State of Work
LychD is pre-alpha. This is the canonical revision-wide delivery index: architecture lives in the Covenants, operation in topic pages, application design in the Composition Portfolio, and executable proof in tracked source, tests, lockfiles, and maintained receipts.
The proved envelope is local, loopback-oriented, single-user, and one control process in the repository-test profile. A disposable PostgreSQL receipt covers the real application factory, in-process SAQ, one Bridge Run, shutdown, and a second boot. It does not prove a real systemd/Podman/GPU/model/browser conjunction, remote use, or multi-tenancy.
Outcome matrix
| Scenario | Answer now | Decisive limit |
|---|---|---|
| CLI bootstrap | Partial: grammar, dry-run plans, transactional init/bind, bounded inspection, and guarded deletion have repository evidence. |
No maintained real-host lifecycle receipt. See CLI and embodiment. |
| Local text chat | Partial: the Pydantic AI adapter, local Run engine, and Bridge contracts work in the repository-test envelope. | No inference-engine plus real-browser acceptance receipt. See Bridge and persistence. |
| Browser safety | Loopback only: Host, CORS, CSRF, and generated bind policy are bounded locally. | The bootstrap Sigil is not authentication; remote and untrusted-browser use remain unsupported. |
| PostgreSQL lifecycle | Repository receipt: factory, PostgreSQL, SAQ, HTTP, shutdown, and second-boot projection recovery run together. | Live dispatch, orchestration, and Context are replaced after startup; no real-host or browser proof. |
| Major blockers | Authenticated caller authority, privacy-safe egress, artifact custody, real host/model receipts, native Oculus, and resource-aware scheduling. | Remote transport, federation, executable evolution, durable recall, and vision/audio bytes remain Partial or Designed. |
How to read this page
| State | Meaning |
|---|---|
| Available | Repository evidence supports the written boundary; this is not a production or remote-safety claim. |
| Operator validation | The software path exists, but the named real host, hardware, model, or engine receipt is missing. |
| Partial | A useful verified subset exists; the explicit not-yet boundary remains binding. |
| Designed | Law or design exists, but users cannot rely on the behavior. |
| Experimental | A runnable LychD path intentionally carries an unstable support contract; no current record has this state. |
| External | Another project owns the subject; this page records only LychD's interoperation boundary. |
Project maturity and delivery state are different. An accepted ADR does not prove implementation.
Current evidence envelope
The strongest maintained conjunction uses the real application factory, disposable PostgreSQL, in-process SAQ, HTTP, shutdown, and a second boot, while substituting offline collaborators after startup. It proves wiring and durable projection recovery, not full composed runtime behavior.
- Source: Application factory
- Verification: Two-boot lifecycle
- Law: Quality and Testing
Inscription and embodiment
Rune configuration loading
State: Available
Proved now: Typed TOML Runes load from their declared hierarchy with validated filesystem provenance and frozen root values; nested Animator Rune models and collections are immutable. The writer walks the same exact admitted schema generation as the loader instead of every imported subclass.
Boundary: Configuration parsing and topology do not prove a CLI rite, generated host unit, or running service.
Evidence
- Source: Rune loader, Rune writer
- Verification: Rune loader tests, Rune writer tests
- Law: Configuration
Core CLI rites
State: Partial
Proved now: The closed command grammar, dry-run planners, journaled init and bind,
bounded status and logs, guarded lifecycle control, and receipt-gated deletion
are tested. Mutating paths use revalidation, no-follow identity checks, lifecycle locking, durable
receipts, and explicit rollback or indeterminate outcomes.
Boundary — Not yet: Status omits full readiness and durable-run health; no run-operation command
or authenticated Vessel submission route is delivered; stop refuses an active Vessel without its
authenticated lifecycle port; deletion preserves objects whose creation provenance is not owned.
Unknown unit or mount truth blocks instead of guessing. No maintained real systemd/Podman lifecycle
or GPU receipt exists.
Evidence
- Source: CLI assembly
- Verification: CLI tests
- Law: CLI
Public release artifact chain
State: Designed
Proved now: Distribution, container, archive-audit, source-preflight, and non-publishing candidate declarations exist and are tested without granting publish authority.
Do not expect yet: No maintained receipt pairs this revision as one anonymously installable PyPI package and immutable GHCR image, and no clean-host install/start/reply/stop promotion gate has run.
