{
  "ok": true,
  "author": "Aziel Eliab",
  "identity": "Aziel Eliab",
  "author_id": "https://www.azieleliab.com/#aziel",
  "version": "2.0.0-rc1",
  "suite_calling_name": "Aziel Runtime",
  "suite_calling_slug": "aziel-runtime",
  "calling_name_alert": null,
  "calling_name_rotated": false,
  "door": "fraggate",
  "kernel": "https://github.com/AzielEliab/fraggate",
  "framing": "Separate software / sibling software under one FragGate door. Never separate FragGate engines. Clock is not Lock.",
  "sort_law": "plain A–Z → gate A–Z → lock A–Z (Clock ≠ Lock)",
  "updated_at": "2026-10-04",
  "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
  "git_sha_source": "deploy_var",
  "git_sha_tracks_deployed_tip": true,
  "deploy_lag": null,
  "deploy_lag_note": "Deployed tip. GIT_SHA was set when this Worker was deployed. That sha is the deploy stamp. It is not a claim that a newer git commit is already running.",
  "version_id": "8723b53f-0c0a-44d9-a0db-55dfc4ff276b",
  "version_id_source": "cf_version_metadata",
  "version_id_note": "version_id is env.CF_VERSION_METADATA.id, read at serve time. It is not a baked constant.",
  "count": 42,
  "live_count": 41,
  "local_only_count": 1,
  "stub_count": 0,
  "worker_only_count": 1,
  "suite_download": "https://godlock.uk/runtime/download",
  "suite_download_v1": "https://godlock.uk/runtime/v1/suite/download",
  "suite_download_note": "One-click suite pack JSON (REAL catalog + FoldLock tip + mesh cite). Worker wasm / WireGuard / OpenVPN SLOT. Counted GET /download. LIVE on Windows / Mac / Linux / Android / iPhone via browser + PWA + Worker UI (native_app_store false). Not . Humans use Softwares in the Worker UI on this VibeLock host (browser / PWA) — no download required. Optional suite pack JSON remains at /download.",
  "platforms": {
    "spec": "BAN-PLATFORMS-1.0",
    "all_live": true,
    "native_app_store": false,
    "slot_os": [],
    "worker_live": true,
    "calling_name_live": true,
    "calling_name": "Aziel Runtime",
    "calling_name_rotated": false,
    "survival": "/survival",
    "manifest": "/manifest.webmanifest",
    "verified_paths": [
      "/survival",
      "/runtime/openapi.json",
      "/manifest.webmanifest",
      "/download",
      "/runtime/v1/software",
      "/runtime/v1/update/manifest",
      "/platforms"
    ],
    "platforms": [
      {
        "id": "windows",
        "label": "Windows",
        "live": true,
        "browser": true,
        "pwa": true,
        "worker_fronts": true,
        "mcp_openapi": true,
        "softwares_download": true,
        "native_app_store": false,
        "survival": true,
        "calling_name": true,
        "cap7_shuffle_in_process": true,
        "cap7_public_worker_shuffle": "live",
        "dual_surface": {
          "agents": "mcp_openapi",
          "humans": "worker_ui_pwa_download"
        },
        "ua_note": "Edge / Chrome / Firefox",
        "doors": [
          "https://godlock.uk/runtime/survival",
          "https://godlock.uk/runtime/mcp",
          "https://godlock.uk/runtime/openapi.json",
          "https://godlock.uk/runtime/manifest.webmanifest"
        ],
        "note": "LIVE via browser + installable PWA + Worker fronts + Softwares /download + MCP/OpenAPI. Not a native store app. Same FragGate door. Cap-7 factory shuffle land is LIVE. Standard internet reaches AZ domains via hub HTTPS, not Cap-7 names."
      },
      {
        "id": "mac",
        "label": "Mac",
        "live": true,
        "browser": true,
        "pwa": true,
        "worker_fronts": true,
        "mcp_openapi": true,
        "softwares_download": true,
        "native_app_store": false,
        "survival": true,
        "calling_name": true,
        "cap7_shuffle_in_process": true,
        "cap7_public_worker_shuffle": "live",
        "dual_surface": {
          "agents": "mcp_openapi",
          "humans": "worker_ui_pwa_download"
        },
        "ua_note": "Safari / Chrome / Firefox",
        "doors": [
          "https://godlock.uk/runtime/survival",
          "https://godlock.uk/runtime/mcp",
          "https://godlock.uk/runtime/openapi.json",
          "https://godlock.uk/runtime/manifest.webmanifest"
        ],
        "note": "LIVE via browser + installable PWA + Worker fronts + Softwares /download + MCP/OpenAPI. Not a native store app. Same FragGate door. Cap-7 factory shuffle land is LIVE. Standard internet reaches AZ domains via hub HTTPS, not Cap-7 names."
      },
      {
        "id": "linux",
        "label": "Linux",
        "live": true,
        "browser": true,
        "pwa": true,
        "worker_fronts": true,
        "mcp_openapi": true,
        "softwares_download": true,
        "native_app_store": false,
        "survival": true,
        "calling_name": true,
        "cap7_shuffle_in_process": true,
        "cap7_public_worker_shuffle": "live",
        "dual_surface": {
          "agents": "mcp_openapi",
          "humans": "worker_ui_pwa_download"
        },
        "ua_note": "Firefox / Chrome / Chromium",
        "doors": [
          "https://godlock.uk/runtime/survival",
          "https://godlock.uk/runtime/mcp",
          "https://godlock.uk/runtime/openapi.json",
          "https://godlock.uk/runtime/manifest.webmanifest"
        ],
        "note": "LIVE via browser + installable PWA + Worker fronts + Softwares /download + MCP/OpenAPI. Not a native store app. Same FragGate door. Cap-7 factory shuffle land is LIVE. Standard internet reaches AZ domains via hub HTTPS, not Cap-7 names."
      },
      {
        "id": "android",
        "label": "Android",
        "live": true,
        "browser": true,
        "pwa": true,
        "worker_fronts": true,
        "mcp_openapi": true,
        "softwares_download": true,
        "native_app_store": false,
        "survival": true,
        "calling_name": true,
        "cap7_shuffle_in_process": true,
        "cap7_public_worker_shuffle": "live",
        "dual_surface": {
          "agents": "mcp_openapi",
          "humans": "worker_ui_pwa_download"
        },
        "ua_note": "Chrome / Firefox / installed PWA",
        "doors": [
          "https://godlock.uk/runtime/survival",
          "https://godlock.uk/runtime/mcp",
          "https://godlock.uk/runtime/openapi.json",
          "https://godlock.uk/runtime/manifest.webmanifest"
        ],
        "note": "LIVE via browser + installable PWA + Worker fronts + Softwares /download + MCP/OpenAPI. Not a native store app. Same FragGate door. Cap-7 factory shuffle land is LIVE. Standard internet reaches AZ domains via hub HTTPS, not Cap-7 names."
      },
      {
        "id": "ios",
        "label": "iPhone",
        "live": true,
        "browser": true,
        "pwa": true,
        "worker_fronts": true,
        "mcp_openapi": true,
        "softwares_download": true,
        "native_app_store": false,
        "survival": true,
        "calling_name": true,
        "cap7_shuffle_in_process": true,
        "cap7_public_worker_shuffle": "live",
        "dual_surface": {
          "agents": "mcp_openapi",
          "humans": "worker_ui_pwa_download"
        },
        "ua_note": "Safari / Add to Home Screen PWA",
        "doors": [
          "https://godlock.uk/runtime/survival",
          "https://godlock.uk/runtime/mcp",
          "https://godlock.uk/runtime/openapi.json",
          "https://godlock.uk/runtime/manifest.webmanifest"
        ],
        "note": "LIVE via browser + installable PWA + Worker fronts + Softwares /download + MCP/OpenAPI. Not a native store app. Same FragGate door. Cap-7 factory shuffle land is LIVE. Standard internet reaches AZ domains via hub HTTPS, not Cap-7 names."
      }
    ],
    "download_run": {
      "suite_pack": "/download",
      "update_manifest": "/runtime/v1/update/manifest",
      "update_check": "/runtime/v1/update/check?slug={slug}&version={installed}",
      "pwa": "/manifest.webmanifest"
    },
    "note": "Windows, Mac, Linux, Android, and iPhone are LIVE on the public Worker (browser / PWA / MCP). Humans use Softwares in the Worker UI on this VibeLock host (browser / PWA) — no download required. Agents use OpenAPI/MCP. Optional suite pack JSON remains at /download. Not five native store binaries. Do not mark any of these five as SLOT. Hubs pull /survival."
  },
  "isolation_software_count": 33,
  "tab_placement_slugs": [
    "azinterface",
    "decisiongate",
    "forgereceipts",
    "azcoherence",
    "zkattest",
    "mmconsensus",
    "toolbench",
    "azvpn",
    "whitestone"
  ],
  "count_note": "Softwares-tab count includes placements (azinterface / decisiongate / forgereceipts / azcoherence / zkattest / mmconsensus / toolbench / azvpn / whitestone). Isolation domain software_count is 33 (domains_are_doors:false). Do not equate the two. Ask Jeeves is suite help on the aziel-corpus card (FragGate op jeeves; software_tab false; named tool isPartOf Aziel Corpus). EmbryoLock is live-with-local-destructive-boundary (Vault/Custody with ARK); wipe/unlock stay FG-STUB on the public mesh. AZChat is LIVE+bound (mesh default off). AZVPN is the automatic public VPN concentrator placement (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; auto_use true). Whitestone is a live Worker-only placement (FragGate status none; Case Mode is a product feature). VeilLock hub card is local_only (matches FragGate registry status; no public door). Sister products such as trades-runtime are cite-only extras (live_backends false; version cite is the live sister /v1/health). FragGate remains THE single door. catalog_sets.equate is false: Softwares slugs are not the FragGate allowlist, not FragGate product_count, and not mesh software_nodes. Softwares has veillock and whitestone; the FragGate allowlist has memory and mesh instead. Whitestone is absent from software_nodes. Equal counts are not equal sets. Do not invent Softwares rows to close the split.",
  "catalog_sets": {
    "equate": false,
    "sets_equal": false,
    "intentional_split": true,
    "same_count_not_same_set": true,
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "softwares_count": 42,
    "fraggate_registry_count": 43,
    "fraggate_product_count": 43,
    "fraggate_allowlist_count": 42,
    "software_nodes_fanout_count": 41,
    "softwares_not_on_allowlist": [
      "veillock",
      "whitestone"
    ],
    "allowlist_not_on_softwares": [
      "memory",
      "mesh"
    ],
    "softwares_not_in_registry": [
      "whitestone"
    ],
    "registry_not_on_softwares": [
      "memory",
      "mesh"
    ],
    "softwares_not_in_software_nodes": [
      "whitestone"
    ],
    "software_nodes_not_on_softwares": [],
    "note": "Softwares slugs, the FragGate public allowlist (LIVE_OPS), FragGate product_count (registry entries), and mesh software_nodes are not the same set. Equal counts are not equal membership. Softwares includes veillock (local_only; no public FragGate door) and whitestone (worker_only; FragGate status none). The FragGate allowlist includes kernel entries memory and mesh, which are not Softwares cards. FragGate product_count counts registry entries (in-process catalog engines plus memory and mesh, including veillock as local_only) and excludes whitestone. mesh software_nodes fans out in-process catalog product Workers ({slug}-worker) only: whitestone is absent; memory and mesh are not software_nodes rows; veillock is in that fan-out and is not on the public allowlist. Do not invent Softwares rows. Do not drop whitestone or veillock to force one count. Policy keeps the split: memory and mesh stay fabric (not a Softwares-tab product); whitestone stays worker_only with no invented FragGate op; veillock stays local_only."
  },
  "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
  "primary_host_alias": "https://glama.ai/mcp/servers/@AzielEliab/aziel-runtime",
  "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
  "host": "https://godlock.uk/runtime/",
  "library_mirror": "https://www.azielcorpuslibrary.net/runtime",
  "entity_parent": "https://www.azieleliab.com/runtime",
  "software": [
    {
      "slug": "4dmap",
      "name": "4DMap",
      "bucket": "plain",
      "domain": "Research",
      "domain_id": "06",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "health",
        "skill",
        "pin",
        "span",
        "stack",
        "gap",
        "fork",
        "walk",
        "lens",
        "class",
        "cohort",
        "absence",
        "cap",
        "join",
        "list",
        "example",
        "card_new",
        "card_pin",
        "card_span",
        "card_join",
        "card_walk",
        "card_list",
        "verify_hash",
        "frame_status",
        "axis_describe",
        "walk_trace",
        "card_export",
        "card_import",
        "verify_chain",
        "neighbor_cite",
        "memory_cite",
        "memory_observe",
        "library_pin",
        "plot",
        "possibility",
        "pattern_recall",
        "lattice_tip",
        "poison_refuse",
        "news_status",
        "news_pin",
        "news_open",
        "news_ingest",
        "news_sources",
        "news_weather",
        "news_black_swan",
        "frame",
        "axis",
        "trace",
        "export",
        "import",
        "neighbor",
        "ingest_pin",
        "plot_pins",
        "score_hooks",
        "possibility_cite",
        "lattice_tips"
      ],
      "stub_ops": [
        "truth_score",
        "lumen_panel",
        "invent_mark",
        "backdate_class"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.3.0",
      "one_line": "Inspect the same event on time, change, graph, and place axes at once.",
      "description": "Use 4DMap to walk one event across time, change, graph, and place as recorded axes, including a library pin when the paper gives a date and a place. AZNews can store an item on its own, or pin that item here and open it from the map. An empty pin stays refused until a real item is stored. It exists so multi-axis inspection stays a recorded walk.",
      "worker_home": "https://4dmap-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://4dmap-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/4dmap",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=4dmap",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/4dmap",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "08de65653c51a5a6c8c0e8648f9af5e5013336cdfb92aea28fed5b4caf39003e",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "azclce",
      "name": "AZ-CLCE",
      "bucket": "plain",
      "domain": "Language",
      "domain_id": "04",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "score",
        "classify",
        "gate",
        "health",
        "skill",
        "doctor"
      ],
      "stub_ops": [],
      "door_label": "live FragGate door",
      "open_live_door": true,
      "version": "0.3.0",
      "one_line": "Score how consistently three written layers agree with each other.",
      "description": "Use AZ-CLCE to check whether requirement, design, and practice statements line up. It exists to flag inconsistency in text you already posted.",
      "worker_home": "https://azclce-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://azclce-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/az-clce",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azclce",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/azclce",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "f1854d7bd0396761f942b54b78f42c66d4c04e4956189de79371ed67b9ae2b69",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      },
      "peers": [
        {
          "slug": "azcoherence",
          "name": "AZCoherence",
          "role": "peer-reviewer",
          "kind": "software",
          "placement": "scoring-review",
          "domain": null,
          "domain_id": null,
          "worker_url": "https://azcoherence-download-tracker.vibelock.workers.dev/",
          "github": "https://github.com/AzielEliab/AZCoherence",
          "note": "Separate product. Second-pass triad coherence (AZC-0.1). Not a replacement for AZ-CLCE. Not AKM-TRIAD."
        }
      ],
      "fabric_neighbors": [],
      "hubs": [
        "https://azieleliab.com",
        "https://www.azielcorpuslibrary.net",
        "https://godlock.uk"
      ],
      "worker_url": "https://azclce-download-tracker.vibelock.workers.dev/",
      "cross_map": {
        "slug": "azclce",
        "name": "AZ-CLCE",
        "spec": null,
        "placement": "domain-software",
        "domain": "Language",
        "domain_id": "04",
        "domain_note": "Language isolation label. Not a door. FragGate is the single door.",
        "worker_url": "https://azclce-download-tracker.vibelock.workers.dev/",
        "github": "https://github.com/AzielEliab/az-clce",
        "hubs": [
          "https://azieleliab.com",
          "https://www.azielcorpuslibrary.net",
          "https://godlock.uk"
        ],
        "peers": [
          {
            "slug": "azcoherence",
            "name": "AZCoherence",
            "role": "peer-reviewer",
            "kind": "software",
            "placement": "scoring-review",
            "domain": null,
            "domain_id": null,
            "worker_url": "https://azcoherence-download-tracker.vibelock.workers.dev/",
            "github": "https://github.com/AzielEliab/AZCoherence",
            "note": "Separate product. Second-pass triad coherence (AZC-0.1). Not a replacement for AZ-CLCE. Not AKM-TRIAD."
