The /estate page was hand-written prose inside estateview.py: 32 hard-coded
fact arrays and zero places reading live data, last edited 2026-07-22. It
cannot go stale by accident — it can only go stale, because nothing connected
it to the repositories it describes. For eight days it told the operator:
· SLH-DSA "campaign in progress", "check.sh exits non-green by design"
— while it had 11 proven certificates, a green button, an 18-attack
self-test and an outside reviewer's attest-with-conditions;
· ed25519 "16 reviewed certificates"
— while they had 31 bound certificates and 3022 inventoried constants;
· nothing at all about five audit phases and five self-tests per repo,
none of which existed on the day the page was last touched.
Those four claims are corrected. More importantly the page now carries a
MEASURED panel rendered from formal-verification-control's
tools/estate-progress.py, which derives every figure from the repositories at
generation time. The panel states three things a reader would otherwise have
to assume:
· WHEN it was measured, and by what;
· WHETHER the repositories have moved since — the snapshot records the HEADs
it was taken against, and the panel compares them live, naming any repo
that has moved rather than quietly showing old numbers as current;
· WHICH PART OF THE PAGE IS MEASURED AT ALL. Everything above the panel is
labelled, in the page itself, as hand-written prose that can be out of
date. That label is the honest part: the map is still prose, and a reader
should know which half is which.
If the snapshot is absent the panel says NOT MEASURED in words and prints the
command to produce one. It never renders nothing, and never falls back to
prose — a blank space and a confident-looking stale figure are the same
failure, and the second is worse.
Two numbers, never one, per PROGRESS-METRIC.md: a single figure is what let
the old metric report 100% for work nobody had attacked.
All three paths tested: current, moved-since, and absent. 145/145 tests pass,
including the sync test guarding drift between this page and ESTATE.md.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Two repos joined the estate on 2026-07-22; both renderings (ESTATE.md +
cockpit /estate) gain their cards, with every fact recomputed from the
repos themselves:
- fips205-source (upstream lane): verbatim snapshot of
integritychain/fips205 (pure-Rust FIPS 205 / SLH-DSA), upstream pin
30bac08, snapshot head 5dca0db — single deviation: upstream CI
workflows stripped, documented in-commit. Aeneas-compat patches land
there as transparent, individually-justified commits; nothing is
proposed upstream.
- fips205-slhdsa-verified (subject lane): SLH-DSA-SHA2-128s verify-path
campaign, marked exactly as its own check.sh says — CAMPAIGN IN
PROGRESS, zero certificates, non-green by design. NOT attested; the
map does not imply otherwise.
Also:
- liveness board now probes fips205-slhdsa-verified (a sibling under
the default repos root). fips205-source is deliberately NOT probed:
the upstream-source shelf lives outside that root, like the five
existing source clones (comment documents the decision).
- drift tripwire (test_estate_view_and_estate_md_do_not_drift) extended
with both new sentinel names.
- stale fact chip refreshed in both renderings: pacta suite 135 → 144
green (the suite grew during the cockpit era; chip was never bumped).
- estateview's pasta dossier no longer calls the curve layer "the one
open verification task in the estate" — the campaign is a second.
Suite 144 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Operator verdict on the first cockpit: unusable, jargon-walled. The
evidence layer was honest but the presentation assumed the reader
already lived inside warden's head. This rebuilds the presentation
layer around a testable UX contract, additive to the design law:
- every page: verdict IN WORDS first (CUSTODY HEALTHY / CUSTODY FROZEN
(LATCHED) / CUSTODY EVIDENCE BROKEN), then evidence, then provenance
- every page: plain-language lead saying what the page answers
- every panel: 'How to read this panel' expander interpreting every
column and pill; jargon carries a ? linking to the glossary
- new /guide view: what warden is, how to read any page, color code,
five-minute tour, 12-term glossary, honest 'what this cockpit cannot
tell you'
- navigation: two-line tabs stating the question each view answers,
present on every page; /estate gets a back-to-cockpit chip
- explained empty states (incidents: 'empty is the good state')
- narrow-viewport fix: tables/pre scroll in their own containers
- estate fact chip updated 130->135 green (both renderings)
UX contract is test-enforced (guide terms, lead+nav+explainers on every
view, empty states); read-only byte-guarantee sweep now covers /guide.
Verified by looking: served --demo, walked all six views in a browser.
Suite 131 -> 135 green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Operator questions answered in code: (1) the estate map now lives IN the
cockpit too — /estate serves the interactive map (lanes, typed edges,
loops, clickable dossiers) to the same human audience the cockpit
serves; ESTATE.md remains the canonical committed version (renders on
GitHub, reachable by agents via llms.txt, needs no running process), and
a name-level sync test guards drift between the two renderings — the
published_assets lesson applied preemptively. (2) 'What is RUNNING?' is
now answered everywhere: an operations strip on the map (ALWAYS ON:
caddy + the LTL read-only container + Forgejo with its single 03:00
mirror cron, all droplet; ON-DEMAND: append/publish/sign ceremonies,
cockpit, MCP, operator machine only; NOT RUNNING: warden — prototype,
no deployed instance, no funds watched; everything else: static files
or external parties), a per-entity Runtime line in every dossier, and a
verified What-is-running table in ESTATE.md (container commands, :ro
mounts and read_only:true on the LTL service, and the crontab checked
on the droplet 2026-07-20, not recalled).
Suite 128 -> 130 (estate route + drift guard). Local-only as before:
nothing deployed, live estate untouched.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>