Evidence
- Source: Package version
- Verification: Release artifact tests
- Version: Distribution declaration
- Law: Packaging
Deployment-plan compilation and materialization
State: Available
Proved now: Soulstone and extension intent compile into validated Quadlet/systemd plans, including Animator targets, conflict topology, and compatible Coven aggregates, and Scribe materializes the declared files. A complete ownership manifest refuses distinct Quadlet/systemd runtime-bearing sources that systemd would resolve to one runtime unit.
Boundary: Generated unit intent does not prove that systemd or Podman started it on a real host.
Evidence
- Source: Deployment transmutation and Scribe ownership manifest
- Verification: Transmutation tests and Scribe tests
- Law: Containers
Runtime actuation and mediated Host Reactor protocol
State: Available
Proved now: The mediated Host Reactor validates and durably claims intent, attests the loaded Scribe graph, performs one bounded target transaction, observes settlement, attempts exact-prior-world compensation, resumes or contains interrupted journal work, and records outcomes under the lifecycle lock.
Boundary: Protocol tests and an isolated private-systemd receipt use inert services, not the
operator's Quadlet/Podman/GPU host. .restored proves the prior world; .contained and unresolved
.processing fence later Reactor work. General repair remains the operator's responsibility.
Evidence
- Source: Host Reactor
- Verification: Reactor tests and private-systemd receipt
- Law: Privilege
systemd user and rootless Podman embodiment
State: Operator validation
Proved now: LychD generates its declared Linux service shape and provides a mediated actuator; Soulstone and Phoenix retain separate identities while sharing validated embedded Quadlet configuration.
Receipt needed: Name the Linux, systemd and Podman versions, generated targets and conflicts, loaded-source attestation, forward switch, compensation, crash recovery, startup, and shutdown. GPU and model proof remains separate.
Evidence
- Source: Quadlet configuration
- Verification: Runtime protocol tests
- Law: Containers
Whole-body snapshot and restore
State: Designed
Proved now: Filesystem preparation exists and the snapshot Covenant defines coordinated filesystem, database, code, and receipt identity.
Do not expect yet: LychD does not freeze, snapshot, restore, and reconcile the whole body as one ritual.
Evidence
- Source: Btrfs preparation
- Verification: Layout tests
- Law: Snapshots
Tomb untrusted execution
State: Designed
Proved now: Security law reserves Tomb as the lower-trust execution boundary.
Do not expect yet: There is no Tomb queue, executor, credential policy, Landlock, or nono
integration.
Evidence
- Law: Security
Persistence, execution, and consent
Phylactery first-light persistence
State: Partial
Proved now: Run, delivery, step, session, consent, checkpoint, and delegated-wait shapes exist
with sequence-fenced claim and settlement, terminal-evidence-fenced owner-specific resume gates,
startup reconciliation, and PostgreSQL migration checks. A real factory receipt completes and
recovers a Bridge Run across two boots. Distinct production asyncpg codecs round-trip plain json
and versioned JSONB, while memory Run, consent, and Bridge-session stores detach mutable values at
the same public boundary as database reads.
Boundary — Not yet: PostgreSQL and SAQ are not one transaction; Step events lack an outbox; memory-profile/PostgreSQL repository parity is incomplete; no general record-retention or compaction path, partition policy, tablespace lifecycle, automatic capacity expansion, or sharding path is delivered; persistent same-boot containment failure has no durable watchdog. The lifecycle receipt substitutes offline collaborators and is not a checkpoint-plus-consent, real-host, inference-engine, or browser receipt.
Evidence
- Source: First-light migration, wait-owner migration, and database factory
- Verification: Run ledger tests, PostgreSQL run-ledger receipts, and two-boot lifecycle
- Law: Persistence
Topology-A local run execution
State: Available
Proved now: One Vessel process admits, claims, executes, cancels, settles, resumes, and projects
Runs against immutable Pattern revisions. Durable publication intent, replay repair, external-wait
relays with capped restart backoff, terminal-evidence repair, bounded identity fencing, bounded
slow-reader resynchronization, and orderly shutdown are tested.
Unresolved child containment stays nonterminal rather than claiming false FAILED truth; a timed-
out cancellation remains CANCELLING. Registry boot derives a private one-to-one legacy_inline
contract, placement, implementation, and resolution lock for each executable v2 station without
changing its frozen Pattern snapshot or digest; exact revision lookup traverses that resolution.
