Approve 0054-0056, apply them, and fix the two smaller findings

0003 is now superseded by 0056. Nothing is left proposed.

Applied:
- 06 corrected from ten contexts to seven plus the api, each row now stating
  why it passes the more-than-one-node test. work, knowledge and stream are
  named as mesh-hosted rather than dropped; `ai` folds into config; `record`
  is deferred explicitly rather than listed. Its frontmatter now cites 0055.
- how-we-build §4 amended per 0054, and the derived page republished by
  playbook 05.

The sync found the drift the playbook exists to catch: the published §4 and
the source did not say the same thing. The source said "four accidents, not
four boundaries"; the published page said "one intent expressed four times",
and only the published page carried the scope caveat. Same rule, two texts,
already diverging. Verified the republish by reading back -- the new rule is
present and the old section's body returns nothing -- rather than trusting the
success message.

The two smaller findings:
- 0051 separated the transport identity from the declaring authority. It said
  the token carries "an address" and "the identity to expect" without saying
  what the node dials. It dials the broker, so pinning only that would make the
  control plane's authority transitive and let a compromised broker forge
  declarations -- which, since the host applies whatever the link delivers, is
  the whole machine. The token now carries four things, and declarations are
  signed and verified per declaration. Cost recorded: rotating the signing
  identity is fleet-wide.
- 0026 no longer restates 0022's rule about generated views. 0022's own words
  are "prose does not restate status; one place, and two is one too many",
  which is what 0026 was doing to it.
This commit is contained in:
2026-08-27 02:21:34 +02:00
parent f49d177a31
commit e1f4c7d9e0
9 changed files with 98 additions and 42 deletions
@@ -47,9 +47,16 @@ beside `02-DECISIONS/`, holding different things.
**If a decision is worth recording, it is worth a record. If it is not worth a record, it is
not recorded.**
`02-DECISIONS` holds every decision. There is no ledger, no index file, and no central status
of any kind. The chronological view — decisions in the order they were taken — is *generated*
from record frontmatter, which is what the ledger was actually for.
`02-DECISIONS` holds every decision, and **there is no ledger** — no separate document in which
a decision is also summarised, ranked or tracked. The chronological view — decisions in the order
they were taken — is *generated* from record frontmatter, which is what the ledger was actually
for.
That generation is not this record's rule. It is
[ADR 0022](0022-status-lives-in-frontmatter.md), which already decides repository-wide that
status lives in frontmatter and every cross-cutting view is generated rather than written. This
record does not restate it — 0022's own words are *prose does not restate status; one place, and
two is one too many*, and an earlier version of this paragraph did exactly that.
Content that was only in the ledger was rehomed rather than dropped: