product. Public VPN auto-binds AZVPN (default_vpn_backend:azvpn). Products stay separate. FragGate stays THE single door."
          }
        },
        "L3": {
          "layer": "L3",
          "replaces_l0": false,
          "doi": null,
          "cid": null,
          "invented_doi": false,
          "invented_cid": false,
          "no_fan": true,
          "zenodo_live": false,
          "home_origin": {
            "id": "home-origin-mini-pc",
            "spec": "ORIGIN-CUTOVER-1.0",
            "status": "slot",
            "live": false,
            "configured": false,
            "cutover": false,
            "replaces_l0": false,
            "deposited": false,
            "hash_verify": null,
            "hostname": null,
            "ip": null,
            "url": null,
            "dns_rented": false,
            "live_dns_changed": false,
            "doi": null,
            "breaks_live_cf_hubs": false,
            "published_surface": false,
            "software_tab": false,
            "serves": "aznet",
            "display": "AZNet",
            "separate_brand": false,
            "aznet_side_net": "unbroken",
            "public_path_default": "L0",
            "refuse": "OC-HOME-ORIGIN-SLOT",
            "note": "No mini-PC origin is bound. No rented DNS, no live DNS change, no deposited bytes. The public path stays L0. The AZNet side-net stays unbroken. Live Cloudflare hubs stay."
          },
          "cold_shelves": {
            "status": "slot",
            "live": false,
            "hash_verify_pass_is_not_live": true,
            "codeberg": {
              "url": "https://codeberg.org/AzielEliab/aziel-lockset-tip",
              "hash_verify": "pass",
              "status": "slot",
              "live": false
            },
            "archive_org": {
              "url": "https://archive.org/details/aziel-lockset-tip",
              "hash_verify": "pass",
              "status": "slot",
              "live": false
            },
            "third_forge": {
              "url": null,
              "status": "slot",
              "live": false,
              "refuse": "CNS-NO-FORGE-MIRROR"
            },
            "gitflic": {
              "url": null,
              "status": "refused",
              "live": false,
              "refuse": "CNS-GITFLIC-EMAIL"
            },
            "usb": {
              "status": "slot",
              "live": false,
              "refuse": "CNS-OPERATOR-ATTEST"
            },
            "zenodo": {
              "status": "slot",
              "zenodo_live": false,
              "doi": null,
              "refuse": "CNS-ZENODO-NOT-LIVE"
            }
          },
          "phoenix": {
            "id": "phoenix",
            "spec": "REHEAL-1.0",
            "status": "live",
            "live": true,
            "controller_hunt": false,
            "vote_to_fix": false,
            "neighbor_vote": false,
            "public_hostname_resurrection": false,
            "replaces_l0": false,
            "note": "Local wait / re-seal. Isolation is the cure. Not public hostname resurrection."
          }
        },
        "L4": {
          "layer": "L4",
          "product": "azos",
          "source": "https://github.com/AzielEliab/azos",
          "motto": "Integrity precedes execution.",
          "replaces_l0": false,
          "full_os": false,
          "softwares_ui": false,
          "remote_shell": false,
          "exec": false,
          "by_need": [
            {
              "need": "read",
              "status": "live",
              "network": false,
              "live": true,
              "note": "Principles and status can be read with no network. Integrity precedes execution."
            },
            {
              "need": "reach",
              "status": "live-when-online",
              "talks": "L0",
              "live": false,
              "note": "When a relay URL is configured, the offline stub uses that L0 HTTPS path. It does not enable the mesh."
            },
            {
              "need": "execute",
              "status": "refuse",
              "live": false,
              "ops": [
                "exec",
                "shell",
                "lattice"
              ],
              "note": "Host exec stays refuse. This stub does not run a shell."
            }
          ]
        },
        "note": "L2 Cap-7 factory exec is LIVE on the Cap-7 plane (metadata and session land). It does not publish ICANN DNS and it is not a public egress IP. L3 names SLOT shelves and does not cut the edge over to a home machine. L4 reads offline and uses L0 when a relay is configured. None replace L0."
      },
      "note": "Methods are named so survival is not one unnamed tunnel. L0 stays the default public path. L1 is LIVE only when configured. Cap-7 mesh-name factory exec is LIVE on the Cap-7 plane and does not replace L0, publish ICANN DNS, or expose a public egress IP. Home-origin and cold shelves stay SLOT. Phoenix does not replace L0. AZnet does not replace the internet."