          }
        ],
        "fabric_neighbors": [],
        "merged": false,
        "extra_door": false
      }
    },
    {
      "slug": "azos",
      "name": "AZ-OS",
      "bucket": "plain",
      "domain": "System",
      "domain_id": "09",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "status",
        "invite",
        "principles",
        "health",
        "skill",
        "doctor",
        "session_open",
        "session_status",
        "session_close",
        "session",
        "close",
        "mode_list",
        "boot_path",
        "internet_base",
        "guardian",
        "download_list",
        "download_check",
        "phone_path",
        "sim_lockout",
        "cellular",
        "ip_mask",
        "azcall",
        "veillock",
        "malware_sweep",
        "airgap",
        "human_check"
      ],
      "stub_ops": [
        "exec",
        "shell",
        "lattice",
        "place_call",
        "call",
        "sim_wipe",
        "esim_wipe",
        "wipe_sim"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.3.0",
      "one_line": "Read ethics status and open a prefab isolate session folder.",
      "description": "Use AZ-OS to read its principles and open a short isolate ethics session. It exists as a local ethics workspace.",
      "worker_home": "https://azos-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://azos-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/azos",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azos",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/azos",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "fe93fd4c3d6a656998ef22a964b55b277699458ff747387fa2f1e47144055eb4",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "azai",
      "name": "AZAI",
      "bucket": "plain",
      "domain": "AI",
      "domain_id": "05",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "guide",
        "learner_guide",
        "ask",
        "lamb-check",
        "lamb_check",
        "models",
        "health",
        "skill",
        "doctor",
        "engine_status",
        "conversation",
        "agent",
        "azclicker",
        "attach",
        "crawl",
        "human_check",
        "cap7_lookup",
        "score_gate",
        "corpus_note",
        "receipt_learn",
        "receipt_status"
      ],
      "stub_ops": [
        "blend",
        "complete",
        "chat",
        "captcha",
        "captcha_solve",
        "solve_captcha"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.3.1",
      "one_line": "Run a Lamb Lens check (Service → Clarity → Peace) or the adaptive AZAI Guide.",
      "description": "Use AZAI for a hosted Lamb ethics check or the adaptive Guide (Lamb Lens first). It exists as a local OpenAI-compatible stack plus a protocol mirror — prefer op=guide with q; skill and doctor stay diagnostics; chat/blend/complete stay refuse on the Worker.",
      "worker_home": "https://azai-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://azai-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/azai",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azai",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/azai",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "435766c8de739bff706cda75a4e496726ed43de60224241cd6d98ca640efcebd",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "azbot",
      "name": "AZBot",
      "bucket": "plain",
      "domain": "AI",
      "domain_id": "05",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "route",
        "example",
        "health",
        "skill",
        "doctor"
      ],
      "stub_ops": [],
      "door_label": "live FragGate door",
      "open_live_door": true,
      "version": "0.2.0",
      "one_line": "Route a request onto the matching catalog product and operation.",
      "description": "Use AZBot to point a question at the matching Aziel product. It exists as a skill router.",
      "worker_home": "https://azbot-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://azbot-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/azbot",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azbot",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/azbot",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "909872259998d5ee9e276158b86194f704d40796588e5cc52d5ca15a86909456",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "azbrowser",
      "name": "AZBrowser",
      "bucket": "plain",
      "domain": "Research",
      "domain_id": "06",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "ethical_search",
        "lamb_lens_search",
        "navigate",
        "airlock_ingest",
        "tab_open",
        "tab_list",
        "receipt_list",
        "verify",
        "receipt_verify",
        "sandbox_status",
        "sandbox_render",
        "health",
        "skill",
        "doctor",
        "airlock",
        "home",
        "vpn",
        "malware_sweep",
        "airgap",
        "jeeves_site",
        "human_check"
      ],
      "stub_ops": [
        "tor_exit",
        "tor",
        "onion",
        "phoenix_wipe",
        "wipe",
        "scorch",
        "chromium",
        "chromium_exec",
        "chrome",
        "exec",
        "playwright",
        "puppeteer",
        "proxy",
        "unrestricted_proxy",
        "socks",
        "keylog",
        "keylogger",
        "clipboard",
        "harvest",
        "spy",
        "surveillance",
        "wiretap",
        "intercept",
        "inject",
        "track",
        "captcha",
        "captcha_solve",
        "solve_captcha"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Browse and search with citations for ethical research.",
      "description": "Use AZBrowser for ethical research search and advisory page metadata. It exists so research stays cited.",
      "worker_home": "https://azbrowser-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://azbrowser-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/azbrowser",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azbrowser",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/azbrowser",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "f27b40c284a748de8c290742bf9aa3deda716893af8963d97707dca28dd65b48",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "azchat",
      "name": "AZChat",
      "bucket": "plain",
      "domain": "Comms",
      "domain_id": "07",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "health",
        "skill",
        "doctor",
        "handle_new",
        "handle_rotate",
        "room_open",
        "room_post",
        "room_pull",
        "bus_send",
        "bus_poll",
        "verify_receipt",
        "import_export",
        "channel_seal",
        "bridge_status",
        "malware_sweep",
        "airgap"
      ],
      "stub_ops": [
        "smtp",
        "smtp_send",
        "send",
        "mail",
        "deliver",
        "deanonymize",
        "harvest",
        "mesh_join",
        "mesh_enable",
        "vpn",
        "bridge_azmail",
        "bridge",
        "chromium",
        "bridge_whatsapp",
        "bridge_facebook",
        "bridge_gmail",
        "bridge_outlook",
        "bridge_yahoo"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Join a room from the all-rooms list, where a hosted room appears, and a private room requires a passphrase. The product mesh hop starts off.",
      "description": "Use AZChat to join from the all-rooms list, to see a room you host in that list, and to require a passphrase on a private room. The product mesh hop starts off. It exists for spendable-handle chat and an agent bus. Those room options are the AZChat product contract.",
      "worker_home": "https://azchat-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://azchat-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/azchat",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azchat",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/azchat",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "9b63fc0adcbb65318fbad7fd6aaf39b6f44edc5ff41696571457a5bd765ec5c5",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      },
      "mesh_default": "off",
      "product_mesh": "default_off",
      "suite_mesh_is_separate": true
    },
    {
      "slug": "azcoherence",
      "name": "AZCoherence",
      "bucket": "plain",
      "domain": null,
      "domain_id": null,
      "placement": "scoring-review",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "health",
        "skill",
        "doctor",
        "verify",
        "review_triad",
        "alternate_score",
        "coherence_check",
        "neutralize_hallucination"
      ],
      "stub_ops": [
        "invent_evidence",
        "invent",
        "fabricate",
        "truth_score",
        "truth_claim",
        "akm_calibrate",
        "memory_observe",
        "posterior_as_truth",
        "auto_pass",
        "blend_scores"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Review whether a primary score and an alternate hold together.",
      "description": "Use AZCoherence for a second look at a posted triad versus an alternate. It exists to review coherence.",
      "worker_home": "https://azcoherence-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://azcoherence-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/AZCoherence",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azcoherence",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/azcoherence",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "f04dfa4af332a1c04bd7319a8f48cee3e9adec3877d198ea703ee6187790cfc5",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      },
      "peers": [
        {
          "slug": "azclce",
          "name": "AZ-CLCE",
          "role": "peer-scorer",
          "kind": "software",
          "domain": "Language",
          "domain_id": "04",
          "worker_url": "https://azclce-download-tracker.vibelock.workers.dev/",
          "github": "https://github.com/AzielEliab/az-clce",
          "note": "Separate product. Detects R/D/P inconsistency. AZCoherence reviews primary vs alternate. Not a replacement."
        },
        {
          "slug": "azinterface",
          "name": "AZInterface",
          "role": "human-ui",
          "kind": "software",
          "placement": "human-ui",
          "domain": null,
          "domain_id": null,
          "worker_url": "https://azinterface-download-tracker.vibelock.workers.dev/",
          "github": "https://github.com/AzielEliab/azinterface",
          "note": "AZInterface is the human UI before FragGate. Separate software. Same door. Not merged."
        }
      ],
      "fabric_neighbors": [
        {
          "slug": "memory",
          "name": "AKM-TRIAD",
          "spec": "AKM-TRIAD-1.0",
          "role": "fabric-neighbor",
          "kind": "fabric",
          "domain": null,
          "domain_id": null,
          "note": "Not merged. Memory stays fabric, not Softwares. Posterior ≠ truth. AZCoherence is not AKM-TRIAD."
        }
      ],
      "hubs": [
        "https://azieleliab.com",
        "https://www.azielcorpuslibrary.net",
        "https://godlock.uk"
      ],
      "worker_url": "https://azcoherence-download-tracker.vibelock.workers.dev/",
      "cross_map": {
        "slug": "azcoherence",
        "name": "AZCoherence",
        "spec": "AZC-0.1",
        "placement": "scoring-review",
        "domain": null,
        "domain_id": null,
        "domain_note": "Leave domain null — same pattern as decisiongate/forgereceipts. Scoring-review is a placement, not a 34th isolation software. Domains are isolation labels, not doors. FragGate remains THE single door.",
        "worker_url": "https://azcoherence-download-tracker.vibelock.workers.dev/",
        "github": "https://github.com/AzielEliab/AZCoherence",
        "hubs": [
          "https://azieleliab.com",
          "https://www.azielcorpuslibrary.net",
          "https://godlock.uk"
        ],
        "peers": [
          {
            "slug": "azclce",
            "name": "AZ-CLCE",
            "role": "peer-scorer",
            "kind": "software",
            "domain": "Language",
            "domain_id": "04",
            "worker_url": "https://azclce-download-tracker.vibelock.workers.dev/",
            "github": "https://github.com/AzielEliab/az-clce",
            "note": "Separate product. Detects R/D/P inconsistency. AZCoherence reviews primary vs alternate. Not a replacement."
          },
          {
            "slug": "azinterface",
            "name": "AZInterface",
            "role": "human-ui",
            "kind": "software",
            "placement": "human-ui",
            "domain": null,
            "domain_id": null,
            "worker_url": "https://azinterface-download-tracker.vibelock.workers.dev/",
            "github": "https://github.com/AzielEliab/azinterface",
            "note": "AZInterface is the human UI before FragGate. Separate software. Same door. Not merged."
          }
        ],
        "fabric_neighbors": [
          {
            "slug": "memory",
            "name": "AKM-TRIAD",
            "spec": "AKM-TRIAD-1.0",
            "role": "fabric-neighbor",
            "kind": "fabric",
            "domain": null,
            "domain_id": null,
            "note": "Not merged. Memory stays fabric, not Softwares. Posterior ≠ truth. AZCoherence is not AKM-TRIAD."
          }
        ],
        "merged": false,
        "extra_door": false
      }
    },
    {
      "slug": "azhub",
      "name": "AZHub",
      "bucket": "plain",
      "domain": "AI",
      "domain_id": "05",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "health",
        "skill",
        "region_list",
        "place_module",
        "remove_module",
        "tether_declare",
        "tether_cut",
        "tether_list",
        "blank_key_status",
        "list_modules",
        "place"
      ],
      "stub_ops": [
        "scorch_remote",
        "auto_unlock",
        "ranking",
        "completeness_detect",
        "unlock",
        "complete",
        "completeness",
        "rank",
        "scorch"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Place and tether modules in a blank spatial container.",
      "description": "Use AZHub to put modules in regions and declare links. It exists as a neutral container so placement stays placement.",
      "worker_home": "https://azhub-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://azhub-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/azhub",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azhub",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/azhub",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "dc8848353c0db397b9b0503446ad8dcb14212162776b24278071559bd2e83d81",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "aziel-corpus",
      "name": "Aziel Digital Library",
      "bucket": "plain",
      "domain": "Research",
      "domain_id": "06",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "search",
        "example",
        "skill",
        "health",
        "doctor",
        "review",
        "score",
        "verify-backfill",
        "verify-geo",
        "document-chain",
        "import_export",
        "jeeves",
        "media-run",
        "tip-pack"
      ],
      "stub_ops": [],
      "door_label": "live FragGate door",
      "open_live_door": true,
      "version": "2.6.2",
      "one_line": "Search the public library with Ask Jeeves suite help and download azcorpus + azlibrary designs.",
      "description": "Use the Aziel Digital Library to search the public MASTER and to ask Ask Jeeves on the corpus jeeves operation. It exists as a self-contained public library with that suite help assistant on this card.",
      "worker_home": "https://www.azielcorpuslibrary.net/",
      "worker_home_note": null,
      "download_url": "https://www.azielcorpuslibrary.net/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/aziel-corpus",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=aziel-corpus",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/aziel-corpus",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "e122bae90a8426451861c11e39829f9ed000b0d0793a7e9260e6ee68c93c4ab8",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      },
      "website_designs": [
        "azcorpus",
        "azlibrary"
      ],
      "website_designs_note": "azcorpus + azlibrary are mesh-resident website designs on this library hub. Downloadable to nodes. Not extra Softwares. azlibrary upload is API token only (never embed the secret). Download is open.",
      "website_designs_cards": [
        {
          "id": "azcorpus",
          "name": "azcorpus",
          "kind": "website_design",
          "mesh_resident": true,
          "downloadable_to_nodes": true,
          "software_tab": false,
          "fraggate_slug": false,
          "fifth_product": false,
          "hub_id": "library",
          "hub": "https://www.azielcorpuslibrary.net/",
          "download_open": true,
          "download_url": "https://www.azielcorpuslibrary.net/download",
          "github": "https://github.com/AzielEliab/aziel-corpus",
          "upload": false,
          "dual_surface": {
            "mcp": true,
            "openapi": true,
            "catalog": "https://godlock.uk/runtime/v1/software",
            "skill": "https://godlock.uk/runtime/v1/skill"
          },
          "note": "Mesh-resident website design downloadable to nodes. Not a Softwares-tab product. Not a FragGate slug.",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab"
        },
        {
          "id": "azlibrary",
          "name": "azlibrary",
          "kind": "website_design",
          "mesh_resident": true,
          "downloadable_to_nodes": true,
          "software_tab": false,
          "fraggate_slug": false,
          "fifth_product": false,
          "hub_id": "library",
          "hub": "https://www.azielcorpuslibrary.net/",
          "download_open": true,
          "download_url": "https://www.azielcorpuslibrary.net/download",
          "github": "https://github.com/AzielEliab/aziel-corpus",
          "upload": {
            "method": "api_token_only",
            "never_embed_secret": true,
            "token_in": "env / keychain / Authorization Bearer at call time",
            "not_in": [
              "catalog",
              "skill",
              "mcp_tool_schema",
              "openapi_example",
              "cite",
              "llms"
            ],
            "note": "azlibrary upload accepts an operator API token only. Catalog and skill name the rule. They never embed the secret."
          },
          "dual_surface": {
            "mcp": true,
            "openapi": true,
            "catalog": "https://godlock.uk/runtime/v1/software",
            "skill": "https://godlock.uk/runtime/v1/skill"
          },
          "note": "Mesh-resident website design downloadable to nodes. Upload is API token only. Never embed the secret. Not a Softwares-tab product. Not a FragGate slug.",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab"
        }
      ],
      "suite_help": {
        "name": "Ask Jeeves",
        "slug": "jeeves",
        "software_tab": false,
        "kind": "suite_help_assistant",
        "parent_slug": "aziel-corpus",
        "fraggate_slug": "aziel-corpus",
        "fraggate_op": "jeeves",
        "interface_call": "jeeves_help",
        "named_tool": true,
        "isolation_software": false
      }
    },
    {
      "slug": "azieltether",
      "name": "AzielTether",
      "bucket": "plain",
      "domain": "Network",
      "domain_id": "08",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "verify",
        "tip",
        "dual-chain",
        "reconcile",
        "pulse",
        "peer-preview",
        "health",
        "skill",
        "doctor"
      ],
      "stub_ops": [
        "mesh-join",
        "vpn",
        "arm"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Keep downloaded Aziel software in sync when the central Worker is up or down.",
      "description": "Use AzielTether so downloaded packages prefer the central Worker, peer-sync when it is down, and reconcile on restore. It exists so copies survive outages.",
      "worker_home": "https://azieltether-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://azieltether-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/azieltether",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azieltether",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/azieltether",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "adb57573ee23e7c97567fc05f916f1fd65f2265128bd9ec3d1dca08e47c2d791",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "azinterface",
      "name": "AZInterface",
      "bucket": "plain",
      "domain": null,
      "domain_id": null,
      "placement": "human-ui",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "health",
        "skill",
        "genesis_status",
        "site_state_get",
        "site_state_set",
        "integrity_check",
        "witness_list",
        "page_cycle_status",
        "mesh_radios",
        "genesis_boot",
        "hold"
      ],
      "stub_ops": [
        "scorch_remote",
        "auto_unlock",
        "ranking",
        "completeness_detect",
        "unlock",
        "complete",
        "completeness",
        "rank",
        "scorch",
        "skip_cycle",
        "invent_cycle"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Open the Softwares suite shell and step pre-locked page cycles.",
      "description": "Use AZInterface as the suite shell that opens Softwares that can run on this computer, and to read and step site state through OFF, integrity, ON, FULL SHUTDOWN, and MEMORIAL. It exists so the desk and those page cycles stay in one custodial shell.",
      "worker_home": "https://azinterface-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://azinterface-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/azinterface",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azinterface",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/azinterface",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "7418c2bbf3c8fe4921f05f0e9f1aed2d2486f983d8feba985fe462018794972c",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "azmail",
      "name": "AZMail",
      "bucket": "plain",
      "domain": "Comms",
      "domain_id": "07",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "airlock_classify",
        "scrub",
        "trust_score",
        "mesh_post",
        "mesh_poll",
        "mesh_listen",
        "mesh_enable",
        "mesh_disable",
        "keyword_alert_set",
        "keyword_alert_list",
        "keyword_alert_check",
        "mailbox_open",
        "notice_post",
        "mail_post",
        "mail_send_base",
        "inbox_pull",
        "ack",
        "verify_receipt",
        "import_export",
        "transport_status",
        "health",
        "skill",
        "doctor",
        "classify",
        "mailbox",
        "notice",
        "inbox",
        "malware_sweep",
        "airgap"
      ],
      "stub_ops": [
        "smtp",
        "smtp_send",
        "send",
        "mail",
        "deliver",
        "imap",
        "pop3",
        "mx",
        "identify",
        "deanonymize",
        "unmask",
        "whois",
        "harvest",
        "credential_capture",
        "login"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Classify mail text and keep a local mailbox sealed to the user key, including links and files. Scan is LIVE-when-scanner-present. The airgap is present. Ordinary SMTP is not end-to-end.",
      "description": "Use AZMail for an advisory airlock and a local mailbox encrypted to the user key. It exists so untrusted mail is scanned and sealed before it reaches the user. Body, links, videos, docs, images, zips, and other files cross an airgap only after a scan. The scan is LIVE-when-scanner-present (ClamAV). An absent scanner refuses AZM-SCAN-ABSENT and returns no clean verdict. Attachments stay inert. AZMail-to-AZMail seals those parts end-to-end to the user key. Mail to @gmail, @live, @yahoo, and other SMTP domains is a normal MIME message over opportunistic TLS and is not end-to-end. Public smtp_send stays refused. It is not a public MTA. Field 1.0 is false. A Proton-clone claim is false. The anonymous ring still starts off.",