Boundary: This does not prove automatic source compatibility, a transactional event outbox, separate-worker truth, multi-process streaming, federation, or producer backpressure. The private lock is not persisted on Run, portable, configurable, or projected by Loom/Orb; no public Spell or Scroll contribution store is delivered.
Evidence
- Source: Run engine, event bus, workflow resolution, and startup relay
- Verification: Run engine tests, event-bus tests, workflow identity tests, and lifespan tests
- Law: Workers and Workflow
Pydantic AI 1.25.1 cognitive adapter
State: Available
Proved now: LychD constructs typed agents and runs Bridge through the exact
pydantic-ai-slim==1.25.1 contract with serializable state and fail-closed provider profiles.
Boundary: This does not claim Pydantic AI v2 durability, stream events, GraphBuilder, automatic usage propagation, or exact pre-request token counts for current OpenAI-compatible models.
Evidence
- Source: Agent factory
- Verification: Agent factory tests
- Version: Dependency
- Law: Agents
Pydantic AI v2 migration
State: Designed
Proved now: Agent and Graph law records a future v2 migration while the lockfile remains on 1.25.1.
Do not expect yet: V2 messages, toolsets, deferred events, durability, and graph contracts are not installed behavior.
Evidence
- Current baseline: Dependency
- Law: Agents
Graph stasis and consent re-admission
State: Partial
Proved now: Logical parking, bounded approval rounds, exact Consent ownership, simulated
restart, re-admission, idempotent settlement, and fail-closed substitution on resume are tested.
Post-park probe failure preserves AWAITING_CONSENT; uncertain cancellation containment leaves the
Run CANCELLING instead of manufacturing terminal truth. Hardware convergence budgets are
checkpoint-owned per Run and survive a durable park plus a replacement GraphRunner.
Boundary — Not yet: There is no PostgreSQL Consent-plus-Checkpoint restart receipt. A legacy checkpoint from before the hardware-budget field cannot reconstruct attempts that already happened. Multiple approval calls in one model response are rejected, and no production toolset currently originates approval.
Evidence
- Source: Graph runner and Run engine
- Verification: Consent resume tests, Run engine tests, and rehydration tests
- Law: Graph and Human in the Loop
Delegated agent execution
State: Partial
Proved now: Typed requests without credential or ambient-authority fields, artifact references, process-local job submission/adoption/cancellation serialized with runtime-start acceptance, exact wait ownership, terminal-evidenced Graph parking and re-admission, typed containment-profile intent, PostgreSQL shapes, and a no-effect reference adapter exist. The reference adapter reconstructs its deterministic projection for refresh and cancellation after coordinator/runtime restart without replaying an external effect, retains it across failed durable adoption, and retires it after terminal settlement.
Boundary — Not yet: No declared external provider launches. There is no lower-trust executor, credential or egress isolation, process-tree containment, durable artifact custody, measured budgets, real PostgreSQL/provider recovery receipt, or live-browser proof. Request prompts are persisted verbatim; callers must apply the Privacy Cut and egress policy before any future remote runtime receives them. An effectful runtime must also reconcile ambiguous post-transmission start failures through durable provider identity rather than treating a generic exception as proof of failure.
Evidence
- Source: Delegation coordinator, delegated job store, Graph runner, reference runtime, and reference adapter catalogue
- Verification: Delegation tests, restart-resume tests, delegation schema tests, and extension-policy tests
- Law: Workers
Durable in-app Attention
State: Designed
Proved now: Bridge consent cards and shared invalidation-aware counts establish a bounded projection that a future Attention inbox can consume.
Do not expect yet: There is no owned inbox, acknowledgement, retry, expiry, escalation, notification delivery, or external channel.