    },
    "note": "L0 is the public path and stays the default. L1 peer bearers (relay HTTPS, a configured direct or LAN URL, loopback, extra relays) are opt-in. A peer with no public address and no configured direct URL uses the relay. This protocol does not punch holes through NAT. The Worker does not publish ICANN DNS and does not claim radio PHY without hardware. GET /v1/mesh never enables. AZnet does not replace the internet. Survival methods are named beside L0. The Worker edge is the default LIVE path. Cap-7 factory exec is LIVE on the Cap-7 plane and is not a public egress IP. Cold shelves stay SLOT. doi is null."
  },
  "survival_methods": {
    "spec": "CROSS-NETWORK-SURVIVAL-1.0",
    "cold_multi_shelf": "COLD-MULTI-SHELF-1.0",
    "reheal": "REHEAL-1.0",
    "model": "stack",
    "fork": false,
    "single_method": false,
    "plane_a_is_one_tunnel": true,
    "independent_requirement_met": false,
    "do_not_paint_slot_as_live": true,
    "replaces_l0": false,
    "default": "L0",
    "default_live": "cf-worker-edge",
    "l0_live": true,
    "l1_live": false,
    "name": "AZnet",
    "aznet_replaces_internet": false,
    "not_a_second_internet": true,
    "get_never_enables": true,
    "softwares_frozen": true,
    "softwares_count": 42,
    "no_fan": true,
    "doi": null,
    "cid": null,
    "invented_doi": false,
    "invented_cid": false,
    "zenodo_live": false,
    "runtime_is_shelf": false,
    "methods": [
      {
        "n": 1,
        "id": "cf-worker-edge",
        "layer": "L0",
        "status": "live",
        "live": true,
        "configured": true,
        "implemented": true,
        "opt_in": false,
        "this_pr": false,
        "replaces_l0": false,
        "probed": false,
        "reachability_claimed": false,
        "note": "Cloudflare Worker edge. FragGate, MCP/OpenAPI/Glama, Softwares 42, the HTTPS relay, and the human UI. This is the default path."
      },
      {
        "n": 2,
        "id": "multi-relay",
        "layer": "L1",
        "status": "live-when-configured",
        "live": false,
        "configured": false,
        "implemented": true,
        "opt_in": true,
        "this_pr": true,
        "replaces_l0": false,
        "probed": false,
        "reachability_claimed": false,
        "relay_count": 0,
        "note": "Extra QNM relays. LIVE only when more than one relay URL is named. One relay stays L0. Each relay keeps that handle's sequence. Naming a URL is not a probe."
      },
      {
        "n": 3,
        "id": "direct-lan",
        "layer": "L1",
        "status": "live-when-configured",
        "live": false,
        "configured": false,
        "implemented": true,
        "opt_in": true,
        "this_pr": true,
        "mode": null,
        "nat_punch": "refuse",
        "nat_refuse": "FED-MESH-NAT-REFUSE",
        "hole_punch": false,
        "replaces_l0": false,
        "probed": false,
        "reachability_claimed": false,
        "note": "Configured direct or LAN URL, or loopback. LIVE only when that URL is named and classifies. NAT hole-punch is refused. The Worker does not discover a LAN. Classification is not a reachability claim."
      },
      {
        "n": 4,
        "id": "cap7-mesh-dns",
        "layer": "L2",
        "status": "live",
        "live": true,
        "configured": true,
        "implemented": true,
        "factory_exec": true,
        "factory_status": "live",
        "plane": "cap7",
        "this_pr": true,
        "replaces_l0": false,
        "dns_publish": false,
        "public_icann": false,
        "public_egress_ip": false,
        "packet_egress": false,
        "icann_dns": false,
        "resolves_to_hub": false,
        "mesh_only": true,
        "not_a_second_internet": true,
        "cite_status": "live",
        "ops": [
          "geo-target",
          "session-stick",
          "egress-rotate"
        ],
        "worker_live": true,
        "hosted": true,
        "hosted_vpn": false,
        "miragegrid_pr_landed": true,
        "worker_egress": "https://miragegrid.vibelock.workers.dev/v1/egress",
        "worker_planned": "https://miragegrid.vibelock.workers.dev/v1/planned",
        "residential": false,
        "cf_geo_exit_pool": false,
        "sticky_public_ip": false,
        "packet_forwarding": false,
        "azvpn": false,
        "note": "Cap-7 mesh-name factory exec is LIVE on FragGate. geo-target, session-stick, and egress-rotate run on the Cap-7 plane (region label, sticky mesh node and factory land, land rotate among 7 sites). cite_status alone is not this factory status. The public MirageGrid Worker Cap-7 control plane is LIVE (https://miragegrid.vibelock.workers.dev/v1/egress and https://miragegrid.vibelock.workers.dev/v1/planned). They are not a public egress IP, not a residential IP, not a Cloudflare geo-exit pool, not a sticky public IP, not packet forwarding, not ICANN DNS, and not AZVPN. Not a public resolver. AZNet pairs with AZBrowser through FragGate."