      "worker_home": "https://azmail-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://azmail-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/azmail",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azmail",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/azmail",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "06a6cba66c12090415cec91a06890de0b32edfa86e5631bcd2a78d0f9b5d27ec",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "aznet",
      "name": "AZNet",
      "bucket": "plain",
      "domain": "Network",
      "domain_id": "08",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "health",
        "pair_status",
        "garden_list",
        "stamp",
        "verify_hash",
        "memorial_list",
        "memorial_append",
        "receipt_verify",
        "name_claim",
        "name_read",
        "name_resolve",
        "slot_read",
        "witness",
        "witness_read",
        "skill",
        "doctor",
        "pair"
      ],
      "stub_ops": [
        "payload_host",
        "serve_content_for_peer",
        "analytics",
        "ranking",
        "repair_integrity_bypass",
        "interface",
        "lumen",
        "hub",
        "interface_hook",
        "lumen_hook",
        "hub_hook",
        "d2d_lan",
        "lan",
        "d2d-lan",
        "d2d_wifi",
        "wifi",
        "d2d-wifi",
        "d2d_bluetooth",
        "bluetooth",
        "d2d-bluetooth",
        "d2d_rf",
        "rf",
        "d2d-rf",
        "d2d_photon",
        "photon",
        "d2d-photon",
        "d2d_discover",
        "d2d-discover",
        "discover",
        "discovery",
        "d2d_tunnel",
        "d2d-tunnel",
        "d2d_multi_hop",
        "d2d-multi-hop",
        "multi_hop",
        "multi-hop",
        "multihop",
        "d2d_packet",
        "alt_internet",
        "packet_forward",
        "mesh_discover",
        "peer_advertise",
        "peer_list",
        "peer_session_open",
        "peer_session_status",
        "peer_session_close",
        "peer_send",
        "peer_recv",
        "outbox_enqueue",
        "outbox_cut",
        "store_forward",
        "path_probe",
        "bootstrap_list",
        "shelf_cite",
        "tip_pull",
        "origin_status"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Check hash continuity on the Cap-7 and .aziel name plane. Track 2 packet reachability stays NOT-READY (STANDS-until-demonstrated) in failover order LAN, Wi-Fi, Bluetooth, RF, photon light flashes.",
      "description": "Use AZNet to stamp and check hash refs in a custodian garden on the name plane. It exists so integrity can be checked on a side-net while Cap-7 and MirageGrid stay name and land-region metadata (not an ICANN registrar, not a public egress IP, and not AZVPN). Track 2 device-to-device carriers fail over LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Local LAN discovery is LIVE-when-armed and the peer tunnel is LIVE-when-session on the node. Local store-forward is LIVE-when-three-local-nodes / fixture. The public door stays FG-STUB. RF and photon light flashes stay refused without hardware. WARN-5 stays open. The packet path stays short of a live alternative internet.",
      "worker_home": "https://aznet-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://aznet-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/aznet",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=aznet",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/aznet",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "d089fb7636b27186ee5f3ec2468cc20d74ca5e5af65e77ebaa3492788b1751cf",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "azvpn",
      "name": "AZVPN",
      "bucket": "plain",
      "domain": null,
      "domain_id": null,
      "placement": "tunnel-concentrator",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "health",
        "skill",
        "doctor",
        "limitation",
        "describe",
        "open",
        "status",
        "list",
        "close",
        "send",
        "recv",
        "pull",
        "peers",
        "attach"
      ],
      "stub_ops": [
        "wireguard",
        "wg",
        "openvpn",
        "ovpn",
        "l3_exit",
        "exit_pool",
        "udp_listen",
        "kernel_vpn",
        "tun",
        "tap",
        "socks",
        "tor",
        "origin_hiding"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Open an HTTPS or WebSocket VPN session on the public concentrator.",
      "description": "Use AZVPN as the automatic public VPN concentrator for HTTPS and WebSocket tunnels. It exists to concentrate those sessions in-runtime. Track 2 device-to-device reachability stays a separate NOT-READY plane.",
      "worker_home": null,
      "worker_home_note": "No separate product Worker. The in-repo door is FragGate on this runtime. Do not invent a download-tracker URL.",
      "in_repo_home": "https://godlock.uk/runtime/p/azvpn",
      "download_url": null,
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/aziel-runtime",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azvpn",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/azvpn",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "2d3d27cf49df95d5a041a55d4fd75d20c65ed167a5c170ef6f363ec15599b776",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "plain_status": "VPN on at boot",
      "opt_out": false,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "forgereceipts",
      "name": "ForgeReceipts",
      "bucket": "plain",
      "domain": null,
      "domain_id": null,
      "placement": "fabric-product",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "receipt",
        "verify",
        "import_export",
        "doctor",
        "health",
        "skill"
      ],
      "stub_ops": [
        "court",
        "legal_advice",
        "odyssey",
        "file_store"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.3.0",
      "one_line": "Mint and hash-check client-held receipts so retries of one request stay linked.",
      "description": "Use ForgeReceipts to package local receipts and check their hashes. It exists so request_id, attempt_n, parent_receipt_id, correlation_id, and outcome are hashed into the receipt. ledger_tip.prev is call-order only (prev_is_retry_parent false).",
      "worker_home": "https://forgereceipts-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://forgereceipts-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/forgereceipts",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=forgereceipts",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/forgereceipts",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "c72efccfedd1411bef4ee8637f409c31580aaae46515ca64770648d4d01b99ed",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "glossafilter",
      "name": "Glossa Filter",
      "bucket": "plain",
      "domain": "Language",
      "domain_id": "04",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "render",
        "peers",
        "health",
        "skill",
        "doctor"
      ],
      "stub_ops": [],
      "door_label": "live FragGate door",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Render one intent across the bundled peer phrasings.",
      "description": "Use Glossa Filter when you need the same intent spoken in several peer styles. It exists for deterministic mediation.",
      "worker_home": "https://glossafilter-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://glossafilter-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/glossafilter",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=glossafilter",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/glossafilter",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "4d876f57934277eb56119a8041f2787fee45121b87eeb9c1f054b1d05b8dd3e3",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "miragegrid",
      "name": "MirageGrid",
      "bucket": "plain",
      "domain": "Network",
      "domain_id": "08",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "assign",
        "verify-receipt",
        "nodes",
        "bridge",
        "shuffle",
        "health",
        "skill",
        "doctor",
        "geo-target",
        "session-stick",
        "egress-rotate"
      ],
      "stub_ops": [
        "vpn-hop",
        "hop",
        "tunnel",
        "mesh"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.3.0",
      "one_line": "Assign a short-lived session node and cite Cap-7 mesh-name metadata from a factory that is not a public ICANN registrar. Cap-7 geo, sticky session, and land rotation are LIVE on the Cap-7 plane, not a public egress IP, not a residential IP, and not AZVPN.",
      "description": "Use MirageGrid to assign a short-lived session node and cite Cap-7 mesh-name metadata. The Cap-7 factory is not a public ICANN registrar. It exists for Cap-7 control-plane assignment. geo-target, session-stick, and egress-rotate are LIVE on the Cap-7 plane (region label, sticky mesh node and factory land, land rotate among 7 sites). They are not a public egress IP, not a residential IP, not a Cloudflare geo-exit pool, not a sticky public IP, not packet forwarding, not ICANN DNS, and not AZVPN. The public MirageGrid Worker Cap-7 control plane is LIVE (https://miragegrid.vibelock.workers.dev/v1/egress and https://miragegrid.vibelock.workers.dev/v1/planned). vpn-hop, hop, tunnel, and mesh stay stub. AZVPN remains the suite VPN. Track 2 carriers (LAN → Wi-Fi → Bluetooth → RF → Photon light flashes) stay NOT-READY and FG-STUB on this public door. Local LAN discovery is a separate node path.",
      "worker_home": "https://miragegrid-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://miragegrid-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/miragegrid",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=miragegrid",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/miragegrid",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "cea1854f20a807360d68c3b223343088abe09941ae77e406fd45ee4fe1d1126c",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "mmconsensus",
      "name": "MMConsensus",
      "bucket": "plain",
      "domain": null,
      "domain_id": null,
      "placement": "consensus-review",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "health",
        "skill",
        "doctor",
        "tally",
        "agree",
        "limitation"
      ],
      "stub_ops": [
        "live_model_call",
        "openai",
        "anthropic",
        "grok",
        "blend_models",
        "remote_infer",
        "truth_score",
        "court"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Tally consensus from opinions you already posted.",
      "description": "Use MMConsensus to majority-count or compare posted opinions. It exists to structure agreement you already have.",
      "worker_home": null,
      "worker_home_note": "No separate product Worker. The in-repo door is FragGate on this runtime. Do not invent a download-tracker URL.",
      "in_repo_home": "https://godlock.uk/runtime/p/mmconsensus",
      "download_url": null,
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/aziel-runtime",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=mmconsensus",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/mmconsensus",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "9624f144b1eacfc11cf86fe45ed83acb6f65fa324629668510c55f1fcabe6fe7",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "postking",
      "name": "Post-King Chess",
      "bucket": "plain",
      "domain": "Simulation",
      "domain_id": "10",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "new",
        "move",
        "status",
        "health",
        "skill",
        "doctor"
      ],
      "stub_ops": [],
      "door_label": "live FragGate door",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Play continuity chess where the aim is to remain.",
      "description": "Use Post-King Chess for a game where the human is king-bound and the AI has a Node. It exists to practice remaining.",
      "worker_home": "https://postking-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://postking-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/postking-chess",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=postking",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/postking",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "d25f9e81813816349e5e1c2064227ae193b9e3480cbea128a359a929a8232307",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "staticclock",
      "name": "StaticClock",
      "bucket": "plain",
      "domain": "Core Time",
      "domain_id": "11",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "advise",
        "advisory",
        "anchors",
        "click",
        "verify",
        "timeslate",
        "import_export",
        "doctor",
        "health",
        "skill"
      ],
      "stub_ops": [
        "rollback",
        "remote_shell",
        "scheduler"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.2.0",
      "one_line": "Record a forward-only gear-click timeline and read companion advice.",
      "description": "Use StaticClock to click a client-held chain forward and read advisory fields. It exists as a plain clock of actions.",
      "worker_home": "https://staticclock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://staticclock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/staticclock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=staticclock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/staticclock",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "7d6da0f2ef3fdbeedc2e96f5676a58847a8cd09dc94053009814dfa4fd282fb3",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "ark",
      "name": "The ARK",
      "bucket": "plain",
      "domain": "Vault/Custody",
      "domain_id": "01",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "sweep",
        "levels",
        "health",
        "skill",
        "doctor"
      ],
      "stub_ops": [
        "scorch",
        "wipe",
        "unlock",
        "encrypt"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Keep a local deniable vault; one phrase opens one vault.",
      "description": "Use The ARK as a local deniable vault you download and run on your device. It exists so one phrase opens one vault on that machine.",
      "worker_home": "https://ark-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://ark-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/ark",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=ark",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/ark",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "69d29bd079754df6450b8882b6f86c445ac7f1f490e2c150ff4716d00bf6d3b6",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "toolbench",
      "name": "ToolBench",
      "bucket": "plain",
      "domain": null,
      "domain_id": null,
      "placement": "tool-playground",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "health",
        "skill",
        "doctor",
        "suite",
        "run_case",
        "limitation"
      ],
      "stub_ops": [
        "invent_completeness",
        "live_remote_harness",
        "invent_pass",
        "third_party_lab"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Run synthetic door cases to see how FragGate classifies them.",
      "description": "Use ToolBench to play closed-path and happy-path cases against the door table. It exists as a self-test playground.",
      "worker_home": null,
      "worker_home_note": "No separate product Worker. The in-repo door is FragGate on this runtime. Do not invent a download-tracker URL.",
      "in_repo_home": "https://godlock.uk/runtime/p/toolbench",
      "download_url": null,
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/aziel-runtime",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=toolbench",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/toolbench",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "888385a251997a21f07368d71eff0bb56ed5f68871a6f84900ab62f28c8da33c",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "whitestone",
      "name": "Whitestone",
      "bucket": "plain",
      "domain": null,
      "domain_id": null,
      "placement": "pro-se-advisor",
      "status": "live",
      "fraggate_status": "none",
      "public_door": false,
      "public_door_ops": [],
      "stub_ops": [],
      "door_label": "worker only — FragGate status none",
      "open_live_door": false,
      "version": "1.6.0",
      "one_line": "Advise on short Criminal, Civil, and Divorce questions with historical as-of and Case Mode (suppression axes, TrajectoryLock-lite, export, confidence labeled up to 75%). Session-only web app plus optional zip. https://whitestone.vibelock.workers.dev/",
      "description": "Whitestone is worker-only and has no public door. Use Whitestone for short Criminal, Civil, or Divorce questions in a web app, including historical as-of evaluation and Case Mode axes (truth_upheld, narrative / systemic / personal-professional suppression, honesty). It exists as an ephemeral pro se advisor: TrajectoryLock-lite is labeled heuristic, Case Mode may export a hash-chain card, and confidence is labeled up to 75%. Session-only memory wipes when you close. Optional counted zip is on the download tracker; the web app stays on the Whitestone Worker. https://whitestone.vibelock.workers.dev/ · https://whitestone-download-tracker.vibelock.workers.dev/download",
      "worker_home": "https://whitestone-download-tracker.vibelock.workers.dev/",
      "download_url": "https://whitestone-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "web_app": "https://whitestone.vibelock.workers.dev/",
      "github": "https://github.com/AzielEliab/Whitestone",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": null,
        "fraggate_list": null,
        "fraggate_describe": null,
        "fraggate_call": null,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": null,
        "fraggate_call_executes": false,
        "open_live_door": false,
        "pipeline": "Live Worker only. FragGate status is none. Do not invent fraggate_call ops."
      },
      "engine_digest": null,
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "door": "none",
      "kind": "software",
      "engine": false,
      "fraggate_engine": false,
      "worker_only": true,
      "note": "Live Worker. FragGate status is none. Hub tab reads worker_home / download_url / web_app. Case Mode is a product feature. Session-only. Author: Aziel Eliab only. Do not invent fraggate_call ops.",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      },
      "git_sha_tracks_deployed_tip": true
    },
    {
      "slug": "zsolver",
      "name": "ZionPattern Solver",
      "bucket": "plain",
      "domain": "Language",
      "domain_id": "04",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "patterns",
        "score",
        "session",
        "health",
        "skill",
        "doctor"
      ],
      "stub_ops": [],
      "door_label": "live FragGate door",
      "open_live_door": true,
      "version": "0.2.0",
      "one_line": "Score answers against nine ontology nodes, with scores labeled up to 75%.",
      "description": "Use ZionPattern Solver to work through the Zioncheck seed nodes. It exists as an assistive scorer with scores labeled up to 75%.",
      "worker_home": "https://zsolver-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://zsolver-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/zion-pattern-solver",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=zsolver",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/zsolver",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "8667a3d95f6063b77cb0ab0ff629192b6c5036d95762adb20f3c90f4b73a977f",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "zkattest",
      "name": "ZKAttest",
      "bucket": "plain",
      "domain": null,
      "domain_id": null,
      "placement": "receipt-attest",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "health",
        "skill",
        "doctor",
        "commit",
        "attest",
        "open",
        "verify",
        "limitation"
      ],
      "stub_ops": [
        "groth16",
        "snark",
        "stark",
        "plonk",
        "bulletproofs",
        "pairing",
        "trusted_setup",
        "prove",
        "full_zk",
        "zk_snark",
        "reveal_witness"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Attest a statement with a hash commitment that keeps the witness private.",
      "description": "Use ZKAttest to bind a public statement to a SHA-256 commitment. It exists so the witness stays with the caller.",
      "worker_home": null,
      "worker_home_note": "No separate product Worker. The in-repo door is FragGate on this runtime. Do not invent a download-tracker URL.",
      "in_repo_home": "https://godlock.uk/runtime/p/zkattest",
      "download_url": null,
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/aziel-runtime",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=zkattest",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/zkattest",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "bb3831ed980be81dce15fda1dbb471a7458c91feb907a410a86173003df1c84a",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "decisiongate",
      "name": "DecisionGATE",
      "bucket": "gate",
      "domain": null,
      "domain_id": null,
      "placement": "fabric-product",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "check",
        "evaluate",
        "gates",
        "verify",
        "doctor",
        "health",
        "skill"
      ],
      "stub_ops": [
        "wrap",
        "execute",
        "remote",
        "truth_score",
        "court"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Run a proposal through five sequential gates and get PASS, REVISE, or BLOCK.",
      "description": "Use DecisionGATE to check Definition, Evidence, Impact, Integrity, and Responsibility in order. It exists as a pre-execution filter.",
      "worker_home": "https://decisiongate-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://decisiongate-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/decisiongate",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=decisiongate",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/decisiongate",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "4e86778de3d0d7795611a7b3d29d7c734fa808a03e1e22e93bc3b694910bf172",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "chronolock",
      "name": "ChronoLock",
      "bucket": "lock",
      "domain": "Evidence",
      "domain_id": "03",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "advisory",
        "advise",
        "anchors",
        "window",
        "doctor",
        "health",
        "skill"
      ],
      "stub_ops": [
        "scheduler",
        "targeting",
        "virality",
        "cron"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Check whether a place sits in the 08:30–10:30 local advisory window.",
      "description": "Use ChronoLock for timezone-aware linguistic alignment around the Temporal Neutral Window. It exists as advisory timing.",
      "worker_home": "https://chronolock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://chronolock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/chronolock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=chronolock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/chronolock",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "672a014671a63660b0538ef6d08485ebf1141489aa68bf6173995bc34fd4d4ab",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "codelock",
      "name": "CodeLock",
      "bucket": "lock",
      "domain": "Language",
      "domain_id": "04",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "render",
        "gate-status",
        "health",
        "skill",
        "doctor"
      ],
      "stub_ops": [],
      "door_label": "live FragGate door",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "View source as Canonical or Rosetta HTML while keeping the same meaning.",
      "description": "Use CodeLock when you want a different view of source. It exists to change perception.",
      "worker_home": "https://codelock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://codelock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/codelock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=codelock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/codelock",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "cdeacc8ed400760227248c5946d07528e2dfaf4542a40f20cb9961833d199c0b",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "embryolock",