Evidence
- Source: Bridge consent projection
- Verification: Consent endpoint tests
- Law: Frontend
Animation and orchestration
Animator dispatch spine
State: Available
Proved now: One-shot catalogue hydration, matching, probe publication, grant issue and
settlement, and lease-aware dispatch are tested with duplicate attribution, snapshot isolation,
cancellation invalidation, and strict endpoint-root policy. A non-empty Soulstone [[models]]
catalogue is an ordered exact allowlist, concrete runtime leaves cannot claim a foreign adapter,
and only an exact registered Portal definition can create a Portal runtime or capability. Every
issue re-probes the exact chosen record rather than trusting cached warmth. Fixed
OpenAI-compatible local and opt-in Portal probes
validate /models inventory and warm only an exact returned model id; malformed or missing
inventory fails closed, and inventory count and id length are bounded before retention. A
served_model_id Rune field pins the provider-facing identity when it differs from a path or
Soulstone name. The v1 grant exposes no Animator or Connector: chat admits a hydrated model and
only declared agent-loop toolsets, tool_execution requires a non-empty toolset, and all
metadata-only families fail closed. There is no public registry handle-binding bypass around grant
issue. Registry-level Portal issue is quarantined as well as both Dispatcher entry points.
Boundary: This is the v1 {animator}:{family}:{model_id} catalogue with one chat-model/toolset
compatibility grant, not the general discriminated grant union. The catalogue has no in-process
hot reload; lease expiry is recorded but not enforced; current Soulstone/Portal inheritance and raw
Quadlet contribution remain. General interface/profile compilation, call/job/session grants,
[[capabilities]], service-job attempts, per-dialect OpenAI-compatible drivers, and secret-vault
integration are not delivered.
Evidence
- Source: Animator registry, Soulstone Rune schema, OpenAI-compatible probe, and fixed-runtime projection
- Verification: Registry tests, runtime adapter tests, catalogue tests, endpoint-policy tests, declaration-compiler tests, and Portal tests
- Law: Dispatcher
General service capability substrate
State: Designed
Proved now: No general-service implementation is claimed. Accepted law separates semantic interfaces, immutable implementation profiles, typed demand, readiness, discriminated model/call/job/session grants, exact Connector dialects, and durable service attempts while retaining the current model path as explicit v1 compatibility.
Do not expect yet: There is no CapabilitySpecV2, CapabilityDemand@1, [[capabilities]]
compiler, general call/job/session driver registry, ServiceJobAttempt@1 persistence or relay,
AWAITING_SERVICE, local durable reservation transfer, OpenAI audio/image/video dialect bake, or
CapabilitySet placement solver.
Evidence
- Topic: Capabilities and Connectors
- Law: Dispatcher, Workers, and Graph
Extension activation and contributions
State: Partial
Proved now: Dependency-first built-in assembly supplies Rune, Portal, runtime, Quadlet, and delegation contributions under provider-bound registration, sealed membership, owned schema branches, and fail-closed synchronous hooks.
Boundary — Not yet: Ownership is not projected into every live capability view. Package installation, locks, upgrade/uninstall, migrations, lifecycle effects, Forge admission, and a stable public SDK are absent.
Evidence
- Source: Extension manager, registration context, and assembly host
- Verification: Assembly tests, activation tests, delegation contribution tests, and generated bind-fileset tests
- Law: Extensions
llama.cpp integration
State: Operator validation
Proved now: Runtime planning, static and router connectors, discovery, capability derivation, load/unload control, and contract tests exist.
Receipt needed: Name the image and revision, model and quantization, GPU and driver, flags, systemd/Podman host, load, inference, and unload results.
Evidence
- Source: llama.cpp adapter
- Verification: Adapter tests
- Law: Dispatcher
vLLM integration
State: Operator validation
Proved now: A vLLM runtime plan, OpenAI-compatible connector, model/capability derivation, and focused tests exist.
Receipt needed: Name the image and revision, model, GPU and driver, arguments, systemd/Podman host, readiness, inference, and shutdown.
Evidence
- Source: vLLM registration, vLLM Rune, and shared OpenAI-compatible runtime
- Verification: Adapter tests
- Law: Dispatcher
SGLang integration
State: Operator validation
Proved now: An SGLang runtime plan, OpenAI-compatible connector, model derivation, and focused tests exist.
Receipt needed: Name the image and revision, model, GPU and driver, arguments, systemd/Podman host, readiness, inference, and shutdown.
Evidence
- Source: SGLang registration, SGLang Rune, and shared OpenAI-compatible runtime
- Verification: Adapter tests
- Law: Dispatcher
ExLlamaV3 through TabbyAPI
State: Operator validation
Proved now: The TabbyAPI-backed runtime, control plane, connector, Soulstone, registration, revision boundary, and contract tests exist.