      },
      {
        "n": 5,
        "id": "home-origin",
        "layer": "L3",
        "status": "slot",
        "live": false,
        "configured": false,
        "implemented": false,
        "this_pr": true,
        "replaces_l0": false,
        "cutover": false,
        "shelf_id": "home-origin-mini-pc",
        "spec": "ORIGIN-CUTOVER-1.0",
        "dns_rented": false,
        "live_dns_changed": false,
        "deposited": false,
        "note": "Home-origin / mini-PC behind the edge stays SLOT (ORIGIN-CUTOVER-1.0). No rented DNS, no live DNS change, no deposited bytes. The public path stays L0. The AZNet side-net stays unbroken."
      },
      {
        "n": 6,
        "id": "cold-shelves",
        "layer": "L3",
        "status": "slot",
        "live": false,
        "configured": false,
        "implemented": false,
        "code_ready": true,
        "this_pr": true,
        "replaces_l0": false,
        "re_expand": true,
        "doi": null,
        "cid": null,
        "invented_doi": false,
        "invented_cid": false,
        "no_fan": true,
        "zenodo_live": false,
        "zenodo_refuse": "CNS-ZENODO-NOT-LIVE",
        "doi_refuse": "CNS-NO-TIP-DOI",
        "cid_refuse": "CNS-NO-CID",
        "plane_b": "slot",
        "plane_c": "slot",
        "hash_verify_pass_is_not_live": true,
        "codeberg": {
          "url": "https://codeberg.org/AzielEliab/aziel-lockset-tip",
          "hash_verify": "pass",
          "status": "slot",
          "live": false
        },
        "archive_org": {
          "url": "https://archive.org/details/aziel-lockset-tip",
          "hash_verify": "pass",
          "status": "slot",
          "live": false,
          "same_blast_radius": "archive-org"
        },
        "third_forge": {
          "url": null,
          "status": "slot",
          "live": false,
          "refuse": "CNS-NO-FORGE-MIRROR"
        },
        "gitflic": {
          "url": null,
          "status": "refused",
          "live": false,
          "refuse": "CNS-GITFLIC-EMAIL"
        },
        "usb": {
          "status": "slot",
          "live": false,
          "refuse": "CNS-OPERATOR-ATTEST"
        },
        "note": "Cold shelves for chain re-expand. Codeberg and archive.org hash-verify PASS still SLOT. Third forge URL null (CNS-NO-FORGE-MIRROR). GitFlic refused. USB SLOT. Zenodo is not LIVE. doi null. No invented CID."
      },
      {
        "n": 7,
        "id": "phoenix",
        "layer": "law",
        "spec": "REHEAL-1.0",
        "status": "live",
        "live": true,
        "replaces_l0": false,
        "this_pr": false,
        "controller_hunt": false,
        "vote_to_fix": false,
        "neighbor_vote": false,
        "public_hostname_resurrection": false,
        "note": "Phoenix is local wait / re-seal. No controller hunt. No neighbor vote-to-fix. Isolation is the cure. Not public hostname resurrection."
      }
    ],
    "runtime": {
      "name": "AZnet",
      "slug": "aznet",
      "catalog_label": "AZNet",
      "same_software": true,
      "model": "stack",
      "fork": false,
      "default": "L0",
      "replaces_l0": false,
      "aznet_replaces_internet": false,
      "not_a_second_internet": true,
      "public_icann": false,
      "radio_phy": false,
      "get_never_enables": true,
      "softwares_frozen": true,
      "softwares_count": 42,
      "doi": null,
      "cid": null,
      "L2": {
        "layer": "L2",
        "id": "cap7-mesh-dns",
        "dns_publish": false,
        "status": "live",
        "live": true,
        "factory_exec": true,
        "factory_status": "live",
        "plane": "cap7",
        "worker_live": true,
        "hosted": true,
        "hosted_vpn": false,
        "miragegrid_pr_landed": true,
        "worker_egress": "https://miragegrid.vibelock.workers.dev/v1/egress",
        "worker_planned": "https://miragegrid.vibelock.workers.dev/v1/planned",
        "residential": false,
        "cf_geo_exit_pool": false,
        "sticky_public_ip": false,
        "public_egress_ip": false,
        "packet_egress": false,
        "public_icann": false,
        "resolves_to_hub": false,
        "internet_reachable": false,
        "icann_tld_az": false,
        "standard_internet_reaches_cap7": false,
        "radio_phy": false,
        "replaces_l0": false,
        "cite": {
          "status": "live",
          "path": "/v1/mesh/az-generator",
          "code": "CAP7-CITE",
          "note": "Factory duplication cite stays LIVE. Factory exec is a separate stamp (geo-target, session-stick, egress-rotate). The public MirageGrid Worker Cap-7 control plane is LIVE (https://miragegrid.vibelock.workers.dev/v1/egress and https://miragegrid.vibelock.workers.dev/v1/planned). Not a public resolver. Not a public egress IP. Not a residential IP. Not AZVPN."