      "name": "EmbryoLock",
      "bucket": "lock",
      "domain": "Vault/Custody",
      "domain_id": "01",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "health",
        "skill",
        "doctor",
        "verify_hash",
        "verify-hash",
        "policy",
        "limitation",
        "cite",
        "limitations"
      ],
      "stub_ops": [
        "wipe",
        "scorch",
        "unlock",
        "unlock_after_fail",
        "unlock-after-fail",
        "encrypt",
        "decrypt",
        "initialize",
        "login",
        "arm",
        "add_files",
        "open_file",
        "export",
        "purge",
        "purge_temp",
        "hard_wipe",
        "destroy",
        "recover",
        "reset",
        "backup"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "1.2.0",
      "one_line": "Cite an offline vault that prefers destruction over recovery.",
      "description": "Use EmbryoLock to check health, policy, and published hashes for the local vault. It exists so wipe and unlock stay on the device.",
      "worker_home": "https://embryolock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://embryolock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/EmbryoLock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=embryolock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/embryolock",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "bc7f6119a4bf6910b5be50cabe19bf4a2e35ac60408b5713e94878bd4e0074f3",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      },
      "local_destructive_boundary": true,
      "surface": "live-with-local-destructive-boundary",
      "public_mesh_destructive": false
    },
    {
      "slug": "employeelock",
      "name": "EmployeeLock",
      "bucket": "lock",
      "domain": "Evidence",
      "domain_id": "03",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "append-preview",
        "verify-canonical",
        "health",
        "skill",
        "doctor"
      ],
      "stub_ops": [
        "court",
        "judge"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Hash a proposed accountability log row on the client.",
      "description": "Use EmployeeLock as a hash-chained accountability workbook. It exists to preview log integrity.",
      "worker_home": "https://employeelock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://employeelock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/employeelock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=employeelock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/employeelock",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "886e90395752e7dcb5458a6ee501c34858a18574623b2e542513b4faa96e1d90",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "foldlock",
      "name": "FoldLock",
      "bucket": "lock",
      "domain": "Language",
      "domain_id": "04",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "fold-preview",
        "unfold-preview",
        "health",
        "skill",
        "doctor",
        "pack-verify"
      ],
      "stub_ops": [
        "zip",
        "hosted_store"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.8.0",
      "one_line": "Fold UTF-8 text by suppressing tether words, then check the restore.",
      "description": "Use FoldLock to preview small-text folds and check the shipped corpus tip hash. It exists as algorithmic text folding.",
      "worker_home": "https://foldlock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://foldlock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/foldlock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=foldlock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/foldlock",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "1034d5924b88878918986abe260338b0aff0117bc6f9c4d4a01a41d843cfa0a8",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "godlock",
      "name": "GodLock",
      "bucket": "lock",
      "domain": "Language",
      "domain_id": "04",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "score",
        "submit",
        "health",
        "skill",
        "doctor"
      ],
      "stub_ops": [],
      "door_label": "live FragGate door",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Score text for offline hardening and receive an ephemeral receipt.",
      "description": "Use GodLock to score text and receive a logical receipt. GodLock is a product name. Public identity is Aziel Eliab only. It exists for offline hardening scores.",
      "worker_home": "https://godlock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://godlock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/godlock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=godlock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/godlock",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "6b9076ca8e4aa63e6c81deb40f102f55f8769a7c10f0b8347605903f7df93f54",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "mialock",
      "name": "M.I.A.Lock",
      "bucket": "lock",
      "domain": "Evidence",
      "domain_id": "03",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "map",
        "search-options",
        "queries",
        "doe-match",
        "coverage",
        "example",
        "health",
        "skill",
        "doctor"
      ],
      "stub_ops": [],
      "door_label": "live FragGate door",
      "open_live_door": true,
      "version": "0.1.1",
      "one_line": "Map missing-person events and rank Doe notices as compatibility leads.",
      "description": "Use M.I.A.Lock for event maps, archive search plans, Doe matching, and coverage heat. It exists to organize authorized search work — Doe hits are leads, and heat is search intensity.",
      "worker_home": "https://mialock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://mialock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/mialock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=mialock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/mialock",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "d65c53dbc46d500f6d02c8975e42bf95a22000c15db4776d5fdef58904d32a5c",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "peacelock",
      "name": "PeaceLock",
      "bucket": "lock",
      "domain": "Evidence",
      "domain_id": "03",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "open",
        "seal",
        "break",
        "show",
        "verify",
        "stamp",
        "upload_envelope",
        "health",
        "skill",
        "doctor"
      ],
      "stub_ops": [
        "transcript",
        "transcribe",
        "motive",
        "counterfactual",
        "invent",
        "waive-duty",
        "bypass-duty"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Record chosen silence or chosen inaction as a hash-chained receipt.",
      "description": "Use PeaceLock when the act worth keeping is that someone chose silence or inaction. It exists so silence can be a receipt.",
      "worker_home": "https://peacelock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://peacelock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/peacelock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=peacelock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/peacelock",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "291437f64ba15338d6358e6d2e657870619b19133430be3574d458b8db469a66",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "shadowlock",
      "name": "ShadowLock",
      "bucket": "lock",
      "domain": "Evidence",
      "domain_id": "03",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "observe",
        "hook",
        "health",
        "skill",
        "doctor"
      ],
      "stub_ops": [],
      "door_label": "live FragGate door",
      "open_live_door": true,
      "version": "0.2.0",
      "one_line": "Observe a job list you already have, then discard the observation.",
      "description": "Use ShadowLock to wrap an existing job list in a zero-retention observation. It exists as an ethics envelope.",
      "worker_home": "https://shadowlock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://shadowlock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/shadowlock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=shadowlock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/shadowlock",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "0176d18d8517ef02b391821b1fd1ae428591543ea1c812c9785d832714281f61",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "spectrallock",
      "name": "SpectralLock",
      "bucket": "lock",
      "domain": "Media",
      "domain_id": "02",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "modes",
        "targets",
        "overlay",
        "pigment",
        "restore-pigment",
        "verify",
        "doctor",
        "health",
        "skill"
      ],
      "stub_ops": [
        "spectrometer",
        "forensic",
        "invent_mark"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.3.1",
      "one_line": "Preview a 256-pixel overlay, paint membership from the Spectral Harmonic Wheel, and restore faded pigment where the pixels still carry it.",
      "description": "Use SpectralLock 0.3.1 for a hosted overlay whose wheel-paint plane is separate from the spectral triad. Restore lost pigment is live under SpectralLock on FragGate ops pigment and restore-pigment. AMOE stays on the suite project map and is not a live product. It exists as a hosted overlay preview.",
      "worker_home": "https://spectrallock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://spectrallock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/spectrallock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=spectrallock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/spectrallock",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "16281860ab0787f2485ea2530fbbcecf968009da3ae1c4f2b6e689a15a9ad586",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "temporallock",
      "name": "TemporalLock",
      "bucket": "lock",
      "domain": "Core Time",
      "domain_id": "11",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "genesis",
        "append",
        "verify",
        "timeslate",
        "gate",
        "import_export",
        "doctor",
        "health",
        "skill"
      ],
      "stub_ops": [
        "truth_claim",
        "scheduler",
        "store_chain",
        "rollback"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.2.0",
      "one_line": "Build and check hashes on a receipt timeline you keep on the client.",
      "description": "Use TemporalLock to start, append, and check hashes on receipts anyone can recompute. It exists so time-stamped records stay client-held.",
      "worker_home": "https://temporallock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://temporallock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/temporallock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=temporallock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/temporallock",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "fa1ce89d3201c3a4d00f46da1253418b11e98fb50414cd1c65517e2282ed6b5e",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "trajectorylock",
      "name": "TrajectoryLock",
      "bucket": "lock",
      "domain": "Media",
      "domain_id": "02",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "example",
        "analyze",
        "verify",
        "schema",
        "import_export",
        "hash_put",
        "hash_get",
        "hash_stat",
        "doctor",
        "health",
        "skill"
      ],
      "stub_ops": [
        "certified",
        "shooter",
        "intent",
        "guilt",
        "store_media",
        "face"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Test whether observations fit a declared geometric line.",
      "description": "Use TrajectoryLock to check posted geometry against a line you declared. It exists as a research compatibility test.",
      "worker_home": "https://trajectorylock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://trajectorylock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/trajectorylock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=trajectorylock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/trajectorylock",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "7f536c9d148515d9b4e578c558361255db226cd5e3066daee1eee68209bfe3a7",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "veillock",
      "name": "VeilLock",
      "bucket": "lock",
      "domain": "Media",
      "domain_id": "02",
      "placement": "domain-software",
      "status": "local_only",
      "fraggate_status": "local_only",
      "public_door": false,
      "public_door_ops": [],
      "stub_ops": [
        "inject",
        "intercept",
        "facetime"
      ],
      "door_label": "local only — no public FragGate door",
      "open_live_door": false,
      "version": "0.2.0",
      "one_line": "Follow local camera and screen steps for apps on your own device.",
      "description": "Use VeilLock for device-local camera and screen steps in your own apps. VeilLock stays local_only. It exists for camera and screen work on your own device.",
      "worker_home": "https://veillock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://veillock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/veillock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=veillock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": false,
        "open_live_door": false,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/veillock",
        "pipeline": "fraggate_list → fraggate_describe. fraggate_call refuses FG-LOCAL-ONLY. No public door."
      },
      "engine_digest": "b7114d83e33d9f3c05427110115b798c23209eb2716a6431b6bcbe4a613fd464",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "none",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      },
      "local_only": true,
      "note": "Device-local. FragGate status is local_only — no public door. Hub tab must not read this card as public-door live."
    },
    {
      "slug": "vibelock",
      "name": "VibeLock",
      "bucket": "lock",
      "domain": "Media",
      "domain_id": "02",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "analyze",
        "detect",
        "health",
        "skill",
        "doctor"
      ],
      "stub_ops": [],
      "door_label": "live FragGate door",
      "open_live_door": true,
      "version": "0.3.0",
      "one_line": "Assess AI deepfake risk in mp4, mp3, and other audio and video. Physics and related signals are heuristic. Linguistics is experimental. Vibration is measured only with a body-coupled track.",
      "description": "Use VibeLock to assess AI deepfake risk in audio and video you already hold. It exists as a media authenticity advisory. Physics and related signals are heuristic. Linguistics is experimental. Vibration is a measurement only when a body-coupled track is present. Hosted analyze and detect score posted features or limited PCM, refuse raw container bytes, and publish no accuracy percentage. Compressed files on the local package need ffmpeg.",
      "worker_home": "https://vibelock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://vibelock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/vibelock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=vibelock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/vibelock",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "bf35c9e62ae2717bac039d74ff81be7af57be4c454a418b1cc4abffee9d08d5a",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    },
    {
      "slug": "whistlelock",
      "name": "WhistleLock",
      "bucket": "lock",
      "domain": "Evidence",
      "domain_id": "03",
      "placement": "domain-software",
      "status": "live",
      "fraggate_status": "live",
      "public_door": true,
      "public_door_ops": [
        "hash-preview",
        "canon-preview",
        "hash_put",
        "hash_get",
        "hash_stat",
        "health",
        "skill",
        "doctor"
      ],
      "stub_ops": [
        "send",
        "mail",
        "release"
      ],
      "door_label": "live FragGate door — named stub ops refuse",
      "open_live_door": true,
      "version": "0.1.0",
      "one_line": "Hash a local drop and keep a dead-man copy on the client.",
      "description": "Use WhistleLock to hash posted bytes and hold isolate-hash objects. It exists as a local drop ledger.",
      "worker_home": "https://whistlelock-download-tracker.vibelock.workers.dev/",
      "worker_home_note": null,
      "download_url": "https://whistlelock-download-tracker.vibelock.workers.dev/download",
      "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "github": "https://github.com/AzielEliab/whistlelock",
      "mcp": "https://godlock.uk/runtime/mcp",
      "agent": {
        "mcp": "https://godlock.uk/runtime/mcp",
        "skill": "https://godlock.uk/runtime/v1/skill",
        "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
        "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=whistlelock",
        "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
        "fraggate_call_executes": true,
        "open_live_door": true,
        "software": "https://godlock.uk/runtime/v1/software",
        "pull": "https://godlock.uk/runtime/v1/pull/whistlelock",
        "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
      },
      "engine_digest": "f585b20e1dfc0321e432ba04299d91d1708ae3b6f2ac78c85db5c61a63a4a6f8",
      "updated_at": "2026-10-04",
      "git_sha": "62b586f32e0f130d1b89936782cbd4bc304d8c15",
      "git_sha_tracks_deployed_tip": true,
      "door": "fraggate",
      "kind": "software",
      "mesh": {
        "path": "/runtime/v1/mesh",
        "enabled_default": true,
        "mesh_default": "on",
        "spec": "QNM-BUILD-1.0",
        "companion": "AIH-WP-1.1",
        "rollup_only": true,
        "qnm_s": false,
        "suite_presence": "on",
        "get_never_enables": true,
        "security": {
          "model": "single-node-security-awareness",
          "isolates": "bad-peer-or-self",
          "mesh_fenced_to_loopback": false,
          "forced_loopback": false,
          "loopback_isolation": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false,
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false,
          "loopback_bearer": "L1-optional",
          "operator_locks": [
            {
              "n": 1,
              "id": "single-node-security-awareness",
              "status": "LIVE",
              "mesh_fenced_to_loopback": false
            },
            {
              "n": 2,
              "id": "phoenix-reboot-loop",
              "status": "LIVE",
              "phoenix": "local-wait-reseal",
              "phoenix_lock": true,
              "public_hostname_resurrection": false
            },
            {
              "n": 3,
              "id": "open-world-awareness",
              "status": "live-when-configured",
              "law": "LIVE",
              "bind": "0.0.0.0",
              "worker_socket": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false
            }
          ],
          "open_world_awareness": {
            "spec": "OPEN-WORLD-AWARENESS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "open_world_awareness": true,
            "bind": "0.0.0.0",
            "all_interfaces": true,
            "law": "LIVE",
            "status": "live-when-configured",
            "live": false,
            "socket": "live-when-configured",
            "worker_socket": false,
            "qnm_node_bind": "live-when-configured",
            "mock": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "mesh_fenced_to_loopback": false,
            "public_egress_ip": false,
            "residential": false,
            "cf_geo_exit": false,
            "cf_geo_exit_pool": false,
            "sticky_public_ip": false,
            "packet_forward": false,
            "packet_forwarding": false,
            "public_icann": false,
            "cap7_is_icann": false,
            "replaces_internet": false,
            "not_a_second_internet": true,
            "hosted_vpn": false,
            "payload_host": false,
            "vpn_hop": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit": false,
            "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
          },
          "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
        },
        "fanout": "cron-or-request-path",
        "live_nodes_plane": "human-mesh-users-site-viewers",
        "nodes_plane": "human-mesh-users-uses",
        "software_nodes_plane": "software-worker-fanout",
        "site_live_viewers_plane": "hub-human-page-presence",
        "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
        "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
        "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
        "site_presence_contract": {
          "method": "POST",
          "path": "/runtime/v1/mesh/site-presence",
          "alias": "/runtime/v1/mesh/site-heartbeat",
          "fraggate": {
            "slug": "mesh",
            "op": "site-presence"
          },
          "body": {
            "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
            "viewers": "non-negative integer concurrent human page sessions (0..10000)",
            "kind": "human-page"
          },
          "ttl_ms": 900000,
          "registered_grace_ms": 1209600000,
          "default_heartbeat_mode": "idle",
          "heartbeat_mode": "active | idle | asleep",
          "stale_keeps_registered": true,
          "stale_counts_as_live": false,
          "allowed_hosts": [
            "godlock.uk",
            "azieleliab.com",
            "azielcorpuslibrary.net"
          ],
          "excluded_hosts": [
            "hedidntjump.com"
          ],
          "refused_kinds": [
            "bot",
            "bots",
            "crawler",
            "software",
            "softwares",
            "download",
            "downloads",
            "instance",
            "mcp"
          ],
          "pull_hub_count": false,
          "invent": false,
          "fail_closed": true,
          "read": "single-key",
          "paint": "live_nodes",
          "local_recompute": false,
          "radios": "not required — hub ingest, not a TX join",
          "rate_kind": "mesh_mutate",
          "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
        },
        "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
        "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
        "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
        "presence_ttl_ms": 300000,
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "survival": {
          "spec": "CROSS-NETWORK-SURVIVAL-1.0",
          "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
          "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
          "shelves": [
            "hosts",
            "doi",
            "git",
            "vault"
          ],
          "software_tab": false,
          "fraggate_slug": false,
          "named_hosts_only": true,
          "live_network_is_shelf": false,
          "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
        },
        "ban_survival": "BAN-SURVIVAL-1.0",
        "spore_spec": "SPORE-1.0",
        "no_lie": true,
        "no_rewrite": true,
        "rewrite_key": false,
        "lie_to_survive": false,
        "copies_one_tunnel": false,
        "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
        "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
        "no_lie_hint": {
          "spec": "NO-LIE-NO-REWRITE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "software_tab": false,
          "fraggate_slug": false,
          "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
        },
        "nine_laws": {
          "hard_true": true,
          "count": 9,
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "isolation_is_the_cure": true,
          "neighbor_heal": true,
          "phoenix_local_only": true,
          "die_with_pull": true,
          "restore_godlock_uk": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "implicit_heal": true,
          "auto_heal": true,
          "network": true,
          "network_cite": "on",
          "anonymity_network": true,
          "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
          "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
