diff --git a/03-DESIGN/01-to-be/28-building-the-bus.md b/03-DESIGN/01-to-be/28-building-the-bus.md index 7c3c69c..3c3d607 100644 --- a/03-DESIGN/01-to-be/28-building-the-bus.md +++ b/03-DESIGN/01-to-be/28-building-the-bus.md @@ -252,10 +252,10 @@ pays for itself furthest away. - [x] 3.8 **the declaration model** of [design 29](29-what-a-module-declares.md): local names derived to subjects, the three namespaces, permissions computed from a declaration, and a manifest that contains no subject. Done in the controller's composer (permissions, streams, - consumers) and in the runtime's client (subjects derived from the credential, never named - by a module). What is **not** done is enforcing "a manifest contains no subject" as a - catalogue test — the rule holds by construction today because nothing reads a subject from - a manifest, and a rule held by construction is one a later field could break quietly. + consumers), in the runtime's client (subjects derived from the credential, never named by a + module), and as a catalogue test asserting all 72 manifests hold no subject — because the + rule held by construction, and a rule held by construction is one a later field breaks + quietly. - [x] 3.9 **seats declared by modules** — the manifest now carries `seats` (name, scope, accepts/emits/serves, retention) and `uses`, and registration refuses a `mesh-*` name, a duplicate declarer, an undeclared `uses` or claim, a seat with no protocol, a scope