        },
        "refuse": {
          "icann": {
            "ok": false,
            "code": "CAP7-RESOLVE-INJECT",
            "public_icann": false
          },
          "register": {
            "ok": false,
            "code": "AZ-GEN-CALL-REFUSED",
            "live_registrar": false
          }
        },
        "aznet_azbrowser": {
          "in_tree": true,
          "spec": "AZN-WP-0.1",
          "peer": "azbrowser",
          "pair_flag": "azbrowser",
          "kind": "functional-order",
          "door": "fraggate",
          "pairing_is_tunnel": false,
          "payload_host": false,
          "public_icann": false,
          "replaces_l0": false,
          "repos": {
            "aznet": "https://github.com/AzielEliab/aznet",
            "azbrowser": "https://github.com/AzielEliab/azbrowser"
          },
          "note": "Functional-order pair with AZBrowser (order/token). Hash continuity / silent side-net. Pairing ≠ tunnel. Pairing is not a VPN product. Public VPN auto-binds AZVPN (default_vpn_backend:azvpn). Products stay separate. FragGate stays THE single door."
        }
      },
      "L3": {
        "layer": "L3",
        "replaces_l0": false,
        "doi": null,
        "cid": null,
        "invented_doi": false,
        "invented_cid": false,
        "no_fan": true,
        "zenodo_live": false,
        "home_origin": {
          "id": "home-origin-mini-pc",
          "spec": "ORIGIN-CUTOVER-1.0",
          "status": "slot",
          "live": false,
          "configured": false,
          "cutover": false,
          "replaces_l0": false,
          "deposited": false,
          "hash_verify": null,
          "hostname": null,
          "ip": null,
          "url": null,
          "dns_rented": false,
          "live_dns_changed": false,
          "doi": null,
          "breaks_live_cf_hubs": false,
          "published_surface": false,
          "software_tab": false,
          "serves": "aznet",
          "display": "AZNet",
          "separate_brand": false,
          "aznet_side_net": "unbroken",
          "public_path_default": "L0",
          "refuse": "OC-HOME-ORIGIN-SLOT",
          "note": "No mini-PC origin is bound. No rented DNS, no live DNS change, no deposited bytes. The public path stays L0. The AZNet side-net stays unbroken. Live Cloudflare hubs stay."
        },
        "cold_shelves": {
          "status": "slot",
          "live": false,
          "hash_verify_pass_is_not_live": true,
          "codeberg": {
            "url": "https://codeberg.org/AzielEliab/aziel-lockset-tip",
            "hash_verify": "pass",
            "status": "slot",
            "live": false
          },
          "archive_org": {
            "url": "https://archive.org/details/aziel-lockset-tip",
            "hash_verify": "pass",
            "status": "slot",
            "live": false
          },
          "third_forge": {
            "url": null,
            "status": "slot",
            "live": false,
            "refuse": "CNS-NO-FORGE-MIRROR"
          },
          "gitflic": {
            "url": null,
            "status": "refused",
            "live": false,
            "refuse": "CNS-GITFLIC-EMAIL"
          },
          "usb": {
            "status": "slot",
            "live": false,
            "refuse": "CNS-OPERATOR-ATTEST"
          },
          "zenodo": {
            "status": "slot",
            "zenodo_live": false,
            "doi": null,
            "refuse": "CNS-ZENODO-NOT-LIVE"
          }
        },
        "phoenix": {
          "id": "phoenix",
          "spec": "REHEAL-1.0",
          "status": "live",
          "live": true,
          "controller_hunt": false,
          "vote_to_fix": false,
          "neighbor_vote": false,
          "public_hostname_resurrection": false,
          "replaces_l0": false,
          "note": "Local wait / re-seal. Isolation is the cure. Not public hostname resurrection."