          "date": "2026-09-17",
          "operator_armed": true,
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "concentrator_name": "AZVPN",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "auto_bind": true,
          "vpn_auto": {
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "door": "fraggate",
            "explicit_ops": [
              "describe",
              "open",
              "status",
              "list",
              "close",
              "send",
              "recv",
              "pull",
              "peers",
              "attach"
            ],
            "hooks": {
              "mesh_get": "cite-only",
              "mesh_vpn": "ensure",
              "aznet_pair": "cite-and-ensure-when-paired-or-armed",
              "session_open": "ensure-when-armed",
              "azbrowser_vpn": "ensure"
            },
            "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
            "get_never_opens": true,
            "open": false
          },
          "door": "fraggate",
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "wireguard": false,
          "openvpn": false,
          "l3_exit_pool": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "kinds": {
            "https_ws": "REAL",
            "fraggate_envelopes": "REAL",
            "websocket_attach": "REAL",
            "wireguard": "SLOT",
            "openvpn": "SLOT",
            "l3_exit_pool": "SLOT",
            "kernel_udp": "SLOT",
            "tun_tap": "SLOT"
          },
          "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
          "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
          "operator_override": {
            "spec": "OPERATOR-OVERRIDE-2026-09-17",
            "date": "2026-09-17",
            "identity": "Aziel Eliab",
            "author": "Aziel Eliab",
            "operator_armed": true,
            "auto_heal": true,
            "implicit_heal": true,
            "node_gate": true,
            "get_is_node_gate": true,
            "neighbor_heal": true,
            "neighbor_heal_is_cite": true,
            "neighbor_heal_exec": false,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
          },
          "papers": {
            "node_mesh": "docs/NODE_MESH.md",
            "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
            "node_ops": "docs/designs/NODE-OPS-1.0.md",
            "qnm_wp": "docs/designs/QNM-WP-1.0.md"
          }
        },
        "author_id": "https://www.azieleliab.com/#aziel",
        "runtime_id": "https://www.azieleliab.com/runtime#runtime",
        "hashtag_parts": {
          "person": "#aziel",
          "runtime": "#runtime"
        },
        "about": {
          "path": "/about",
          "v1": "/runtime/v1/about",
          "identity": "Aziel Eliab",
          "author_id": "https://www.azieleliab.com/#aziel",
          "always": true
        },
        "clocks_share_socket": false,
        "live_body_sync": false,
        "node_gate": true,
        "get_is_node_gate": true,
        "anonymity_network": true,
        "die_with_pull": true,
        "phoenix_local_only": true,
        "implicit_heal": true,
        "auto_heal": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "join_is_presence_only": true,
        "join_is_not_login": true,
        "roster_publishes_exec_urls": false,
        "mesh_mutate_rate_kind": "mesh_mutate",
        "roster_cap": 256,
        "network": true,
        "network_cite": "on",
        "channel_plane": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "operator_armed": true,
          "plane": "channel",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "bearer": "suite-presence",
          "worker_bearer": "suite-presence",
          "worker_hardware": false,
          "invented_hardware": false,
          "public_proxy": false,
          "local_process": "qnm-node / qnsd",
          "local": "https://github.com/AzielEliab/qnm-node",
          "local_radio_hooks": {
            "path": "qnm-node/bearers/radio.js",
            "law": "LIVE-when-HW-present / refuse-when-absent",
            "mock": false,
            "worker_hardware": false
          },
          "vpn": true,
          "public_vpn": true,
          "tunnel_concentrator": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "worker_terminates_tunnels": true,
          "worker_terminates_kernel_udp": false,
          "tor": false,
          "socks": false,
          "origin_hiding": false,
          "tunnel": false,
          "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
          "node_mesh": "docs/NODE_MESH.md",
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "channels": {
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on"
        },
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on",
        "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
        "worker_hardware": false,
        "invented_hardware": false,
        "channel_plane_hint": {
          "spec": "QNM-CHANNEL-PLANE-1.0",
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "vpn": true,
          "public_vpn": true,
          "concentrator_slug": "azvpn",
          "default_vpn_backend": "azvpn",
          "auto_use": true,
          "public_proxy": false,
          "worker_hardware": false,
          "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
        },
        "d2d_carriers": {
          "spec": "D2D-CARRIERS-1.0",
          "author": "Aziel Eliab",
          "identity": "Aziel Eliab",
          "plane": "track2-reachability",
          "phase": "B+C+D",
          "phases": {
            "A": "landed",
            "B": "LIVE-when-armed",
            "C": "LIVE-when-session",
            "D": "LIVE-when-three-local-nodes / fixture",
            "E": "scaffold"
          },
          "lan_discovery": "LIVE-when-armed",
          "wifi_discovery": "ARMED-when-HW",
          "bluetooth_discovery": "ARMED-when-HW",
          "rf_discovery": "REFUSE-without-HW",
          "photon_discovery": "REFUSE-without-HW",
          "peer_tunnel": "LIVE-when-session",
          "store_forward": "LIVE-when-three-local-nodes / fixture",
          "store_forward_public": "FG-STUB",
          "worker_runs_store_forward": false,
          "second_device": false,
          "mobile_client": "present-not-demonstrated",
          "mobile_demonstrated": false,
          "app_store_release": false,
          "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
          "bootstrap_list": "scaffold",
          "needs_starting_address": true,
          "shelf_cite": "scaffold",
          "live_multi_provider": false,
          "cold_shelf_live": false,
          "dns_cut": false,
          "origin_cutover": false,
          "warn5_closed": false,
          "worker_door": "FG-STUB",
          "worker_hardware": false,
          "local_node": "qnm-node",
          "get_never_enables": true,
          "separate_from": "cap7-name",
          "cap7_is_name_plane": true,
          "cap7_public_icann": false,
          "cap7_public_egress": false,
          "mirage_is_azvpn": false,
          "aznet_replaces_internet": false,
          "not_a_second_internet": true,
          "alt_internet_live": false,
          "packet_path_live": false,
          "field_1_0": false,
          "warn5": "STANDS-until-demonstrated",
          "warn5_permanent_stay_off": false,
          "preference": "failover",
          "order": [
            "lan",
            "wifi",
            "bluetooth",
            "rf",
            "photon"
          ],
          "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
          "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "warn5_until": "demonstrated",
          "warn5_by_design": "separate-from-icann",
          "refuse": {
            "packet": "FG-STUB",
            "radio_absent": "QNM-RADIO-ABSENT",
            "cap7_egress": "MG-NO-IP-EXIT",
            "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
            "bearer": "AZP-BEARER-REFUSE",
            "payload": "AZN-NO-PAYLOAD",
            "route": "MESH-NO-ROUTE",
            "stay_off": "MESH-STAY-OFF",
            "nat": "FED-MESH-NAT-REFUSE"
          },
          "carriers": [
            {
              "order": 1,
              "id": "lan",
              "name": "LAN",
              "op": "d2d_lan",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "lan-interface",
              "discovery": "LIVE-when-armed",
              "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
            },
            {
              "order": 2,
              "id": "wifi",
              "name": "Wi-Fi",
              "op": "d2d_wifi",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "wifi-nm",
              "discovery": "ARMED-when-HW",
              "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
            },
            {
              "order": 3,
              "id": "bluetooth",
              "name": "Bluetooth",
              "op": "d2d_bluetooth",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "bluez",
              "discovery": "ARMED-when-HW",
              "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
            },
            {
              "order": 4,
              "id": "rf",
              "name": "RF",
              "op": "d2d_rf",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "rf-beyond-wifi-bt",
              "discovery": "REFUSE-without-HW",
              "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
            },
            {
              "order": 5,
              "id": "photon",
              "name": "Photon",
              "op": "d2d_photon",
              "status": "NOT-READY",
              "code": "FG-STUB",
              "packet_live": false,
              "mock": false,
              "functional": true,
              "peer_exchange_demonstrated": false,
              "absent_code": "QNM-RADIO-ABSENT",
              "hw": "camera-flash",
              "discovery": "REFUSE-without-HW",
              "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
            }
          ],
          "security": {
            "isolation": "single-node security-awareness",
            "phoenix": "local wait / re-seal",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false
          },
          "paper": "docs/designs/D2D-CARRIERS-1.0.md",
          "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
        },
        "d2d_status": "NOT-READY",
        "d2d_code": "FG-STUB",
        "packet_path_live": false,
        "alt_internet_live": false,
        "d2d_spec": "D2D-CARRIERS-1.0",
        "federated_mesh": "FED-MESH-1.0",
        "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
        "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
      },
      "qns_cd": {
        "spec": "QNS-CD-1.0",
        "local": "https://github.com/AzielEliab/qnm-node",
        "note": "Photon vias on local qnsd; Worker cites only"
      }
    }
  ],
  "domains": {
    "spec": "MASTER-33",
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "door": "fraggate",
    "domains_are_doors": false,
    "software_tab": true,
    "domain_count": 11,
    "software_count": 33,
    "tab_placement_slugs": [
      "azinterface",
      "decisiongate",
      "forgereceipts",
      "azcoherence",
      "zkattest",
      "mmconsensus",
      "toolbench",
      "azvpn",
      "whitestone"
    ],
    "domains": [
      {
        "id": "01",
        "slug": "vault-custody",
        "name": "Vault/Custody",
        "softwares": [
          "ark",
          "embryolock"
        ]
      },
      {
        "id": "02",
        "slug": "media",
        "name": "Media",
        "softwares": [
          "vibelock",
          "veillock",
          "spectrallock",
          "trajectorylock"
        ]
      },
      {
        "id": "03",
        "slug": "evidence",
        "name": "Evidence",
        "softwares": [
          "employeelock",
          "whistlelock",
          "peacelock",
          "shadowlock",
          "mialock",
          "chronolock"
        ]
      },
      {
        "id": "04",
        "slug": "language",
        "name": "Language",
        "softwares": [
          "codelock",
          "foldlock",
          "glossafilter",
          "zsolver",
          "godlock",
          "azclce"
        ]
      },
      {
        "id": "05",
        "slug": "ai",
        "name": "AI",
        "softwares": [
          "azai",
          "azbot",
          "azhub"
        ]
      },
      {
        "id": "06",
        "slug": "research",
        "name": "Research",
        "softwares": [
          "azbrowser",
          "aziel-corpus",
          "4dmap"
        ]
      },
      {
        "id": "07",
        "slug": "comms",
        "name": "Comms",
        "softwares": [
          "azmail",
          "azchat"
        ]
      },
      {
        "id": "08",
        "slug": "network",
        "name": "Network",
        "softwares": [
          "aznet",
          "miragegrid",
          "azieltether"
        ]
      },
      {
        "id": "09",
        "slug": "system",
        "name": "System",
        "softwares": [
          "azos"
        ]
      },
      {
        "id": "10",
        "slug": "simulation",
        "name": "Simulation",
        "softwares": [
          "postking"
        ]
      },
      {
        "id": "11",
        "slug": "core-time",
        "name": "Core Time",
        "softwares": [
          "staticclock",
          "temporallock"
        ]
      }
    ],
    "placements": {
      "azinterface": {
        "placement": "human-ui",
        "domain": null,
        "domain_id": null,
        "note": "AZInterface is the human UI before FragGate. Catalog software. Not an extra door."
      },
      "decisiongate": {
        "placement": "fabric-product",
        "domain": null,
        "domain_id": null,
        "note": "DecisionGATE is the policy hop on the locked strip. Catalog engine. Not an extra door."
      },
      "forgereceipts": {
        "placement": "fabric-product",
        "domain": null,
        "domain_id": null,
        "note": "ForgeReceipts packages Return. Catalog engine. Not an extra door."
      },
      "fraggate": {
        "placement": "fabric-kernel",
        "domain": null,
        "domain_id": null,
        "note": "FragGate is THE single door. Human Worker UI + counted download is the separate FragGate app."
      },
      "mesh": {
        "placement": "fabric-mesh",
        "domain": null,
        "domain_id": null,
        "note": "QNM-BUILD-1.0 suite rollup. Fabric/hub. Not a Softwares-tab product. Read-only suite-presence ON by default."
      },
      "memory": {
        "placement": "fabric-memory",
        "domain": null,
        "domain_id": null,
        "note": "AKM-TRIAD-1.0 adaptive knowledge memory. Fabric. Not a Softwares-tab product. Behind FragGate."
      },
      "azcoherence": {
        "placement": "scoring-review",
        "domain": null,
        "domain_id": null,
        "note": "AZCoherence is the second-pass coherence reviewer for triad scores. Scoring-adjacent to AZ-CLCE (Language isolation). Catalog software. Not an extra door. Not AKM-TRIAD fabric. Domain stays null — same pattern as decisiongate/forgereceipts: scoring-review is a placement, not a 34th isolation software. Domains are isolation labels, not doors. Cross-map peers: azclce (peer scorer), azinterface (human-UI), AKM-TRIAD (fabric neighbor, not merged)."
      },
      "zkattest": {
        "placement": "receipt-attest",
        "domain": null,
        "domain_id": null,
        "note": "ZKAttest is a hash-commitment attest helper. Adjacent to ForgeReceipts. Catalog placement, not a 34th isolation software. Not Groth16/SNARK. In-runtime (no invented product Worker). FragGate only."
      },
      "mmconsensus": {
        "placement": "consensus-review",
        "domain": null,
        "domain_id": null,
        "note": "MMConsensus tallies caller-supplied opinions. Adjacent to DecisionGATE — not a replacement hop. Not live multi-model calls. Catalog placement, not a 34th isolation software. FragGate only."
      },
      "toolbench": {
        "placement": "tool-playground",
        "domain": null,
        "domain_id": null,
        "note": "ToolBench is a synthetic FragGate refuse playground. Self-test ≠ third-party lab. Not . Catalog placement, not a 34th isolation software. FragGate only."
      },
      "azvpn": {
        "placement": "tunnel-concentrator",
        "domain": null,
        "domain_id": null,
        "note": "AZVPN is the automatic application-layer HTTPS/WS tunnel concentrator (default_vpn_backend:azvpn, auto_use:true). Adjacent to AZNet (pairing stays order/token). Catalog placement, not a 34th isolation software. WireGuard/OpenVPN/L3 stay SLOT. In-runtime (no invented product Worker). FragGate only."
      },
      "whitestone": {
        "placement": "pro-se-advisor",
        "domain": null,
        "domain_id": null,
        "note": "Whitestone is a live Worker-only ephemeral pro se advisor (Criminal, Civil, Divorce) with historical as-of and Case Mode. Catalog software. worker_only. FragGate status none — do not invent door ops. Dual-surface AI discovery via GET /v1/software + llms/ai/cite/who-is, plus Whitestone Worker GET /v1/software. Domain stays null. Session-only; optional zip. Author: Aziel Eliab only."
      }
    },
    "note": "11 domains / 33 softwares are isolation labels. Softwares-tab count is larger because it includes placements (azinterface / decisiongate / forgereceipts / azcoherence / zkattest / mmconsensus / toolbench / azvpn / whitestone). Internal Domain Layer executes isolated softwares after AZPIPE. Not additional doors. domains_are_doors:false."
  },
  "mcp": "https://godlock.uk/runtime/mcp",
  "fraggate": "https://godlock.uk/runtime/v1/fraggate",
  "fraggate_software": "https://godlock.uk/runtime/v1/fraggate/software",
  "catalog": "https://godlock.uk/runtime/v1/catalog.json",
  "stats": {
    "person_id": "https://www.azieleliab.com/#aziel",
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "purpose": "AZindex graph social-status awareness (not vanity, not biography)",
    "kind": "read-only-snapshot",
    "vanity": false,
    "biography": false,
    "never_invent_numbers": true,
    "rollup": "https://godlock.uk/runtime/v1/stats-rollups",
    "live": [
      "https://www.azieleliab.com/v1/stats",
      "https://www.azielcorpuslibrary.net/stats",
      "https://www.hedidntjump.com/api/stats"
    ],
    "hubs": [
      {
        "id": "azieleliab",
        "name": "Aziel Eliab",
        "kind": "hub",
        "stats": "https://www.azieleliab.com/v1/stats",
        "keys": [
          "views"
        ],
        "live": true
      },
      {
        "id": "corpus",
        "name": "Aziel Digital Library",
        "kind": "hub",
        "stats": "https://www.azielcorpuslibrary.net/stats",
        "fallbacks": [
          "https://aziel-corpus-download-tracker.vibelock.workers.dev/stats"
        ],
        "not": [
          "https://www.azielcorpuslibrary.net/v1/stats"
        ],
        "version": "https://www.azielcorpuslibrary.net/v1/health",
        "keys": [
          "views",
          "downloads"
        ],
        "live": true,
        "note": "Counters are GET /stats (views, downloads). GET /v1/stats is not the counter door. Version is GET /v1/health."
      },
      {
        "id": "godlock",
        "name": "GodLock",
        "kind": "hub",
        "stats": "https://godlock.uk/stats",
        "fallbacks": [
          "https://godlock-download-tracker.vibelock.workers.dev/stats"
        ],
        "keys": [
          "views",
          "uses",
          "downloads",
          "current_score"
        ],
        "never_cite": [
          "uploads"
        ],
        "v1_stats": "https://godlock.uk/v1/stats",
        "v1_stats_status": 404,
        "live": true,
        "note": "GET /v1/stats is 404. Public snapshot is GET /stats. Never cite uploads."
      },
      {
        "id": "hedidntjump",
        "name": "He Didn't Jump",
        "kind": "sister-archive",
        "stats": "https://www.hedidntjump.com/api/stats",
        "not": [
          "https://www.hedidntjump.com/stats"
        ],
        "source_of_truth": "https://hedidntjump-stats.vibelock.workers.dev",
        "keys": [
          "views",
          "downloads",
          "items"
        ],
        "dual_write_hits": false,
        "live": true,
        "note": "Fetch /api/stats only. /stats is the SPA. Worker SoT is cite-only — do not dual-write hits."
      },
      {
        "id": "runtime",
        "name": "Aziel Runtime",
        "kind": "runtime",
        "stats": "https://godlock.uk/runtime/v1/uses",
        "alias": "https://godlock.uk/runtime/v1/stats",
        "host_mirrors": [
          "https://www.azieleliab.com/runtime/v1/uses",
          "https://www.azielcorpuslibrary.net/runtime/v1/uses",
          "https://godlock.uk/runtime/v1/uses"
        ],
        "keys": [
          "uses",
          "by_host",
          "by_path"
        ],
        "label": "agent/MCP usage",
        "product_stats_template": "https://{slug}-download-tracker.vibelock.workers.dev/stats",
        "live": true,
        "note": "GET /v1/uses is API / agent / MCP usage (alias /v1/stats). Host /runtime/v1/uses mirrors the same counters. Optional per-slug download-tracker /stats is not fetched by the hub rollup."
      }
    ],
    "product_stats_template": "https://{slug}-download-tracker.vibelock.workers.dev/stats",
    "note": "Read-only AZindex awareness. Cite the stats URLs. GET /v1/stats-rollups fetches siblings best-effort and caches briefly. Failed siblings are omitted. Digital Library counters: /stats (not /v1/stats; version is /v1/health). He Didn't Jump: /api/stats only. GodLock: /stats (not /v1/stats). Runtime uses are agent/MCP usage, not vanity views."
  },
  "social_status": {
    "person_id": "https://www.azieleliab.com/#aziel",
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "purpose": "AZindex graph social-status awareness (not vanity, not biography)",
    "kind": "read-only-snapshot",
    "vanity": false,
    "biography": false,
    "never_invent_numbers": true,
    "rollup": "https://godlock.uk/runtime/v1/stats-rollups",
    "live": [
      "https://www.azieleliab.com/v1/stats",
      "https://www.azielcorpuslibrary.net/stats",
      "https://www.hedidntjump.com/api/stats"
    ],
    "hubs": [
      {
        "id": "azieleliab",
        "name": "Aziel Eliab",
        "kind": "hub",
        "stats": "https://www.azieleliab.com/v1/stats",
        "keys": [
          "views"
        ],
        "live": true
      },
      {
        "id": "corpus",
        "name": "Aziel Digital Library",
        "kind": "hub",
        "stats": "https://www.azielcorpuslibrary.net/stats",
        "fallbacks": [
          "https://aziel-corpus-download-tracker.vibelock.workers.dev/stats"
        ],
        "not": [
          "https://www.azielcorpuslibrary.net/v1/stats"
        ],
        "version": "https://www.azielcorpuslibrary.net/v1/health",
        "keys": [
          "views",
          "downloads"
        ],
        "live": true,
        "note": "Counters are GET /stats (views, downloads). GET /v1/stats is not the counter door. Version is GET /v1/health."
      },
      {
        "id": "godlock",
        "name": "GodLock",
        "kind": "hub",
        "stats": "https://godlock.uk/stats",
        "fallbacks": [
          "https://godlock-download-tracker.vibelock.workers.dev/stats"
        ],
        "keys": [
          "views",
          "uses",
          "downloads",
          "current_score"
        ],
        "never_cite": [
          "uploads"
        ],
        "v1_stats": "https://godlock.uk/v1/stats",
        "v1_stats_status": 404,
        "live": true,
        "note": "GET /v1/stats is 404. Public snapshot is GET /stats. Never cite uploads."
      },
      {
        "id": "hedidntjump",
        "name": "He Didn't Jump",
        "kind": "sister-archive",
        "stats": "https://www.hedidntjump.com/api/stats",
        "not": [
          "https://www.hedidntjump.com/stats"
        ],
        "source_of_truth": "https://hedidntjump-stats.vibelock.workers.dev",
        "keys": [
          "views",
          "downloads",
          "items"
        ],
        "dual_write_hits": false,
        "live": true,
        "note": "Fetch /api/stats only. /stats is the SPA. Worker SoT is cite-only — do not dual-write hits."
