Merge pull request 'Publish-safe: remove two disclosures, and record Nox as the answer to 006' (#3) from chore/publish-safe into main

This commit was merged in pull request #3.
This commit is contained in:
2026-08-23 21:41:12 +02:00
3 changed files with 38 additions and 5 deletions
@@ -176,8 +176,8 @@ init — without the recursion.
Worth noting what is *not* in this table: the dozens of `systemctl` call sites that Worth noting what is *not* in this table: the dozens of `systemctl` call sites that
configure the **host OS's own** units — NetworkManager, resolved, oomd, zram, docker.service, configure the **host OS's own** units — NetworkManager, resolved, oomd, zram, docker.service,
fail2ban, sshd, zfs, across `modules/asusd`, `g14-power`, `wireguard`, `sshd`, `zfs` and fail2ban, sshd, zfs, across the vendor-firmware and power modules, `wireguard`, `sshd`, `zfs`
others. Those are not HAL supervising itself; they are HAL configuring an Arch box. They and others. Those are not HAL supervising itself; they are HAL configuring an Arch box. They
are out of scope for every option above and do not go away under any of them. are out of scope for every option above and do not go away under any of them.
--- ---
+3 -3
View File
@@ -75,9 +75,9 @@ is the ceremony option 2 was rejected for.
trigger ([ADR 0025](0025-hq-is-the-source-of-the-constitution.md)): the moment something trigger ([ADR 0025](0025-hq-is-the-source-of-the-constitution.md)): the moment something
outside the mesh must be governed by the same rules, product-level content moves down a level outside the mesh must be governed by the same rules, product-level content moves down a level
and this repository becomes what its name already claims. and this repository becomes what its name already claims.
- A new repository was created rather than the old one transferred — the forge predates the - A new repository was created rather than the old one transferred, because the forge predates
transfer API. `jschoubben/hq` is left in place untouched; it is not the source of truth and the transfer API. The original was verified to contain nothing the new one lacks — every ref
nothing points at it. an ancestor, no tags, issues, pull requests, releases or wiki content — and then removed.
- The mesh's own documents now live one conceptual level below the repository they are in. A - The mesh's own documents now live one conceptual level below the repository they are in. A
reader arriving at `01-RESEARCH` should understand it as the mesh's research, not Novox's. reader arriving at `01-RESEARCH` should understand it as the mesh's research, not Novox's.
Nothing in the folder names says so, and that is the cost of not restructuring. Nothing in the folder names says so, and that is the cost of not restructuring.
@@ -55,3 +55,36 @@ checked it — including in the same commit that wrote the rule.
and this content is governed rather than incidental. and this content is governed rather than incidental.
- Public repository, private mesh: the sync direction must not become a path for mesh-specific - Public repository, private mesh: the sync direction must not become a path for mesh-specific
content to arrive **into** these documents. content to arrive **into** these documents.
## Proposed direction — Nox is the search
*Added 2026-08-23.* Rather than syncing these documents into the knowledge base, **Nox
([ADR 0027](../../02-DECISIONS/0027-the-product-is-novox-mesh.md)) works from within this
repository and holds its knowledge directly.** Retrieval becomes an agent reading the source,
not a copy living in a second store.
This is a better answer than the one the README originally promised, on three counts:
- **No sync, so no drift.** The failure mode of a derived copy — the enforced copy winning
while the reasoned one quietly stops being true — cannot occur when there is no copy.
- **It dissolves the original objection properly.** The argument against a separate repository
was that it adds a fourth knowledge *system*. An agent with read access adds no store at all.
- **It is always current**, including for uncommitted work in progress.
**But it changes the promise, and that is worth stating rather than glossing.** ADR 0019's
answer was that these documents would be returned *beside everything else* in a symptom search.
An agent that must be **asked** is reachable; it is not surfacing. The two differ in exactly
the case the operational memory is designed for: someone debugging an error who has no reason
to think HQ knows anything about it.
So the open question narrows to one thing:
> When a symptom is searched and the answer happens to live in a design document or a decision
> record here, does the searcher find it without already suspecting it exists?
If Nox is the only path, the answer is no, and the reasoning in ADR 0019 needs amending rather
than satisfying. If Nox also contributes what it knows to a symptom search — or the search
consults Nox — the answer is yes and the original promise holds.
That is a design question for Nox, not a defect in this repository, and it should be settled
before ADR 0019 is treated as answered.