        }
      },
      "L4": {
        "layer": "L4",
        "product": "azos",
        "source": "https://github.com/AzielEliab/azos",
        "motto": "Integrity precedes execution.",
        "replaces_l0": false,
        "full_os": false,
        "softwares_ui": false,
        "remote_shell": false,
        "exec": false,
        "by_need": [
          {
            "need": "read",
            "status": "live",
            "network": false,
            "live": true,
            "note": "Principles and status can be read with no network. Integrity precedes execution."
          },
          {
            "need": "reach",
            "status": "live-when-online",
            "talks": "L0",
            "live": false,
            "note": "When a relay URL is configured, the offline stub uses that L0 HTTPS path. It does not enable the mesh."
          },
          {
            "need": "execute",
            "status": "refuse",
            "live": false,
            "ops": [
              "exec",
              "shell",
              "lattice"
            ],
            "note": "Host exec stays refuse. This stub does not run a shell."
          }
        ]
      },
      "note": "L2 Cap-7 factory exec is LIVE on the Cap-7 plane (metadata and session land). It does not publish ICANN DNS and it is not a public egress IP. L3 names SLOT shelves and does not cut the edge over to a home machine. L4 reads offline and uses L0 when a relay is configured. None replace L0."
    },
    "note": "Methods are named so survival is not one unnamed tunnel. L0 stays the default public path. L1 is LIVE only when configured. Cap-7 mesh-name factory exec is LIVE on the Cap-7 plane and does not replace L0, publish ICANN DNS, or expose a public egress IP. Home-origin and cold shelves stay SLOT. Phoenix does not replace L0. AZnet does not replace the internet."
  },
  "aznet_layers": {
    "name": "AZnet",
    "slug": "aznet",
    "catalog_label": "AZNet",
    "same_software": true,
    "model": "stack",
    "fork": false,
    "default": "L0",
    "replaces_l0": false,
    "aznet_replaces_internet": false,
    "not_a_second_internet": true,
    "public_icann": false,
    "radio_phy": false,
    "get_never_enables": true,
    "softwares_frozen": true,
    "softwares_count": 42,
    "doi": null,
    "cid": null,
    "L2": {
      "layer": "L2",
      "id": "cap7-mesh-dns",
      "dns_publish": false,
      "status": "live",
      "live": true,
      "factory_exec": true,
      "factory_status": "live",
      "plane": "cap7",
      "worker_live": true,
      "hosted": true,
      "hosted_vpn": false,
      "miragegrid_pr_landed": true,
      "worker_egress": "https://miragegrid.vibelock.workers.dev/v1/egress",
      "worker_planned": "https://miragegrid.vibelock.workers.dev/v1/planned",
      "residential": false,
      "cf_geo_exit_pool": false,
      "sticky_public_ip": false,
      "public_egress_ip": false,
      "packet_egress": false,
      "public_icann": false,
      "resolves_to_hub": false,
      "internet_reachable": false,
      "icann_tld_az": false,
      "standard_internet_reaches_cap7": false,
      "radio_phy": false,
      "replaces_l0": false,
      "cite": {
        "status": "live",
        "path": "/v1/mesh/az-generator",
        "code": "CAP7-CITE",
        "note": "Factory duplication cite stays LIVE. Factory exec is a separate stamp (geo-target, session-stick, egress-rotate). The public MirageGrid Worker Cap-7 control plane is LIVE (https://miragegrid.vibelock.workers.dev/v1/egress and https://miragegrid.vibelock.workers.dev/v1/planned). Not a public resolver. Not a public egress IP. Not a residential IP. Not AZVPN."
      },
      "refuse": {
        "icann": {
          "ok": false,
          "code": "CAP7-RESOLVE-INJECT",
          "public_icann": false
        },
        "register": {
          "ok": false,
          "code": "AZ-GEN-CALL-REFUSED",
          "live_registrar": false
        }
      },
      "aznet_azbrowser": {
        "in_tree": true,
        "spec": "AZN-WP-0.1",
        "peer": "azbrowser",
        "pair_flag": "azbrowser",
        "kind": "functional-order",
        "door": "fraggate",
        "pairing_is_tunnel": false,
        "payload_host": false,
        "public_icann": false,
        "replaces_l0": false,
        "repos": {
          "aznet": "https://github.com/AzielEliab/aznet",
          "azbrowser": "https://github.com/AzielEliab/azbrowser"
        },
        "note": "Functional-order pair with AZBrowser (order/token). Hash continuity / silent side-net. Pairing ≠ tunnel. Pairing is not a VPN product. Public VPN auto-binds AZVPN (default_vpn_backend:azvpn). Products stay separate. FragGate stays THE single door."