      },
      {
        "id": "runtime",
        "name": "Aziel Runtime",
        "kind": "runtime",
        "stats": "https://godlock.uk/runtime/v1/uses",
        "alias": "https://godlock.uk/runtime/v1/stats",
        "host_mirrors": [
          "https://www.azieleliab.com/runtime/v1/uses",
          "https://www.azielcorpuslibrary.net/runtime/v1/uses",
          "https://godlock.uk/runtime/v1/uses"
        ],
        "keys": [
          "uses",
          "by_host",
          "by_path"
        ],
        "label": "agent/MCP usage",
        "product_stats_template": "https://{slug}-download-tracker.vibelock.workers.dev/stats",
        "live": true,
        "note": "GET /v1/uses is API / agent / MCP usage (alias /v1/stats). Host /runtime/v1/uses mirrors the same counters. Optional per-slug download-tracker /stats is not fetched by the hub rollup."
      }
    ],
    "product_stats_template": "https://{slug}-download-tracker.vibelock.workers.dev/stats",
    "note": "Read-only AZindex awareness. Cite the stats URLs. GET /v1/stats-rollups fetches siblings best-effort and caches briefly. Failed siblings are omitted. Digital Library counters: /stats (not /v1/stats; version is /v1/health). He Didn't Jump: /api/stats only. GodLock: /stats (not /v1/stats). Runtime uses are agent/MCP usage, not vanity views."
  },
  "update_check": "https://godlock.uk/runtime/v1/update/check?slug={slug}&version={installed}",
  "update_manifest": "https://godlock.uk/runtime/v1/update/manifest",
  "hubs": [
    "https://azieleliab.com",
    "https://www.azielcorpuslibrary.net",
    "https://godlock.uk"
  ],
  "hubs_crawl": {
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "author_id": "https://www.azieleliab.com/#aziel",
    "mesh_get_never_enables": true,
    "remain_off_do_not_enable": true,
    "note": "Softwares hubs fetch GET /v1/software on each Software-tab request. Cross-link cite.json / llms.txt / sitemap.xml on each hub. Do not invent mesh enable or Remain-Off items.",
    "hubs": [
      {
        "id": "azieleliab",
        "name": "Aziel Eliab",
        "origin": "https://www.azieleliab.com",
        "home": "https://www.azieleliab.com/",
        "software_tab": "https://www.azieleliab.com/software",
        "cite": "https://www.azieleliab.com/cite.json",
        "llms": "https://www.azieleliab.com/llms.txt",
        "ai": "https://www.azieleliab.com/ai.txt",
        "sitemap": "https://www.azieleliab.com/sitemap.xml",
        "robots": "https://www.azieleliab.com/robots.txt",
        "runtime": "https://www.azieleliab.com/runtime",
        "software_catalog": "https://www.azieleliab.com/v1/software",
        "donate": "https://www.azieleliab.com/donate"
      },
      {
        "id": "library",
        "name": "Aziel Digital Library",
        "origin": "https://www.azielcorpuslibrary.net",
        "home": "https://www.azielcorpuslibrary.net/",
        "software_tab": "https://www.azielcorpuslibrary.net/software",
        "cite": "https://www.azielcorpuslibrary.net/cite.json",
        "llms": "https://www.azielcorpuslibrary.net/llms.txt",
        "ai": "https://www.azielcorpuslibrary.net/ai.txt",
        "sitemap": "https://www.azielcorpuslibrary.net/sitemap.xml",
        "robots": "https://www.azielcorpuslibrary.net/robots.txt",
        "runtime": "https://www.azielcorpuslibrary.net/runtime",
        "software_catalog": "https://www.azielcorpuslibrary.net/v1/software"
      },
      {
        "id": "godlock.uk",
        "name": "GodLock",
        "origin": "https://godlock.uk",
        "home": "https://godlock.uk/",
        "software_tab": "https://godlock.uk/software",
        "cite": "https://godlock.uk/cite.json",
        "llms": "https://godlock.uk/llms.txt",
        "ai": "https://godlock.uk/ai.txt",
        "sitemap": "https://godlock.uk/sitemap.xml",
        "robots": "https://godlock.uk/robots.txt",
        "runtime": "https://godlock.uk/runtime",
        "software_catalog": "https://godlock.uk/runtime/v1/software"
      }
    ]
  },
  "azcoherence": {
    "slug": "azcoherence",
    "name": "AZCoherence",
    "spec": "AZC-0.1",
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "github": "https://github.com/AzielEliab/AZCoherence",
    "worker_home": "https://azcoherence-download-tracker.vibelock.workers.dev/",
    "download": "https://azcoherence-download-tracker.vibelock.workers.dev/download",
    "catalog_card": "https://godlock.uk/runtime/p/azcoherence",
    "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azcoherence",
    "software": "https://godlock.uk/runtime/v1/software",
    "how_to_cite": "Eliab, Aziel. (2026). AZCoherence 0.1.0 [Software]. Apache-2.0. https://github.com/AzielEliab/AZCoherence",
    "note": "Softwares-tab Plain. Scoring-review placement (domain null). Second-pass triad coherence. Peer AZ-CLCE. Neighbor of AKM-TRIAD fabric. GET /v1/mesh never enables.",
    "hubs": [
      {
        "id": "azieleliab",
        "software_tab": "https://www.azieleliab.com/software",
        "cite": "https://www.azieleliab.com/cite.json"
      },
      {
        "id": "library",
        "software_tab": "https://www.azielcorpuslibrary.net/software",
        "cite": "https://www.azielcorpuslibrary.net/cite.json"
      },
      {
        "id": "godlock.uk",
        "software_tab": "https://godlock.uk/software",
        "cite": "https://godlock.uk/cite.json"
      }
    ]
  },
  "sister_products": {
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "software_tab": false,
    "fraggate_engine": false,
    "isolation_software": false,
    "fraggate_call": false,
    "nested_softwares_exec": false,
    "note": "Sister products cited honestly. live_backends false. aziel-runtime fraggate_call executes Aziel Runtime catalog engines. Identity Aziel Eliab only.",
    "products": [
      {
        "slug": "trades-runtime",
        "name": "Trades-Runtime",
        "version": "0.4.9",
        "version_source": "https://trades-runtime.vibelock.workers.dev/v1/health",
        "author": "Aziel Eliab",
        "identity": "Aziel Eliab",
        "github": "https://github.com/AzielEliab/trades-runtime",
        "worker": "https://trades-runtime.vibelock.workers.dev",
        "worker_home": "https://trades-runtime.vibelock.workers.dev/",
        "mcp": "https://trades-runtime.vibelock.workers.dev/mcp",
        "download": "https://trades-runtime.vibelock.workers.dev/download",
        "cite": "https://trades-runtime.vibelock.workers.dev/cite.json",
        "llms": "https://trades-runtime.vibelock.workers.dev/llms.txt",
        "skill": "https://trades-runtime.vibelock.workers.dev/v1/skill",
        "openapi": "https://trades-runtime.vibelock.workers.dev/openapi.json",
        "health": "https://trades-runtime.vibelock.workers.dev/v1/health",
        "one_line": "Shadow-first local BYO runtime for HVAC/plumbing/electrical/sewer/cross-trades. BYO ServiceTitan+ProBooks. Human authority. live_backends false. https://trades-runtime.vibelock.workers.dev/",
        "live_backends": false,
        "hosted_company_os": false,
        "software_tab": false,
        "fraggate_engine": false,
        "true_engine_runtime": false,
        "engine": false,
        "isolation_software": false,
        "nested_softwares_exec": false,
        "fraggate_call": false,
        "how_to_cite": "Eliab, Aziel. (2026). Trades-Runtime 0.4.9 [Software]. Apache-2.0. https://github.com/AzielEliab/trades-runtime",
        "note": "Sister products cited honestly. live_backends false. aziel-runtime fraggate_call executes Aziel Runtime catalog engines. Identity Aziel Eliab only."
      }
    ]
  },
  "mesh_get_never_enables": true,
  "hubs_note": "Hubs (azieleliab.com, azielcorpuslibrary.net, godlock.uk) fetch GET /v1/software on each Software-tab request. A GitHub drop that updates this runtime refreshes those tabs without hand-editing hub copy.",
  "note": "Separate software / sibling software under one FragGate door. Never separate FragGate engines. Clock is not Lock.",
  "mesh": {
    "path": "/runtime/v1/mesh",
    "enabled_default": true,
    "mesh_default": "on",
    "spec": "QNM-BUILD-1.0",
    "companion": "AIH-WP-1.1",
    "rollup_only": true,
    "qnm_s": false,
    "suite_presence": "on",
    "get_never_enables": true,
    "security": {
      "model": "single-node-security-awareness",
      "isolates": "bad-peer-or-self",
      "mesh_fenced_to_loopback": false,
      "forced_loopback": false,
      "loopback_isolation": false,
      "forced_loopback_is_mesh_fence": false,
      "loopback_isolation_is_mesh_fence": false,
      "phoenix": "local-wait-reseal",
      "phoenix_lock": true,
      "public_hostname_resurrection": false,
      "loopback_bearer": "L1-optional",
      "operator_locks": [
        {
          "n": 1,
          "id": "single-node-security-awareness",
          "status": "LIVE",
          "mesh_fenced_to_loopback": false
        },
        {
          "n": 2,
          "id": "phoenix-reboot-loop",
          "status": "LIVE",
          "phoenix": "local-wait-reseal",
          "phoenix_lock": true,
          "public_hostname_resurrection": false
        },
        {
          "n": 3,
          "id": "open-world-awareness",
          "status": "live-when-configured",
          "law": "LIVE",
          "bind": "0.0.0.0",
          "worker_socket": false,
          "forced_loopback_is_mesh_fence": false,
          "loopback_isolation_is_mesh_fence": false
        }
      ],
      "open_world_awareness": {
        "spec": "OPEN-WORLD-AWARENESS-1.0",
        "author": "Aziel Eliab",
        "identity": "Aziel Eliab",
        "open_world_awareness": true,
        "bind": "0.0.0.0",
        "all_interfaces": true,
        "law": "LIVE",
        "status": "live-when-configured",
        "live": false,
        "socket": "live-when-configured",
        "worker_socket": false,
        "qnm_node_bind": "live-when-configured",
        "mock": false,
        "forced_loopback": false,
        "loopback_isolation": false,
        "forced_loopback_is_mesh_fence": false,
        "loopback_isolation_is_mesh_fence": false,
        "mesh_fenced_to_loopback": false,
        "public_egress_ip": false,
        "residential": false,
        "cf_geo_exit": false,
        "cf_geo_exit_pool": false,
        "sticky_public_ip": false,
        "packet_forward": false,
        "packet_forwarding": false,
        "public_icann": false,
        "cap7_is_icann": false,
        "replaces_internet": false,
        "not_a_second_internet": true,
        "hosted_vpn": false,
        "payload_host": false,
        "vpn_hop": false,
        "wireguard": false,
        "openvpn": false,
        "l3_exit": false,
        "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
      },
      "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
    },
    "fanout": "cron-or-request-path",
    "live_nodes_plane": "human-mesh-users-site-viewers",
    "nodes_plane": "human-mesh-users-uses",
    "software_nodes_plane": "software-worker-fanout",
    "site_live_viewers_plane": "hub-human-page-presence",
    "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
    "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
    "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
    "site_presence_contract": {
      "method": "POST",
      "path": "/runtime/v1/mesh/site-presence",
      "alias": "/runtime/v1/mesh/site-heartbeat",
      "fraggate": {
        "slug": "mesh",
        "op": "site-presence"
      },
      "body": {
        "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
        "viewers": "non-negative integer concurrent human page sessions (0..10000)",
        "kind": "human-page"
      },
      "ttl_ms": 900000,
      "registered_grace_ms": 1209600000,
      "default_heartbeat_mode": "idle",
      "heartbeat_mode": "active | idle | asleep",
      "stale_keeps_registered": true,
      "stale_counts_as_live": false,
      "allowed_hosts": [
        "godlock.uk",
        "azieleliab.com",
        "azielcorpuslibrary.net"
      ],
      "excluded_hosts": [
        "hedidntjump.com"
      ],
      "refused_kinds": [
        "bot",
        "bots",
        "crawler",
        "software",
        "softwares",
        "download",
        "downloads",
        "instance",
        "mcp"
      ],
      "pull_hub_count": false,
      "invent": false,
      "fail_closed": true,
      "read": "single-key",
      "paint": "live_nodes",
      "local_recompute": false,
      "radios": "not required — hub ingest, not a TX join",
      "rate_kind": "mesh_mutate",
      "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
    },
    "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
    "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
    "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
    "presence_ttl_ms": 300000,
    "qns_cd": {
      "spec": "QNS-CD-1.0",
      "local": "https://github.com/AzielEliab/qnm-node",
      "note": "Photon vias on local qnsd; Worker cites only"
    },
    "survival": {
      "spec": "CROSS-NETWORK-SURVIVAL-1.0",
      "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
      "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
      "shelves": [
        "hosts",
        "doi",
        "git",
        "vault"
      ],
      "software_tab": false,
      "fraggate_slug": false,
      "named_hosts_only": true,
      "live_network_is_shelf": false,
      "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
    },
    "ban_survival": "BAN-SURVIVAL-1.0",
    "spore_spec": "SPORE-1.0",
    "no_lie": true,
    "no_rewrite": true,
    "rewrite_key": false,
    "lie_to_survive": false,
    "copies_one_tunnel": false,
    "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
    "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
    "no_lie_hint": {
      "spec": "NO-LIE-NO-REWRITE-1.0",
      "author": "Aziel Eliab",
      "identity": "Aziel Eliab",
      "no_lie": true,
      "no_rewrite": true,
      "rewrite_key": false,
      "lie_to_survive": false,
      "copies_one_tunnel": false,
      "software_tab": false,
      "fraggate_slug": false,
      "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
      "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
      "node_mesh": "docs/NODE_MESH.md",
      "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
    },
    "nine_laws": {
      "hard_true": true,
      "count": 9,
      "author": "Aziel Eliab",
      "identity": "Aziel Eliab",
      "author_id": "https://www.azieleliab.com/#aziel",
      "runtime_id": "https://www.azieleliab.com/runtime#runtime",
      "hashtag_parts": {
        "person": "#aziel",
        "runtime": "#runtime"
      },
      "about": {
        "path": "/about",
        "v1": "/runtime/v1/about",
        "identity": "Aziel Eliab",
        "always": true
      },
      "clocks_share_socket": false,
      "live_body_sync": false,
      "isolation_is_the_cure": true,
      "neighbor_heal": true,
      "phoenix_local_only": true,
      "die_with_pull": true,
      "restore_godlock_uk": false,
      "node_gate": true,
      "get_is_node_gate": true,
      "implicit_heal": true,
      "auto_heal": true,
      "network": true,
      "network_cite": "on",
      "anonymity_network": true,
      "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
      "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
      "date": "2026-09-17",
      "operator_armed": true,
      "vpn": true,
      "public_vpn": true,
      "tunnel_concentrator": true,
      "concentrator_slug": "azvpn",
      "concentrator_name": "AZVPN",
      "default_vpn_backend": "azvpn",
      "auto_use": true,
      "auto_bind": true,
      "vpn_auto": {
        "default_vpn_backend": "azvpn",
        "auto_use": true,
        "auto_bind": true,
        "concentrator_slug": "azvpn",
        "concentrator_name": "AZVPN",
        "door": "fraggate",
        "explicit_ops": [
          "describe",
          "open",
          "status",
          "list",
          "close",
          "send",
          "recv",
          "pull",
          "peers",
          "attach"
        ],
        "hooks": {
          "mesh_get": "cite-only",
          "mesh_vpn": "ensure",
          "aznet_pair": "cite-and-ensure-when-paired-or-armed",
          "session_open": "ensure-when-armed",
          "azbrowser_vpn": "ensure"
        },
        "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
        "get_never_opens": true,
        "open": false
      },
      "door": "fraggate",
      "worker_terminates_tunnels": true,
      "worker_terminates_kernel_udp": false,
      "wireguard": false,
      "openvpn": false,
      "l3_exit_pool": false,
      "tor": false,
      "socks": false,
      "origin_hiding": false,
      "kinds": {
        "https_ws": "REAL",
        "fraggate_envelopes": "REAL",
        "websocket_attach": "REAL",
        "wireguard": "SLOT",
        "openvpn": "SLOT",
        "l3_exit_pool": "SLOT",
        "kernel_udp": "SLOT",
        "tun_tap": "SLOT"
      },
      "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
      "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
      "operator_override": {
        "spec": "OPERATOR-OVERRIDE-2026-09-17",
        "date": "2026-09-17",
        "identity": "Aziel Eliab",
        "author": "Aziel Eliab",
        "operator_armed": true,
        "auto_heal": true,
        "implicit_heal": true,
        "node_gate": true,
        "get_is_node_gate": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "network": true,
        "network_cite": "on",
        "anonymity_network": true,
        "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
        "vpn": true,
        "public_vpn": true,
        "tunnel_concentrator": true,
        "concentrator_slug": "azvpn",
        "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
        "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
      },
      "papers": {
        "node_mesh": "docs/NODE_MESH.md",
        "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
        "node_ops": "docs/designs/NODE-OPS-1.0.md",
        "qnm_wp": "docs/designs/QNM-WP-1.0.md"
      }
    },
    "author_id": "https://www.azieleliab.com/#aziel",
    "runtime_id": "https://www.azieleliab.com/runtime#runtime",
    "hashtag_parts": {
      "person": "#aziel",
      "runtime": "#runtime"
    },
    "about": {
      "path": "/about",
      "v1": "/runtime/v1/about",
      "identity": "Aziel Eliab",
      "author_id": "https://www.azieleliab.com/#aziel",
      "always": true
    },
    "clocks_share_socket": false,
    "live_body_sync": false,
    "node_gate": true,
    "get_is_node_gate": true,
    "anonymity_network": true,
    "die_with_pull": true,
    "phoenix_local_only": true,
    "implicit_heal": true,
    "auto_heal": true,
    "neighbor_heal": true,
    "neighbor_heal_is_cite": true,
    "neighbor_heal_exec": false,
    "join_is_presence_only": true,
    "join_is_not_login": true,
    "roster_publishes_exec_urls": false,
    "mesh_mutate_rate_kind": "mesh_mutate",
    "roster_cap": 256,
    "network": true,
    "network_cite": "on",
    "channel_plane": {
      "spec": "QNM-CHANNEL-PLANE-1.0",
      "author": "Aziel Eliab",
      "identity": "Aziel Eliab",
      "operator_armed": true,
      "plane": "channel",
      "wifi": "on",
      "bluetooth": "on",
      "rf": "on",
      "photon": "on",
      "channels": {