Receipt needed: Name TabbyAPI and ExLlamaV3 revisions, NVIDIA GPU and driver, EXL3 model and quantization, cache, split, flags, load/inference/unload, and measured VRAM.
Evidence
- Source: ExLlamaV3 control plane
- Verification: ExLlamaV3 tests
- Law: Dispatcher
Declared conflict topology and systemd target switching
State: Available
Proved now: Declared conflict domains compile into an incompatibility graph and compatible Animator/Coven targets. Switching attests the loaded graph and current world, performs one bounded compound target request, waits for systemd settlement, and classifies success or exact restoration.
Boundary: Repository tests and a private user-manager receipt use inert services, not the operator's Quadlet/Podman/GPU host. Declared coexistence is not measured capacity admission.
Evidence
- Source: Conflict schema and runtime actuator
- Verification: Conflict tests and private-systemd receipt
- Law: Containers
Safe runtime transitions
State: Partial
Proved now: Admission closure, lease drain, serialized transition plans, compound target
actuation, exact-prior-world compensation, interrupted-work containment, and refusal on stale
topology are covered by focused protocol tests. Manual transition priority is constrained to the
canonical 0..100 doctrine range before trace publication or arbitration and at the HTTP query
boundary.
Boundary — Not yet: Dynamic shared-capacity admission, durable multi-process orchestration,
general repair, and a maintained real model/GPU transition receipt are absent. A failed soft
model-load has no trustworthy rollback and requires contained operator recovery; .contained and
unresolved .processing fence later work.
Evidence
- Source: Orchestrator manager
- Verification: Transition tests and Orchestrator API tests
- Law: Orchestrator
Resource-aware VRAM and topology scheduling
State: Designed
Proved now: Orchestrator law defines the scheduling seam; deterministic tests preserve the current simple eviction baseline.
Do not expect yet: Current policy counts conflicting neighbors; it does not model VRAM, footprints, load time, topology, bandwidth, LRU, refits, tiers, or transition peaks.
Evidence
- Source: Current eviction policy
- Verification: Policy tests
- Law: Orchestrator
Altar and observability
The Svelte 5 static client, generated /api/v1 types, validated semantic SSE, local schema assets,
and Litestar delivery exist. Focused tests prove contracts and components, not a
production-factory browser receipt. No XYFlow/Svelte Flow, Sigma, or Graphology dependency and no
Loom or Orb graph canvas or shared graph-projection supply is delivered; ADR 15's renderer
directions and admission gates are law, not implementation evidence.
The document language and interface copy are English. There is no message catalogue, explicit
locale resolver or selector, Principal-preference binding, translated accessibility surface, or
right-to-left receipt. Browser-native date/time formatting may reflect a device locale, but that
incidental variation is not delivered localization support.
The compiled Altar has one fixed LychD Dark palette, dark browser metadata, dark native-control
colour scheme, and no light/system selector, system-scheme following, palette configuration,
runtime theme loader, or supported theme extension. Semantic CSS custom properties establish a
future refactoring seam, but hard-coded dark surfaces remain in the main background, Mermaid, and
static artwork. There is no complete contrast matrix or bright/dim production-browser receipt;
ADR 15's bounded operator-palette contract is design law, not delivered configurability.
Bridge conversation and consent surface
State: Partial
Proved now: Bridge supports typed sessions, one-nonterminal-Run session admission, consent, inspection, semantic SSE, closed GenUI descriptors, durable request identity, authoritative snapshot recovery, lifecycle fencing, and bounded reconstruction against server-owned Run and Pattern identities. Exact retries reuse the canonical Run; distinct overlapping turns are refused. Its per-turn run strip is the first thin projection of one Invocation's Circle. Dispatcher grant ids rebind the Environment snapshot before inference and after consent re-entry.
Boundary — Not yet: There is no real-browser receipt, durable cross-process event/token delivery, general multi-approval, Attention, or notification channel. Text is the only command modality, and no focused Circle workspace composes Scroll, active Spell placement, Context/authority, capability, and evidence projections.
Evidence
- Source: Bridge controller
- Verification: Bridge tests
- Law: Frontend
Nexus transition board
State: Partial
Proved now: Nexus renders typed state and plans, submits explicit transitions, fences ambiguous request identities, follows bounded process-local tickets, and durably reserves the first target request before launch.
