Commit graph

4 commits

Author SHA1 Message Date
cd3b1bc921 cockpit: the estate page now MEASURES instead of asserting
The /estate page was hand-written prose inside estateview.py: 32 hard-coded
fact arrays and zero places reading live data, last edited 2026-07-22. It
cannot go stale by accident — it can only go stale, because nothing connected
it to the repositories it describes. For eight days it told the operator:

  · SLH-DSA "campaign in progress", "check.sh exits non-green by design"
    — while it had 11 proven certificates, a green button, an 18-attack
      self-test and an outside reviewer's attest-with-conditions;
  · ed25519 "16 reviewed certificates"
    — while they had 31 bound certificates and 3022 inventoried constants;
  · nothing at all about five audit phases and five self-tests per repo,
    none of which existed on the day the page was last touched.

Those four claims are corrected. More importantly the page now carries a
MEASURED panel rendered from formal-verification-control's
tools/estate-progress.py, which derives every figure from the repositories at
generation time. The panel states three things a reader would otherwise have
to assume:

  · WHEN it was measured, and by what;
  · WHETHER the repositories have moved since — the snapshot records the HEADs
    it was taken against, and the panel compares them live, naming any repo
    that has moved rather than quietly showing old numbers as current;
  · WHICH PART OF THE PAGE IS MEASURED AT ALL. Everything above the panel is
    labelled, in the page itself, as hand-written prose that can be out of
    date. That label is the honest part: the map is still prose, and a reader
    should know which half is which.

If the snapshot is absent the panel says NOT MEASURED in words and prints the
command to produce one. It never renders nothing, and never falls back to
prose — a blank space and a confident-looking stale figure are the same
failure, and the second is worse.

Two numbers, never one, per PROGRESS-METRIC.md: a single figure is what let
the old metric report 100% for work nobody had attacked.

All three paths tested: current, moved-since, and absent. 145/145 tests pass,
including the sync test guarding drift between this page and ESTATE.md.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-30 18:24:31 +02:00
fd2f6baa36 estate: the SLH-DSA (FIPS 205) campaign enters the map — two new entities
Two repos joined the estate on 2026-07-22; both renderings (ESTATE.md +
cockpit /estate) gain their cards, with every fact recomputed from the
repos themselves:

- fips205-source (upstream lane): verbatim snapshot of
  integritychain/fips205 (pure-Rust FIPS 205 / SLH-DSA), upstream pin
  30bac08, snapshot head 5dca0db — single deviation: upstream CI
  workflows stripped, documented in-commit. Aeneas-compat patches land
  there as transparent, individually-justified commits; nothing is
  proposed upstream.
- fips205-slhdsa-verified (subject lane): SLH-DSA-SHA2-128s verify-path
  campaign, marked exactly as its own check.sh says — CAMPAIGN IN
  PROGRESS, zero certificates, non-green by design. NOT attested; the
  map does not imply otherwise.

Also:
- liveness board now probes fips205-slhdsa-verified (a sibling under
  the default repos root). fips205-source is deliberately NOT probed:
  the upstream-source shelf lives outside that root, like the five
  existing source clones (comment documents the decision).
- drift tripwire (test_estate_view_and_estate_md_do_not_drift) extended
  with both new sentinel names.
- stale fact chip refreshed in both renderings: pacta suite 135 → 144
  green (the suite grew during the cockpit era; chip was never bumped).
- estateview's pasta dossier no longer calls the curve layer "the one
  open verification task in the estate" — the campaign is a second.

Suite 144 green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-22 22:02:39 +02:00
00be6a396e cockpit: UX law — the cockpit never leaves a human in the dark
Operator verdict on the first cockpit: unusable, jargon-walled. The
evidence layer was honest but the presentation assumed the reader
already lived inside warden's head. This rebuilds the presentation
layer around a testable UX contract, additive to the design law:

- every page: verdict IN WORDS first (CUSTODY HEALTHY / CUSTODY FROZEN
  (LATCHED) / CUSTODY EVIDENCE BROKEN), then evidence, then provenance
- every page: plain-language lead saying what the page answers
- every panel: 'How to read this panel' expander interpreting every
  column and pill; jargon carries a ? linking to the glossary
- new /guide view: what warden is, how to read any page, color code,
  five-minute tour, 12-term glossary, honest 'what this cockpit cannot
  tell you'
- navigation: two-line tabs stating the question each view answers,
  present on every page; /estate gets a back-to-cockpit chip
- explained empty states (incidents: 'empty is the good state')
- narrow-viewport fix: tables/pre scroll in their own containers
- estate fact chip updated 130->135 green (both renderings)

UX contract is test-enforced (guide terms, lead+nav+explainers on every
view, empty states); read-only byte-guarantee sweep now covers /guide.
Verified by looking: served --demo, walked all six views in a browser.
Suite 131 -> 135 green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-21 16:15:00 +02:00
1acbaa1a76 cockpit: estate map as a fifth view, with RUNTIME as a first-class dimension
Operator questions answered in code: (1) the estate map now lives IN the
cockpit too — /estate serves the interactive map (lanes, typed edges,
loops, clickable dossiers) to the same human audience the cockpit
serves; ESTATE.md remains the canonical committed version (renders on
GitHub, reachable by agents via llms.txt, needs no running process), and
a name-level sync test guards drift between the two renderings — the
published_assets lesson applied preemptively. (2) 'What is RUNNING?' is
now answered everywhere: an operations strip on the map (ALWAYS ON:
caddy + the LTL read-only container + Forgejo with its single 03:00
mirror cron, all droplet; ON-DEMAND: append/publish/sign ceremonies,
cockpit, MCP, operator machine only; NOT RUNNING: warden — prototype,
no deployed instance, no funds watched; everything else: static files
or external parties), a per-entity Runtime line in every dossier, and a
verified What-is-running table in ESTATE.md (container commands, :ro
mounts and read_only:true on the LTL service, and the crontab checked
on the droplet 2026-07-20, not recalled).

Suite 128 -> 130 (estate route + drift guard). Local-only as before:
nothing deployed, live estate untouched.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 10:58:59 +02:00