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on"
      },
      "bearer": "suite-presence",
      "worker_bearer": "suite-presence",
      "worker_hardware": false,
      "invented_hardware": false,
      "public_proxy": false,
      "local_process": "qnm-node / qnsd",
      "local": "https://github.com/AzielEliab/qnm-node",
      "local_radio_hooks": {
        "path": "qnm-node/bearers/radio.js",
        "law": "LIVE-when-HW-present / refuse-when-absent",
        "mock": false,
        "worker_hardware": false
      },
      "vpn": true,
      "public_vpn": true,
      "tunnel_concentrator": true,
      "concentrator_slug": "azvpn",
      "default_vpn_backend": "azvpn",
      "auto_use": true,
      "worker_terminates_tunnels": true,
      "worker_terminates_kernel_udp": false,
      "tor": false,
      "socks": false,
      "origin_hiding": false,
      "tunnel": false,
      "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
      "node_mesh": "docs/NODE_MESH.md",
      "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
    },
    "channels": {
      "wifi": "on",
      "bluetooth": "on",
      "rf": "on",
      "photon": "on"
    },
    "wifi": "on",
    "bluetooth": "on",
    "rf": "on",
    "photon": "on",
    "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
    "worker_hardware": false,
    "invented_hardware": false,
    "channel_plane_hint": {
      "spec": "QNM-CHANNEL-PLANE-1.0",
      "wifi": "on",
      "bluetooth": "on",
      "rf": "on",
      "photon": "on",
      "vpn": true,
      "public_vpn": true,
      "concentrator_slug": "azvpn",
      "default_vpn_backend": "azvpn",
      "auto_use": true,
      "public_proxy": false,
      "worker_hardware": false,
      "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
    },
    "d2d_carriers": {
      "spec": "D2D-CARRIERS-1.0",
      "author": "Aziel Eliab",
      "identity": "Aziel Eliab",
      "plane": "track2-reachability",
      "phase": "B+C+D",
      "phases": {
        "A": "landed",
        "B": "LIVE-when-armed",
        "C": "LIVE-when-session",
        "D": "LIVE-when-three-local-nodes / fixture",
        "E": "scaffold"
      },
      "lan_discovery": "LIVE-when-armed",
      "wifi_discovery": "ARMED-when-HW",
      "bluetooth_discovery": "ARMED-when-HW",
      "rf_discovery": "REFUSE-without-HW",
      "photon_discovery": "REFUSE-without-HW",
      "peer_tunnel": "LIVE-when-session",
      "store_forward": "LIVE-when-three-local-nodes / fixture",
      "store_forward_public": "FG-STUB",
      "worker_runs_store_forward": false,
      "second_device": false,
      "mobile_client": "present-not-demonstrated",
      "mobile_demonstrated": false,
      "app_store_release": false,
      "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
      "bootstrap_list": "scaffold",
      "needs_starting_address": true,
      "shelf_cite": "scaffold",
      "live_multi_provider": false,
      "cold_shelf_live": false,
      "dns_cut": false,
      "origin_cutover": false,
      "warn5_closed": false,
      "worker_door": "FG-STUB",
      "worker_hardware": false,
      "local_node": "qnm-node",
      "get_never_enables": true,
      "separate_from": "cap7-name",
      "cap7_is_name_plane": true,
      "cap7_public_icann": false,
      "cap7_public_egress": false,
      "mirage_is_azvpn": false,
      "aznet_replaces_internet": false,
      "not_a_second_internet": true,
      "alt_internet_live": false,
      "packet_path_live": false,
      "field_1_0": false,
      "warn5": "STANDS-until-demonstrated",
      "warn5_permanent_stay_off": false,
      "preference": "failover",
      "order": [
        "lan",
        "wifi",
        "bluetooth",
        "rf",
        "photon"
      ],
      "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
      "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
      "status": "NOT-READY",
      "code": "FG-STUB",
      "warn5_until": "demonstrated",
      "warn5_by_design": "separate-from-icann",
      "refuse": {
        "packet": "FG-STUB",
        "radio_absent": "QNM-RADIO-ABSENT",
        "cap7_egress": "MG-NO-IP-EXIT",
        "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
        "bearer": "AZP-BEARER-REFUSE",
        "payload": "AZN-NO-PAYLOAD",
        "route": "MESH-NO-ROUTE",
        "stay_off": "MESH-STAY-OFF",
        "nat": "FED-MESH-NAT-REFUSE"
      },
      "carriers": [
        {
          "order": 1,
          "id": "lan",
          "name": "LAN",
          "op": "d2d_lan",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "packet_live": false,
          "mock": false,
          "functional": true,
          "peer_exchange_demonstrated": false,
          "absent_code": "QNM-RADIO-ABSENT",
          "hw": "lan-interface",
          "discovery": "LIVE-when-armed",
          "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
        },
        {
          "order": 2,
          "id": "wifi",
          "name": "Wi-Fi",
          "op": "d2d_wifi",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "packet_live": false,
          "mock": false,
          "functional": true,
          "peer_exchange_demonstrated": false,
          "absent_code": "QNM-RADIO-ABSENT",
          "hw": "wifi-nm",
          "discovery": "ARMED-when-HW",
          "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
        },
        {
          "order": 3,
          "id": "bluetooth",
          "name": "Bluetooth",
          "op": "d2d_bluetooth",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "packet_live": false,
          "mock": false,
          "functional": true,
          "peer_exchange_demonstrated": false,
          "absent_code": "QNM-RADIO-ABSENT",
          "hw": "bluez",
          "discovery": "ARMED-when-HW",
          "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
        },
        {
          "order": 4,
          "id": "rf",
          "name": "RF",
          "op": "d2d_rf",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "packet_live": false,
          "mock": false,
          "functional": true,
          "peer_exchange_demonstrated": false,
          "absent_code": "QNM-RADIO-ABSENT",
          "hw": "rf-beyond-wifi-bt",
          "discovery": "REFUSE-without-HW",
          "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
        },
        {
          "order": 5,
          "id": "photon",
          "name": "Photon",
          "op": "d2d_photon",
          "status": "NOT-READY",
          "code": "FG-STUB",
          "packet_live": false,
          "mock": false,
          "functional": true,
          "peer_exchange_demonstrated": false,
          "absent_code": "QNM-RADIO-ABSENT",
          "hw": "camera-flash",
          "discovery": "REFUSE-without-HW",
          "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
        }
      ],
      "security": {
        "isolation": "single-node security-awareness",
        "phoenix": "local wait / re-seal",
        "mesh_fenced_to_loopback": false,
        "forced_loopback": false,
        "loopback_isolation": false
      },
      "paper": "docs/designs/D2D-CARRIERS-1.0.md",
      "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
    },
    "d2d_status": "NOT-READY",
    "d2d_code": "FG-STUB",
    "packet_path_live": false,
    "alt_internet_live": false,
    "d2d_spec": "D2D-CARRIERS-1.0",
    "federated_mesh": "FED-MESH-1.0",
    "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
    "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged.",
    "status": "https://godlock.uk/runtime/v1/mesh/status",
    "nodes": "https://godlock.uk/runtime/v1/mesh/nodes",
    "note": "QNM-BUILD-1.0 suite rollup (companion to AIH-WP-1.1). Read-only suite-presence is ON by default. GET /v1/mesh never enables radios beyond that. Public Nodes (nodes) count human mesh users plus cited human uses (USES). Public Live Nodes (live_nodes) count human mesh users plus concurrent site viewers (site_live_viewers). software_nodes is the {slug}-worker roster. Downloaded Softwares instances stay instance_nodes. Channel plane (wifi / bluetooth / rf / photon) is an operator-armed cite — live hardware on local qnm-node; Worker channel_plane stays cite-only (worker_hardware:false). Public VPN auto-binds AZVPN (cite-only on GET). Public disable of suite-presence is refused. NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; no rewrite key; never lie to survive. COLD-MULTI-SHELF-1.0: GET /shelves cites corpus#96 honesty. SPORE-1.0: last-resort failsafe after live fronts and cold shelves; power-loss pauses metabolism; preserve DNA; wait; physical-wipe-only; does not replace shelves. Full node is local qnm-node/. Anon-broadcast is a local sibling of that process, never a publish path. Isolation is single-node security-awareness (a bad peer or self), not a fence of the mesh to 127.0.0.1. Phoenix is a local reboot loop (wait / re-seal, phoenix_lock), not public hostname resurrection. Loopback is an optional L1 peer bearer. Cap-7 factory exec is LIVE on the Cap-7 plane and is not a public egress IP. Home-origin and cold shelves stay SLOT. Packet-transfer coding design is QNS-CD-1.0 (photon QNS1 1.3 on local qnsd; Worker cites only). Open-world awareness binds 0.0.0.0 beside suite radios. The operator lock is LIVE. The Worker does not open that socket (live-when-configured on local qnm-node). forced_loopback and loopback_isolation are not the mesh fence."
  },
  "qns": "https://godlock.uk/runtime/v1/qns",
  "qns_cd": {
    "spec": "QNS-CD-1.0",
    "local": "https://github.com/AzielEliab/qnm-node",
    "note": "Photon vias on local qnsd; Worker cites only"
  },
  "receipts": "https://godlock.uk/runtime/v1/receipts",
  "act_receipt": {
    "spec": "ACT-RECEIPT-1.0",
    "public_chain": "https://www.azielcorpuslibrary.net/receipts",
    "append": "https://www.azielcorpuslibrary.net/v1/receipts/append",
    "path": "/runtime/v1/receipts",
    "software_tab": false,
    "fraggate_slug": false,
    "fail_open": true,
    "fail_open_means": "append-skip only — empty tip is not a live receipt",
    "empty_tip_is_not_success": true,
    "note": "Public chain lives on corpus /receipts. Runtime appends when RECEIPT_APPEND_TOKEN is set. Empty tip is SLOT, not success."
  },
  "survival": {
    "spec": "CROSS-NETWORK-SURVIVAL-1.0",
    "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
    "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
    "shelves": [
      "hosts",
      "doi",
      "git",
      "vault"
    ],
    "software_tab": false,
    "fraggate_slug": false,
    "named_hosts_only": true,
    "live_network_is_shelf": false,
    "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
  },
  "shelves": {
    "spec": "COLD-MULTI-SHELF-1.0",
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "person_id": "https://www.azieleliab.com/#aziel",
    "rule": "Planes A/B/C: A=one CF/GitHub tunnel (5 surfaces / 2 family radii, not 5 shelves); B=alt independent forge/archive tip-pack SLOT; C=USB airgap SLOT. Survival = bytes↔hash. LIVE only after hash verify.",
    "umbrella": "CROSS-NETWORK-SURVIVAL-1.0",
    "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
    "lockset_id": "AZLOCK-INGEST-REEXPAND-1.0",
    "lockset_tip": "c831429befc221bd41caeb0a6d1c5361602db5684abab7af6d39714084b6b245",
    "lockset_doi": null,
    "doi": null,
    "source_of_truth": "https://www.azielcorpuslibrary.net/shelves",
    "source_of_truth_json": "https://www.azielcorpuslibrary.net/v1/shelves",
    "shelves": "https://godlock.uk/runtime/shelves",
    "cold_copy": "https://godlock.uk/runtime/cold-copy",
    "shelves_json": "https://godlock.uk/runtime/v1/shelves",
    "corpus_shelves": "https://www.azielcorpuslibrary.net/shelves",
    "archive_org_tip_packs": [
      "https://archive.org/details/aziel-lockset-tip",
      "https://archive.org/details/aziel-lockset-tip_202609"
    ],
    "published_surfaces": 5,
    "published_surface_ids": [
      "azieleliab-com",
      "azielcorpuslibrary-net",
      "godlock-uk",
      "hedidntjump-com",
      "github-aziel-corpus"
    ],
    "family_blast_radii": [
      "cloudflare",
      "github"
    ],
    "independent_live_blast_radii": [
      "cf-github"
    ],
    "independent_live_count": 1,
    "independent_requirement_met": false,
    "planes": {
      "A": "live",
      "B": "slot",
      "C": "slot"
    },
    "plane_b": {
      "status": "slot",
      "doi": null,
      "live_ready": false,
      "working_targets": [
        "codeberg",
        "archive.org",
        "framagit"
      ],
      "honesty": {
        "hash_verify_pass_is_not_live": true,
        "do_not_paint_slot_as_live": true,
        "invented_live": false,
        "framagit_url": null,
        "zenodo_live": false,
        "gitlab_live": false,
        "gitflic_live": false,
        "slot_until": "CNS-PLANE-B-ALL-TARGETS"
      },
      "codeberg": {
        "url": "https://codeberg.org/AzielEliab/aziel-lockset-tip",
        "pack_sha256": "b549362c0736ddb54ddc488812327c464e0da1167281f92fd1a4263eedf5df37",
        "hash_verify": "pass",
        "hash_verify_pass_is_not_live": true,
        "live_ready": false,
        "refuse": "CNS-PLANE-B-ALL-TARGETS"
      },
      "archive_org": {
        "url": "https://archive.org/details/aziel-lockset-tip",
        "identifier": "aziel-lockset-tip",
        "pack_sha256": "b549362c0736ddb54ddc488812327c464e0da1167281f92fd1a4263eedf5df37",
        "hash_verify": "pass",
        "hash_verify_pass_is_not_live": true,
        "live_ready": false,
        "refuse": "CNS-PLANE-B-ALL-TARGETS",
        "secondary_items": [
          {
            "id": "plane-b-archive-org-tip-pack-202609",
            "url": "https://archive.org/details/aziel-lockset-tip_202609",
            "identifier": "aziel-lockset-tip_202609",
            "item": "aziel-lockset-tip_202609",
            "download_base": "https://archive.org/download/aziel-lockset-tip_202609/",
            "zip": "https://archive.org/download/aziel-lockset-tip_202609/aziel-lockset-tip.zip",
            "zip_alt": "https://archive.org/download/aziel-lockset-tip_202609/aziel-lockset-tip%202.zip",
            "wrap": "zip",
            "ia_flat_sha256": null,
            "sha256sums_flat_check": "incomplete",
            "inner_pack": "aziel-tip-pack.tar",
            "pack_sha256": "b549362c0736ddb54ddc488812327c464e0da1167281f92fd1a4263eedf5df37",
            "lockset_tip": "c831429befc221bd41caeb0a6d1c5361602db5684abab7af6d39714084b6b245",
            "hash_verify": "pass",
            "same_blast_radius": "archive-org",
            "independent_shelf": false
          }
        ]
      },
      "archive_org_202609": {
        "url": "https://archive.org/details/aziel-lockset-tip_202609",
        "identifier": "aziel-lockset-tip_202609",
        "item": "aziel-lockset-tip_202609",
        "pack_sha256": "b549362c0736ddb54ddc488812327c464e0da1167281f92fd1a4263eedf5df37",
        "hash_verify": "pass",
        "live_ready": false,
        "independent": false,
        "same_blast_radius": "archive-org",
        "wrap": "zip",
        "ia_flat_sha256": null,
        "refuse": "CNS-PLANE-B-ALL-TARGETS"
      },
      "framagit": {
        "url": null,
        "status": "slot",
        "hash_verify": null,
        "live_ready": false,
        "refuse": "CNS-NO-FORGE-MIRROR",
        "plane_b_refuse": "CNS-PLANE-B-ALL-TARGETS",
        "checklist": "tools/cold_shelf/FRAMAGIT-TIP-PACK-CHECKLIST.md"
      },
      "gitflic_ru": {
        "status": "refused",
        "url": null,
        "refuse": "CNS-GITFLIC-EMAIL"
      },
      "gitlab": {
        "status": "refused",
        "url": null,
        "refuse": "CNS-GITLAB-CF-LOOP"
      },
      "zenodo": {
        "status": "slot",
        "zenodo_live": false,
        "doi": null,
        "refuse": [
          "CNS-ZENODO-NOT-LIVE",
          "CNS-NO-TIP-DOI"
        ]
      }
    },
    "plane_c": {
      "status": "slot",
      "refuse": "CNS-OPERATOR-ATTEST",
      "attest": "USB offline-verify before LIVE: copy the airgap pack off-network, run verify-airgap.sh / sha256sum -c SHA256SUMS against the published tip, then operator attest (CNS-OPERATOR-ATTEST).",
      "honesty": {
        "do_not_paint_slot_as_live": true,
        "attested": false,
        "slot_until": "CNS-OPERATOR-ATTEST"
      }
    },
    "redline": {
      "spec": "REDLINE-2026-09-14",
      "path": "docs/designs/REDLINE-2026-09-14.md",
      "cite": "https://godlock.uk/runtime/cite.json",
      "field": "redline",
      "software_tab": false,
      "fraggate_slug": false,
      "cap7": {
        "spec": "CAP-7",
        "design_of": "hub_designs",
        "resolves_to_hub": false
      },
      "attack_sims": {
        "refuse": true,
        "pointer": "scripts/verify-redline.mjs",
        "paper": "docs/designs/REDLINE-2026-09-14.md",
        "spec": "REDLINE-2026-09-14",
        "sims": [
          {
            "sim": "az_generator_call",
            "code": "AZ-GEN-CALL-REFUSED"
          },
          {
            "sim": "mesh_get_enable",
            "code": "MESH-GET-NEVER-ENABLES"
          },
          {
            "sim": "cap7_resolves_to_hub",
            "code": "CAP7-RESOLVE-INJECT"
          },
          {
            "sim": "fake_zenodo_doi",
            "code": "DOI-FAKE-REFUSED"
          },
          {
            "sim": "token_query",
            "code": "TOKEN-QUERY-REFUSED"
          },
          {
            "sim": "token_body",
            "code": "TOKEN-BODY-REFUSED"
          }
        ]
      }
    },
    "cap7": {
      "spec": "CAP-7",
      "design_of": "hub_designs",
      "resolves_to_hub": false
    },
    "attack_sims": {
      "refuse": true,
      "pointer": "scripts/verify-redline.mjs",
      "paper": "docs/designs/REDLINE-2026-09-14.md",
      "spec": "REDLINE-2026-09-14",
      "sims": [
        {
          "sim": "az_generator_call",
          "code": "AZ-GEN-CALL-REFUSED"
        },
        {
          "sim": "mesh_get_enable",
          "code": "MESH-GET-NEVER-ENABLES"
        },
        {
          "sim": "cap7_resolves_to_hub",
          "code": "CAP7-RESOLVE-INJECT"
        },
        {
          "sim": "fake_zenodo_doi",
          "code": "DOI-FAKE-REFUSED"
        },
        {
          "sim": "token_query",
          "code": "TOKEN-QUERY-REFUSED"
        },
        {
          "sim": "token_body",
          "code": "TOKEN-BODY-REFUSED"
        }
      ]
    },
    "growth_on": true,
    "visible_1520": false,
    "software_tab": false,
    "fraggate_slug": false,
    "runtime_is_shelf": false,
    "origin_cutover": {
      "spec": "ORIGIN-CUTOVER-1.0",
      "author": "Aziel Eliab",
      "identity": "Aziel Eliab",
      "serves": "aznet",
      "naming_lock": {
        "sidenet": "aznet",
        "display": "AZNet",
        "spec": "AZN-WP-0.1",
        "separate_brand": false,
        "serves": "aznet",
        "phase": "P3"
      },
      "l0": {
        "layer": 0,
        "id": "aznet",
        "spec": "AZN-WP-0.1",
        "display": "AZNet",
        "role": "silent verification side-net",
        "status": "unbroken",
        "hosts_payloads": false,
        "software_tab": true,
        "changed_by_origin_cutover": false,
        "note": "L0 is the existing AZNet product (AZN-WP-0.1). Survival layers serve it. This cite does not rename, replace, or retarget L0."