Boundary — Not yet: Only request admission is durable. Transition observations lack a durable owner, complete history, cross-process projection, restart recovery, and production-browser receipt. Durable admission prevents duplicate launch, but a lost ticket cannot prove the outcome or resume safely; retry refuses to relaunch it.
Evidence
- Source: Nexus controller
- Verification: Nexus tests
- Law: Frontend
Loom workflow instrument
State: Partial
Proved now: Loom browses exact immutable Pattern revisions, manifests, semantic station and permission outlines, checkpoint schemas, implementation revisions, source, active/default state, and retained revisions with stale-response-fenced client loading.
Boundary — Not yet: Loom is a view over the fixed registry, not a Spellweaver editor, mutation surface, independent Spell identity or catalogue, compatibility or teaching surface, drafting canvas, admitted graph-renderer dependency, inert unresolved-Spell projection, Suite executor, or production-browser receipt.
Evidence
- Source: Loom controller, Pattern registry contract, and Loom client
- Verification: Loom tests and client lifecycle tests
- Law: Workflow
Composition Portfolio
State: Designed
Proved now: The Portfolio publishes Native Reference Composition contracts and examples; the
boot catalogue contains only bridge_chat@1 and delegated_rite@1.
Do not expect yet: There is no Composition store or selector, Product catalogue or selector, Portfolio Pattern registration, Suite execution, application scheduling, or delivered domain/effect path for any Portfolio member or Product. Crucible is a designed Weaver choreography, not a registered Pattern, parallel Graph, dossier schema, or Altar surface.
Evidence
- Source: Workflow registry
- Verification: Workflow routing tests
- Topic: Composition Portfolio
- Law: Workflow
Orb instrument
State: Partial
Proved now: Orb renders one Run as ordered, paginated evidence with Pattern revision, capture durability, ledger boundaries, gaps, transition links, stable selection, bounded retry, and teardown-cancelled snapshot reads. Its delegated-job projection applies newest-job and per-job event limits at the store query boundary before rendering the public 32/64 suffixes.
Boundary — Not yet: There is no run list, live tail, graph field, durable Oculus read model, Sigma/Graphology adapter, cross-process completeness, health query, artifact custody, annotation, or multi-run view.
Evidence
- Source: Orb controller and Orb client
- Verification: Orb API tests and Orb client tests
- Law: Observability
Structured logging configuration
State: Available
Proved now: One tested builder configures human and JSON stdlib/Structlog output for CLI and Litestar while preserving stdout/stderr semantics, recovery-command fallback, and thread-stable repeated bootstrap without an unused logging queue.
Boundary: Shared configuration does not prove complete semantic audit coverage, trace storage, OpenTelemetry export, redaction, retention, resource correlation, or Oculus.
Evidence
- Source: Logging configuration
- Verification: Logging tests
- Law: Observability
Native Oculus
State: Designed
Proved now: Observability law defines LychD's canonical evidence meanings and a native read-model boundary; no native Oculus implementation is delivered.
Do not expect yet: There is no native ingestion, durable query/read model, retention path, or Oculus-backed Svelte service. Orb is a bounded Run projection, not Oculus.
Evidence
- Topic: Oculus
- Law: Observability
Phoenix
State: External
Proved now: LychD can generate an optional Phoenix service contribution and preserves an explicitly configured legacy service name.
External owner and boundary: Arize owns Phoenix. LychD
does not own its lifecycle or state, require it for Oculus, or prove application trace export. A
latest image is not a reproducible receipt.
Evidence
- Source: Phoenix configuration
- Verification: Phoenix generation tests
- Law: Observability
Authority and artifacts
Context privatization and Portal egress
State: Designed
Proved now: Context and Security law define privatization labels, source lineage, consumer-specific Privacy Cuts, independent verification, and a separate egress decision.
Do not expect yet: There is no label or lineage implementation, deterministic Censor, transformation-receipt chain, verified Privacy Cut, sanitized Context branch, pseudonym map, Egress Gate, transmission check, or deletion propagation.
Evidence
Local Sigil and scope authority
State: Partial
Proved now: Typed Sigils, scopes, guards, consent preauthorization, transactional use-budget consumption, policy synchronization, and digest-bound auto-grant revalidation are tested on the loopback bootstrap surface.
Boundary — Not yet: The fixed magus:* Sigil is not caller authentication. There is no object
authorization, delegation, revocation, tenant isolation, remote exposure, or general effect-time
reauthorization.