      }
    },
    "L3": {
      "layer": "L3",
      "replaces_l0": false,
      "doi": null,
      "cid": null,
      "invented_doi": false,
      "invented_cid": false,
      "no_fan": true,
      "zenodo_live": false,
      "home_origin": {
        "id": "home-origin-mini-pc",
        "spec": "ORIGIN-CUTOVER-1.0",
        "status": "slot",
        "live": false,
        "configured": false,
        "cutover": false,
        "replaces_l0": false,
        "deposited": false,
        "hash_verify": null,
        "hostname": null,
        "ip": null,
        "url": null,
        "dns_rented": false,
        "live_dns_changed": false,
        "doi": null,
        "breaks_live_cf_hubs": false,
        "published_surface": false,
        "software_tab": false,
        "serves": "aznet",
        "display": "AZNet",
        "separate_brand": false,
        "aznet_side_net": "unbroken",
        "public_path_default": "L0",
        "refuse": "OC-HOME-ORIGIN-SLOT",
        "note": "No mini-PC origin is bound. No rented DNS, no live DNS change, no deposited bytes. The public path stays L0. The AZNet side-net stays unbroken. Live Cloudflare hubs stay."
      },
      "cold_shelves": {
        "status": "slot",
        "live": false,
        "hash_verify_pass_is_not_live": true,
        "codeberg": {
          "url": "https://codeberg.org/AzielEliab/aziel-lockset-tip",
          "hash_verify": "pass",
          "status": "slot",
          "live": false
        },
        "archive_org": {
          "url": "https://archive.org/details/aziel-lockset-tip",
          "hash_verify": "pass",
          "status": "slot",
          "live": false
        },
        "third_forge": {
          "url": null,
          "status": "slot",
          "live": false,
          "refuse": "CNS-NO-FORGE-MIRROR"
        },
        "gitflic": {
          "url": null,
          "status": "refused",
          "live": false,
          "refuse": "CNS-GITFLIC-EMAIL"
        },
        "usb": {
          "status": "slot",
          "live": false,
          "refuse": "CNS-OPERATOR-ATTEST"
        },
        "zenodo": {
          "status": "slot",
          "zenodo_live": false,
          "doi": null,
          "refuse": "CNS-ZENODO-NOT-LIVE"
        }
      },
      "phoenix": {
        "id": "phoenix",
        "spec": "REHEAL-1.0",
        "status": "live",
        "live": true,
        "controller_hunt": false,
        "vote_to_fix": false,
        "neighbor_vote": false,
        "public_hostname_resurrection": false,
        "replaces_l0": false,
        "note": "Local wait / re-seal. Isolation is the cure. Not public hostname resurrection."
      }
    },
    "L4": {
      "layer": "L4",
      "product": "azos",
      "source": "https://github.com/AzielEliab/azos",
      "motto": "Integrity precedes execution.",
      "replaces_l0": false,
      "full_os": false,
      "softwares_ui": false,
      "remote_shell": false,
      "exec": false,
      "by_need": [
        {
          "need": "read",
          "status": "live",
          "network": false,
          "live": true,
          "note": "Principles and status can be read with no network. Integrity precedes execution."
        },
        {
          "need": "reach",
          "status": "live-when-online",
          "talks": "L0",
          "live": false,
          "note": "When a relay URL is configured, the offline stub uses that L0 HTTPS path. It does not enable the mesh."
        },
        {
          "need": "execute",
          "status": "refuse",
          "live": false,
          "ops": [
            "exec",
            "shell",
            "lattice"
          ],
          "note": "Host exec stays refuse. This stub does not run a shell."
        }
      ]
    },
    "note": "L2 Cap-7 factory exec is LIVE on the Cap-7 plane (metadata and session land). It does not publish ICANN DNS and it is not a public egress IP. L3 names SLOT shelves and does not cut the edge over to a home machine. L4 reads offline and uses L0 when a relay is configured. None replace L0."