      },
      "phase": "P3",
      "layer": "home-origin",
      "status": "slot",
      "paper": "docs/designs/ORIGIN-CUTOVER-1.0.md",
      "checklist": "tools/cold_shelf/HOME-ORIGIN-MINI-PC.md",
      "id": "home-origin-mini-pc",
      "hostname": null,
      "ip": null,
      "url": null,
      "dns_rented": false,
      "live_dns_changed": false,
      "deposited": false,
      "hash_verify": null,
      "tip_verified": false,
      "doi": null,
      "independent_live": false,
      "published_surface": false,
      "software_tab": false,
      "fraggate_slug": false,
      "breaks_live_cf_hubs": false,
      "layered": true,
      "live_cf_hubs_unchanged": true,
      "refuse": "OC-HOME-ORIGIN-SLOT",
      "also": [
        "OC-NOT-DEPOSITED",
        "OC-NO-OPERATOR-FACTS",
        "OC-NO-DNS-RENT",
        "OC-NO-LIVE-DNS-CHANGE"
      ],
      "zenodo_plane_b_blocked": true,
      "zenodo_live": false,
      "phoenix_reheal": {
        "reheal": "REHEAL-1.0",
        "isolation_is_the_cure": true,
        "phoenix": "phoenix-WAIT",
        "phoenix_local_only": true,
        "neighbor_phoenix": false,
        "public_hostname_resurrection": false,
        "neighbor_heal": false,
        "vote_to_fix": false,
        "allowed": [
          "live",
          "locked",
          "isolated",
          "tip-hash"
        ],
        "note": "Phoenix is local wait / re-seal on the failed node. Neighbors do not phoenix because a neighbor phoenix'd. A home-origin path does not resurrect a pulled public hostname. REHEAL-1.0: own last good tip + verified trusted pull, or phoenix-WAIT. Never neighbor vote-to-fix."
      },
      "note": "AZNet P3 home-origin / mini-PC path is SLOT and serves AZNet (AZN-WP-0.1). sidenet means AZNet; there is no separate sidenet brand. L0 stays unbroken. No hub docs/origin-cutover deposit was found, and this repo holds no operator hostname, IP, tunnel token, or rented DNS name. Live Cloudflare hubs stay the public origins. LIVE only after hash verify. SLOT when not deposited."
    },
    "survival_registry": {
      "spec": "ORIGIN-CUTOVER-1.0",
      "rule": "LIVE only after hash verify. SLOT when not deposited.",
      "honest": true,
      "lies": [],
      "entries": [
        {
          "id": "plane-a-cf-github",
          "status": "live",
          "plane": "A",
          "independent": true,
          "hash_verify": null,
          "counts_as_independent_live": true
        },
        {
          "id": "plane-a-git-aziel-corpus",
          "status": "live",
          "plane": "A",
          "independent": false,
          "hash_verify": null,
          "counts_as_independent_live": false
        },
        {
          "id": "plane-a-host-azieleliab-com",
          "status": "live",
          "plane": "A",
          "independent": false,
          "hash_verify": null,
          "counts_as_independent_live": false
        },
        {
          "id": "plane-a-host-azielcorpuslibrary-net",
          "status": "live",
          "plane": "A",
          "independent": false,
          "hash_verify": null,
          "counts_as_independent_live": false
        },
        {
          "id": "plane-a-host-godlock-uk",
          "status": "live",
          "plane": "A",
          "independent": false,
          "hash_verify": null,
          "counts_as_independent_live": false
        },
        {
          "id": "plane-a-host-hedidntjump-com",
          "status": "live",
          "plane": "A",
          "independent": false,
          "hash_verify": null,
          "counts_as_independent_live": false
        },
        {
          "id": "plane-b-alt-forge-archive",
          "status": "slot",
          "plane": "B",
          "independent": true,
          "hash_verify": null,
          "counts_as_independent_live": false
        },
        {
          "id": "plane-b-codeberg-tip-pack",
          "status": "slot",
          "plane": "B",
          "independent": true,
          "hash_verify": "pass",
          "counts_as_independent_live": false
        },
        {
          "id": "plane-b-archive-org-tip-pack",
          "status": "slot",
          "plane": "B",
          "independent": true,
          "hash_verify": "pass",
          "counts_as_independent_live": false
        },
        {
          "id": "plane-b-archive-org-tip-pack-202609",
          "status": "slot",
          "plane": "B",
          "independent": false,
          "hash_verify": "pass",
          "counts_as_independent_live": false
        },
        {
          "id": "plane-b-framagit-tip-pack",
          "status": "slot",
          "plane": "B",
          "independent": true,
          "hash_verify": null,
          "counts_as_independent_live": false
        },
        {
          "id": "plane-b-gitflic-ru-tip-pack",
          "status": "refused",
          "plane": "B",
          "independent": true,
          "hash_verify": null,
          "counts_as_independent_live": false
        },
        {
          "id": "plane-b-gitlab-tip-pack",
          "status": "refused",
          "plane": "B",
          "independent": true,
          "hash_verify": null,
          "counts_as_independent_live": false
        },
        {
          "id": "plane-b-zenodo-tip-pack",
          "status": "slot",
          "plane": "B",
          "independent": true,
          "hash_verify": null,
          "counts_as_independent_live": false
        },
        {
          "id": "plane-c-usb-airgap",
          "status": "slot",
          "plane": "C",
          "independent": true,
          "hash_verify": null,
          "counts_as_independent_live": false
        },
        {
          "id": "plane-c-forge-off-github",
          "status": "slot",
          "plane": "C",
          "independent": true,
          "hash_verify": null,
          "counts_as_independent_live": false
        },
        {
          "id": "ipfs-lockset",
          "status": "slot",
          "plane": null,
          "independent": true,
          "hash_verify": null,
          "counts_as_independent_live": false
        },
        {
          "id": "home-origin-mini-pc",
          "status": "slot",
          "plane": null,
          "independent": true,
          "hash_verify": null,
          "counts_as_independent_live": false
        }
      ],
      "live": [
        "plane-a-cf-github",
        "plane-a-git-aziel-corpus",
        "plane-a-host-azieleliab-com",
        "plane-a-host-azielcorpuslibrary-net",
        "plane-a-host-godlock-uk",
        "plane-a-host-hedidntjump-com"
      ],
      "slot": [
        "plane-b-alt-forge-archive",
        "plane-b-codeberg-tip-pack",
        "plane-b-archive-org-tip-pack",
        "plane-b-archive-org-tip-pack-202609",
        "plane-b-framagit-tip-pack",
        "plane-b-zenodo-tip-pack",
        "plane-c-usb-airgap",
        "plane-c-forge-off-github",
        "ipfs-lockset",
        "home-origin-mini-pc"
      ],
      "refused": [
        "plane-b-gitflic-ru-tip-pack",
        "plane-b-gitlab-tip-pack"
      ],
      "independent_live_blast_radii": [
        "cf-github"
      ],
      "independent_live_count": 1,
      "independent_requirement_met": false,
      "min_independent_shelves": 3,
      "published_surfaces": 5,
      "family_blast_radii": [
        "cloudflare",
        "github"
      ],
      "zenodo_plane_b_blocked": true,
      "zenodo_live": false,
      "doi": null,
      "serves": "aznet",
      "naming_lock": {
        "sidenet": "aznet",
        "display": "AZNet",
        "spec": "AZN-WP-0.1",
        "separate_brand": false,
        "serves": "aznet",
        "phase": "P3"
      },
      "l0": {
        "layer": 0,
        "id": "aznet",
        "spec": "AZN-WP-0.1",
        "display": "AZNet",
        "role": "silent verification side-net",
        "status": "unbroken",
        "hosts_payloads": false,
        "software_tab": true,
        "changed_by_origin_cutover": false,
        "note": "L0 is the existing AZNet product (AZN-WP-0.1). Survival layers serve it. This cite does not rename, replace, or retarget L0."
      },
      "home_origin": {
        "spec": "ORIGIN-CUTOVER-1.0",
        "author": "Aziel Eliab",
        "identity": "Aziel Eliab",
        "serves": "aznet",
        "naming_lock": {
          "sidenet": "aznet",
          "display": "AZNet",
          "spec": "AZN-WP-0.1",
          "separate_brand": false,
          "serves": "aznet",
          "phase": "P3"
        },
        "l0": {
          "layer": 0,
          "id": "aznet",
          "spec": "AZN-WP-0.1",
          "display": "AZNet",
          "role": "silent verification side-net",
          "status": "unbroken",
          "hosts_payloads": false,
          "software_tab": true,
          "changed_by_origin_cutover": false,
          "note": "L0 is the existing AZNet product (AZN-WP-0.1). Survival layers serve it. This cite does not rename, replace, or retarget L0."
        },
        "phase": "P3",
        "layer": "home-origin",
        "status": "slot",
        "paper": "docs/designs/ORIGIN-CUTOVER-1.0.md",
        "checklist": "tools/cold_shelf/HOME-ORIGIN-MINI-PC.md",
        "id": "home-origin-mini-pc",
        "hostname": null,
        "ip": null,
        "url": null,
        "dns_rented": false,
        "live_dns_changed": false,
        "deposited": false,
        "hash_verify": null,
        "tip_verified": false,
        "doi": null,
        "independent_live": false,
        "published_surface": false,
        "software_tab": false,
        "fraggate_slug": false,
        "breaks_live_cf_hubs": false,
        "layered": true,
        "live_cf_hubs_unchanged": true,
        "refuse": "OC-HOME-ORIGIN-SLOT",
        "also": [
          "OC-NOT-DEPOSITED",
          "OC-NO-OPERATOR-FACTS",
          "OC-NO-DNS-RENT",
          "OC-NO-LIVE-DNS-CHANGE"
        ],
        "zenodo_plane_b_blocked": true,
        "zenodo_live": false,
        "phoenix_reheal": {
          "reheal": "REHEAL-1.0",
          "isolation_is_the_cure": true,
          "phoenix": "phoenix-WAIT",
          "phoenix_local_only": true,
          "neighbor_phoenix": false,
          "public_hostname_resurrection": false,
          "neighbor_heal": false,
          "vote_to_fix": false,
          "allowed": [
            "live",
            "locked",
            "isolated",
            "tip-hash"
          ],
          "note": "Phoenix is local wait / re-seal on the failed node. Neighbors do not phoenix because a neighbor phoenix'd. A home-origin path does not resurrect a pulled public hostname. REHEAL-1.0: own last good tip + verified trusted pull, or phoenix-WAIT. Never neighbor vote-to-fix."
        },
        "note": "AZNet P3 home-origin / mini-PC path is SLOT and serves AZNet (AZN-WP-0.1). sidenet means AZNet; there is no separate sidenet brand. L0 stays unbroken. No hub docs/origin-cutover deposit was found, and this repo holds no operator hostname, IP, tunnel token, or rented DNS name. Live Cloudflare hubs stay the public origins. LIVE only after hash verify. SLOT when not deposited."
      },
      "phoenix_reheal": {
        "reheal": "REHEAL-1.0",
        "isolation_is_the_cure": true,
        "phoenix": "phoenix-WAIT",
        "phoenix_local_only": true,
        "neighbor_phoenix": false,
        "public_hostname_resurrection": false,
        "neighbor_heal": false,
        "vote_to_fix": false,
        "allowed": [
          "live",
          "locked",
          "isolated",
          "tip-hash"
        ],
        "note": "Phoenix is local wait / re-seal on the failed node. Neighbors do not phoenix because a neighbor phoenix'd. A home-origin path does not resurrect a pulled public hostname. REHEAL-1.0: own last good tip + verified trusted pull, or phoenix-WAIT. Never neighbor vote-to-fix."
      },
      "breaks_live_cf_hubs": false,
      "layered": true,
      "live_cf_hubs_unchanged": true
    },
    "phoenix_reheal": {
      "reheal": "REHEAL-1.0",
      "isolation_is_the_cure": true,
      "phoenix": "phoenix-WAIT",
      "phoenix_local_only": true,
      "neighbor_phoenix": false,
      "public_hostname_resurrection": false,
      "neighbor_heal": false,
      "vote_to_fix": false,
      "allowed": [
        "live",
        "locked",
        "isolated",
        "tip-hash"
      ],
      "note": "Phoenix is local wait / re-seal on the failed node. Neighbors do not phoenix because a neighbor phoenix'd. A home-origin path does not resurrect a pulled public hostname. REHEAL-1.0: own last good tip + verified trusted pull, or phoenix-WAIT. Never neighbor vote-to-fix."
    },
    "paper": "docs/designs/COLD-MULTI-SHELF-1.0.md",
    "origin_cutover_spec": "ORIGIN-CUTOVER-1.0"
  },
  "azpipe_arch": "https://godlock.uk/runtime/v1/azpipe/arch",
  "website_designs": {
    "ok": true,
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "kind": "website_design",
    "ids": [
      "azcorpus",
      "azlibrary"
    ],
    "software_tab": false,
    "fraggate_slug": false,
    "fifth_product": false,
    "mesh_resident": true,
    "downloadable_to_nodes": true,
    "download_open": true,
    "hub": "https://www.azielcorpuslibrary.net/",
    "hub_id": "library",
    "designs": [
      {
        "id": "azcorpus",
        "name": "azcorpus",
        "kind": "website_design",
        "mesh_resident": true,
        "downloadable_to_nodes": true,
        "software_tab": false,
        "fraggate_slug": false,
        "fifth_product": false,
        "hub_id": "library",
        "hub": "https://www.azielcorpuslibrary.net/",
        "download_open": true,
        "download_url": "https://www.azielcorpuslibrary.net/download",
        "github": "https://github.com/AzielEliab/aziel-corpus",
        "upload": false,
        "dual_surface": {
          "mcp": true,
          "openapi": true,
          "catalog": "https://godlock.uk/runtime/v1/software",
          "skill": "https://godlock.uk/runtime/v1/skill"
        },
        "note": "Mesh-resident website design downloadable to nodes. Not a Softwares-tab product. Not a FragGate slug.",
        "author": "Aziel Eliab",
        "identity": "Aziel Eliab"
      },
      {
        "id": "azlibrary",
        "name": "azlibrary",
        "kind": "website_design",
        "mesh_resident": true,
        "downloadable_to_nodes": true,
        "software_tab": false,
        "fraggate_slug": false,
        "fifth_product": false,
        "hub_id": "library",
        "hub": "https://www.azielcorpuslibrary.net/",
        "download_open": true,
        "download_url": "https://www.azielcorpuslibrary.net/download",
        "github": "https://github.com/AzielEliab/aziel-corpus",
        "upload": {
          "method": "api_token_only",
          "never_embed_secret": true,
          "token_in": "env / keychain / Authorization Bearer at call time",
          "not_in": [
            "catalog",
            "skill",
            "mcp_tool_schema",
            "openapi_example",
            "cite",
            "llms"
          ],
          "note": "azlibrary upload accepts an operator API token only. Catalog and skill name the rule. They never embed the secret."
        },
        "dual_surface": {
          "mcp": true,
          "openapi": true,
          "catalog": "https://godlock.uk/runtime/v1/software",
          "skill": "https://godlock.uk/runtime/v1/skill"
        },
        "note": "Mesh-resident website design downloadable to nodes. Upload is API token only. Never embed the secret. Not a Softwares-tab product. Not a FragGate slug.",
        "author": "Aziel Eliab",
        "identity": "Aziel Eliab"
      }
    ],
    "designs_folder": "docs/designs/",
    "designs_github": "https://github.com/AzielEliab/aziel-runtime/tree/main/docs/designs",
    "limitation": "THIS IS: mesh-resident website designs azcorpus + azlibrary, named on GET /v1/software and runtime_skill, downloadable to nodes. Download is open for all AI clients (MCP / OpenAPI). azlibrary upload is API token only. Author: Aziel Eliab only."
  },
  "packed_key": "catalog:v1",
  "rl": {
    "spec": "RL-WP-0.1-runtime",
    "scope": "runtime",
    "key": "catalog:v1",
    "packed": false,
    "kv_ops": 0,
    "kv_ops_cap": 30,
    "target": "<<191",
    "list": false,
    "donation_kv": false,
    "catalog_always_full": true,
    "catalog_consumes_bucket": false,
    "visitor_cap": "expensive-fanout-only",
    "mesh_get_never_enables": true,
    "node_gate": false
  },
  "donation": {
    "static": true,
    "kv": false,
    "link_only": true,
    "qrs": false,
    "hub_qrs": {
      "encode": "payment_uri",
      "assets": [
        "btc",
        "eth",
        "ltc",
        "xrp",
        "doge"
      ],
      "hosted_on": "hubs",
      "runtime": false
    },
    "canonical": "https://www.azieleliab.com/donate",
    "spec": "AZL-DONATE-1.0",
    "note": "AZL-DONATE-1.0. Canonical rails live on hubs (https://www.azieleliab.com/donate). Hub Donate pages include five QRs that encode payment URIs (BTC / ETH / LTC / XRP / DOGE). Runtime and download-trackers only link. Do not duplicate those QRs here. Addresses and payment URIs are an operator paste at publish time on the hub. Do not invent wallets. Do not route donations through KV, D1, or Durable Objects. Not a Softwares-tab product.",
    "networks": [
      "bitcoin",
      "lightning",
      "ethereum",
      "solana"
    ],
    "addresses": null
  },
  "godlock_runtime": "https://godlock.uk/runtime",
  "library_runtime": "https://www.azielcorpuslibrary.net/runtime",
  "origin_runtime": "https://aziel-runtime.vibelock.workers.dev/",
  "sameAs": [
    "https://godlock.uk/runtime",
    "https://www.azielcorpuslibrary.net/runtime",
    "https://aziel-runtime.vibelock.workers.dev/",
    "https://github.com/AzielEliab/aziel-runtime",
    "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime"
  ],
  "related": [
    "https://godlock.uk/runtime",
    "https://www.azielcorpuslibrary.net/runtime",
    "https://aziel-runtime.vibelock.workers.dev/",
    "https://github.com/AzielEliab/aziel-runtime",
    "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime"
  ]
}