Evidence
- Source: Sigil identity, consent ledger, and policy synchronization
- Verification: Guard tests, policy-integrity tests, and PostgreSQL consent tests
- Law: Security
Local browser and bind boundary
State: Partial
Proved now: Generated ports and uncaged service policy bind IPv4 loopback; native serve
refuses non-loopback host, inherited-file-descriptor, and UNIX-domain-socket arguments and
environment overrides, then publishes one effective 127.0.0.1 or ::1 TCP listener. Launch,
Host, CORS, local schema assets, fixed root handlers, and
CSRF contracts are bounded and tested.
Boundary — Not yet: Requests still receive the bootstrap Sigil. No hostile-browser receipt, security-header contract, or remote principal exists; proxied, tunneled, non-loopback, and untrusted-browser use remain unsupported.
Evidence
- Source: Application composition, server policy, and fixed Altar routes
- Verification: Network policy tests, native launcher tests, HTTP boundary tests, and Altar route tests
- Law: Security
Scout web acquisition
State: Designed
Proved now: Web-acquisition law separates search, fetch, render, extraction, destination pinning, quarantine, authentication, and paid effects. The accepted design selects native static Fetch + Extract, a SearXNG Search Soulstone, and a later isolated Crawl4AI renderer candidate; Firecrawl remains deferred and paid web-acquisition Portals remain private-extension territory.
Do not expect yet: There is no Scout provider, browser service, endpoint, Agent tool, acquisition receipt, download quarantine, authenticated session, or Smith ingestion path. There is no SearXNG or Crawl4AI Rune/adapter, no Scout provider store or effect-scoped tool binding, and no renderer containment outside the shared Pod.
Evidence
- Topic: Scout
- Law: Web Acquisition
Vision admission
State: Partial
Proved now: Capability declarations distinguish the Vision family from image modality and
dispatch metadata preserves that distinction. A WARM v1 vision record still fails closed at
grant issue because no typed visual execution surface exists.
Boundary — Not yet: LychD does not upload, store, normalize, request, transport, or render image bytes through Bridge and an engine.
Evidence
- Source: Capability vocabulary
- Verification: Vision catalogue tests and grant-boundary tests
- Law: Vision
Audio admission
State: Partial
Proved now: Capabilities declare audio input/output modalities while speech services remain the
stt and tts families. Even when observed WARM, both v1 families fail closed at grant issue
because no typed transcription or synthesis call surface exists.
Boundary — Not yet: There is no audio-byte custody or transport, streaming socket, resonance buffer, working STT/TTS adapter, or Audio Coven.
Evidence
- Source: Capability vocabulary
- Verification: Audio catalogue tests and grant-boundary tests
- Law: Audio
Artifact reference contract
State: Partial
Proved now: Intent preserves an immutable artifact digest, classification, size, media type, and required modality through the Run ledger.
Boundary — Not yet: ArtifactRef is not byte custody. There is no upload/store adapter,
principal-bound retrieval, materializer, derivation provenance, retention/deletion, provider fetch
audit, or Reliquary backend.
Evidence
- Source: Artifact reference
- Verification: Artifact tests
- Law: Vision
Evolution and federation
Candidate Archive intake seam
State: Designed
Proved now: Memory law defines authoritative Archive records, lineage, lifecycle, derived representations, namespaces, and correction boundaries.
Do not expect yet: There is no CandidateArchivePort, intake adapter, runtime wiring,
PostgreSQL Archive adapter, semantic ingestion, embedding or retrieval, curation, promotion, RAG,
or training loop.
Evidence
- Law: Memory
Mirror identity
State: Designed
Proved now: Identity law defines a filtered, revisable binding rather than a second cognitive runtime.
Do not expect yet: There is no identity store, synthesis loop, hydration adapter, versioned Persona, calibration, or promoted persistent identity.
Evidence
Shadow simulation
State: Designed
Proved now: Simulation law defines branch expansion, scoring, pruning, authority, and verified collapse.
Do not expect yet: There is no runnable branch graph, MCTS engine, branch store, budgeted simulation, collapse implementation, or reaper.
Evidence
- Topic: Shadow
- Law: Simulation
Riddle evaluation
State: Designed
Proved now: Evaluation law defines adversarial evidence, capability comparison, and calibration.