  },
  "hole_punch": false,
  "nat_refuse": "FED-MESH-NAT-REFUSE",
  "worker_is_one_relay": true,
  "not_a_second_internet": true,
  "fanout": "cron-or-request-path",
  "verified_handles": 0,
  "handle_nodes": 0,
  "handle_live_nodes": 0,
  "handle_isolated_nodes": 0,
  "verified_handles_note": "verified_handles counts distinct #handles whose signing key matches the handle and whose presence was seen inside 5 minutes. One handle is one node. Three local instances with three keys are three nodes. The count is handles, not people. software_nodes stays the {slug}-worker roster. instance_nodes stays downloaded Softwares. The published nodes pill stays human mesh users plus cited human uses. The published live_nodes pill stays human mesh users plus site viewers. Handles are not added into those pills.",
  "federated": {
    "spec": "FED-MESH-1.0",
    "title": "FED-MESH-1.0: Local-First Edge Mesh",
    "author": "Aziel Eliab",
    "local_first": true,
    "inner_core": "Raw data, signing keys, and heavy compute stay on the local node.",
    "outer_mesh": "By default the mesh carries signed receipts, state digests (engine_digest-style), and ref updates. Raw data moves only on an explicit end-to-end encrypted share.",
    "worker_requires_plaintext": false,
    "neighborhood": "LAN discovery, preferring cluster peers, and offline work run on the local node. This relay does not discover a LAN. It accepts a later sync of rollups and ref updates whose chains are valid, and it refuses forks.",
    "content_model": "Content-addressed objects. A signed ref update names the handle, ref name, object hash, previous ref hash, sequence, and signature. This relay stores and serves that index and anchors it. It does not need the object bytes.",
    "object_cache": "Optional cache of small public objects. Each object is at most 4096 bytes. The cache holds at most 64 objects and 64KiB. The hash is checked. A mismatch or an oversized body is refused.",
    "object_fetch": "A peer asks { v, kind: object-fetch, hash } and answers { v, kind: object, hash, body_b64 } or FED-MESH-NO-OBJECT.",
    "name_records": "Signed .aziel name records. A self-certifying name is the handle body plus .aziel and is final immediately. A friendly name carries proof-of-work and stays pending until it has aged 72 hours and 2 other handles have witnessed it. The first valid final claim wins. A handle may hold 3 user .aziel names. Four reserved slots mirror the hub sites and are not user-nameable. Transfer and release are signed by the current owner. A fork is refused.",
    "mesh_security": "Friendly claims need proof-of-work, a 72 hour age, and 2 witness handles before they are final. Equivocation proofs flag one handle. This relay does not execute peer code, does not rank handles, and does not cut a peer off the whole mesh.",
    "slots": "Each handle has 4 reserved hub-mirror slots (ae, corpus, godlock, hdj) and 3 user .aziel names, plus the automatic <handle>.aziel name. Reserved slots restore only an object this relay already hash-verified. MirageGrid Cap-7 factory .az names are a separate layer.",
    "user_slot_cap": 3,
    "reserved_slot_cap": 4,
    "reserved_slots": [
      {
        "slot": "ae",
        "hub": "AZ.AzielEliab.AZ",
        "origin": "https://www.azieleliab.com/"
      },
      {
        "slot": "corpus",
        "hub": "AZ.AzielCorpusLibrary.AZ",
        "origin": "https://www.azielcorpuslibrary.net/"
      },
      {
        "slot": "godlock",
        "hub": "AZ.Godlock.AZ",
        "origin": "https://godlock.uk/"
      },
      {
        "slot": "hdj",
        "hub": "AZ.HeDidntJump.AZ",
        "origin": "https://www.hedidntjump.com/"
      }
    ],
    "ethics": "No pornography, no pictures of children, and no hate content in domain names. A matching name isolates that handle. Content classifiers run on the hosting node and are absent here. Isolation stores a reason code and an evidence hash, not the bytes. An appeal requests a re-check and does not clear isolation. The blocklist and classifiers miss names and false-positive. This is not a claim that every violation is caught.",
    "blocklist_version": "FED-MESH-BLOCKLIST-1",
    "classifiers_run_here": false,
    "factory_cap7": "MirageGrid global Cap-7 factory names (azgrid, azcloak, azvault, azshift real; azbooth, azflag, azstandby decoy) are unchanged. They are .az cites, not these per-handle .aziel slots.",
    "name_pow_bits": 8,
    "name_pending_ms": 259200000,
    "witness_k": 2,
    "peer_route_per_min": 30,
    "zero_knowledge": false,
    "state_adversary_protection": false,
    "worker_executes_peer_code": false,
    "scanner": "absent",