Do not expect yet: There is no runnable harness, maintained suite, scorer contract, benchmark history, pass-at-k experiment, or routing update.
Evidence
- Topic: Riddle
- Law: Evaluation
Soulforge training
State: Designed
Proved now: Training law defines how consecrated examples may enter governed training.
Do not expect yet: There is no dataset harvest, training job, isolated trainer, checkpoint evaluation, model registration, rollback, or production promotion.
Evidence
Inert Creation promotion envelope
State: Designed
Proved now: Creation law defines an attributable request → candidate → verification → promotion-request → target-owner-effect chain.
Do not expect yet: There is no Creation contract or process-local state-machine implementation, workspace, filesystem or command executor, database recovery, safe Forge, autonomous repair, target-owner promotion effect, rollback execution, or self-extension runtime. There is likewise no instantiated distributed repository identity or maintainer roster, executable key-custody and rotation mechanism, governance-epoch ledger, quorum verifier, signed portable promotion envelope, independent attestation plane, canonical source on Radicle, Radicle node topology, or downstream-mirror cutover.
Evidence
Remote IAM
State: Designed
Proved now: IAM law assigns remote identity and authorization to Ward rather than the loopback Sigil.
Do not expect yet: There is no credential-backed principal, remote session, object authority, delegation, revocation, tenant isolation, or audit contract.
Evidence
A2A and Intercom
State: Designed
Proved now: A2A law defines sovereign asynchronous labor, bounded public-task envelopes, verification, replay, expiry and revocation boundaries, and durable inbox/outbox ownership.
Do not expect yet: There is no envelope, policy, or ledger implementation; peer/key custody, discovery, cryptographic verifier, transport, durable inbox/outbox, callback or artifact fetch, Run/Graph bridge, restart recovery, effect receipt, or interoperability profile.
Evidence
- Law: Agent-to-Agent
x402 payments
State: Designed
Proved now: Payment law assigns negotiation and settlement to Toll and future price discovery to dispatch.
Do not expect yet: There is no quote, reservation, authorization, signer, payment, settlement, reconciliation, budget enforcement, or safe HTTP 402 response.
Evidence
Legion federation
State: Designed
Proved now: Federation law separates cognitive Master authority from node-local physical authority and rejects shared databases and universal credentials.
Do not expect yet: There is no enrollment, expiring advertisement, reservation, fencing, artifact transfer, durable spool, cancellation, or settlement.
Evidence
VPN Tether
State: Designed
Proved now: VPN law defines Tether as private reachability over WireGuard without application authority, with exact peer and route intent and separate lifecycle ownership.
Do not expect yet: There is no Tether Domain contract, Rune or provider, generated service, UDP publication, interface or enrollment effect, peer/key custody, live route policy, health, reconciliation, revocation effect, or identity proof.
Evidence
Proxy Veil
State: Designed
Proved now: Proxy law assigns edge proxy and TLS composition to Veil.
Do not expect yet: There is no provider, certificate lifecycle, generated edge policy, Gateway Host manifest or Home/Remote realization, firewall projection, remote ingress hardening, or proof that a proxy substitutes for application authorization.
Evidence
Human ruling queue
This page does not own a backlog. These unresolved choices remain hard gates until their owning Covenant records a ruling:
- single-Vessel ownership, hung shutdown, durable process leases, and multi-process event custody;
- authenticated caller/object authority, effect-time reauthorization, and remote exposure;
- extension trust, package lifecycle, stable ownership splits, and external-provider containment;
- durable Creation, memory derivation, privacy, training eligibility, promotion, and rollback; and
- Linux platform floor, production-browser evidence, and recovery of ambiguous physical effects.
Operator receipt requirements
A receipt names the exact commit, configuration, host and security context, runtime and dependency revisions, hardware/model identity when relevant, commands, expected and observed results, bounded timings, useful work, cancellation, shutdown, recovery, redacted logs, artifact digests, date, operator, verdict, and uncovered boundary. A materially different engine, model, image, driver, hardware topology, or configuration needs its own receipt.
Update law
When behavior or evidence changes, update source, focused verification, the owning topic, and this one delivery record together; downgrade immediately when proof disappears. Do not copy canonical states into README, Prophecy, Lexicon, ADR indexes, or every Composition leaf.
Enter the Work
Perform Summoning to test one bounded local conjunction. Preserve the observations as a named receipt; hope does not promote a delivery state.