    "az_dns": ".az is normal DNS. The exception is the Cap-7 allowlist (azgrid.az, azbooth.az, azcloak.az, azvault.az, azshift.az, azflag.az, azstandby.az) and the AZ.* hub names (AZ.AzielEliab.AZ, AZ.Godlock.AZ, AZ.AzielCorpusLibrary.AZ, AZ.HeDidntJump.AZ). Those are cites, not .aziel name records. Standard internet does not reach Cap-7. AZ.* resolves through hub HTTPS. icann_tld_az is false.",
    "worker_is_one_relay": true,
    "protocol_requires_this_worker": false,
    "tenant_exec_on_worker": false,
    "tenant_tasks": "local nodes",
    "edge_compute_on_worker": false,
    "private_keys_on_worker": false,
    "message_bodies": "X25519-HKDF-SHA256-AES-GCM ciphertext",
    "relay_sees_plaintext": false,
    "receipt_sentences_public": true,
    "transport_confidentiality": "TLS to the relay, when the URL is https. The relay still sees routing metadata. Loopback tests may use http.",
    "nat": "A peer with no public address sends and receives through a relay. This protocol does not punch holes through NAT. An ask to punch refuses FED-MESH-NAT-REFUSE. hole_punch is false. Not public ICANN DNS. Not radio PHY.",
    "direct_transport": "Same signed envelope on loopback or a configured LAN URL. Modes are relay-https, direct-lan, and loopback. The relay is the fallback.",
    "bootstrap": "A new node needs at least one relay address it already has (config, CLI, or a signed list from any relay). A signed list on this Worker is one source. It is not the only source.",
    "failover": "A node may register with more than one relay. Each relay keeps that handle's own sequence. GET /v1/mesh/relay is the health check. A failed check selects the next configured relay. GET never enables.",
    "single_point_of_failure": false,
    "relay_hop": "one forward to relays named on the recipient registration or on an accepted peer list",
    "get_never_enables": true,
    "e2e": true,
    "counts": "verified_handles"
  },
  "calling_name_alert": null,
  "calling_name": {
    "rotated": false,
    "calling_name": "Aziel Runtime",
    "identity": "Aziel Eliab",
    "pull": "/survival",
    "publish": false,
    "mesh_broadcast": false
  },
  "durability": {
    "production_binds": {
      "wrangler": "wrangler.toml [[durable_objects.bindings]]",
      "SESSION": {
        "bound": true,
        "class_name": "RuntimeSession",
        "migration": "v1",
        "durable_commit": true
      },
      "CHAINLOCK": {
        "bound": true,
        "class_name": "ChainWriter",
        "migration": "v2",
        "durable_commit": true
      },
      "RATE": {
        "bound": true,
        "class_name": "RateQuota",
        "migration": "v3",
        "durable_commit": true
      },
      "note": "Production wrangler.toml binds SESSION / CHAINLOCK / RATE. Isolate tests and unbound deploys label MemoryStore / isolate window — not durable-commit."
    },
    "fraggate_ledger": {
      "kind": "ask-refuse-hash-chain",
      "window_cap": 64,
      "ephemeral_window": true,
      "durable_commit": true,
      "durable_commit_label": "CHAINLOCK Durable Object (commit-before-ack, public window last 64)",
      "memory_store_is_durable": false,
      "public_qxact_ledger": false
    },
    "chainlock": {
      "kind": "append-only-stamps",
      "durable_commit": true,
      "durable_commit_label": "CHAINLOCK Durable Object per chain (commit-before-ack)",
      "memory_store_is_durable": false,
      "public_ledger": false
    },
    "session": {
      "kind": "runtime-session",
      "durable_commit": true,
      "durable_commit_label": "SESSION Durable Object (TTL 6h, receipt cap 64)",
      "receipt_cap": 64,
      "ttl_ms": 21600000,
      "memory_store_is_durable": false
    },
    "rate_quota": {
      "kind": "abuse-quota",
      "durable_commit": true,
      "durable_commit_label": "RATE Durable Object (per IP+bucket sliding window)",
      "memory_store_is_durable": false
    },
    "memory_store": {
      "durable": false,
      "durable_commit": false,
      "note": "MemoryStore is in-process isolate memory. Not a durable commit. Do not treat as CHAINLOCK, SESSION, or a public ledger."
    },
    "akm_memory": {
      "durable": false,
      "durable_commit": false,
      "isolate_index": true,
      "ledger": "chainlock-learn",
      "ledger_durable": true,
      "rebuildable": true,
      "rebuild_on_get_miss": true,
      "belief_is_not_truth": true,
      "memory_delete": false,
      "memory_update_overwrite": false,
      "http_dry_run_writes": false,
      "note": "AKM-TRIAD Belief List is derived from the append-only ChainLock learn ledger. Isolate MemoryStore is a cache, never the durable source. GET/resolve/recall rebuild from learn on a cold isolate. Posterior ≠ truth. HTTP dry_run does not write."
    }
  },
  "qns_cd_spec": "QNS-CD-1.0"
}